<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Android OS (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/android.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/android-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Android OS (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:35 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-0072 – In addInputMethodListener of com.android.server.inputmethod.InputMethodManagerSe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0072</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0072</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0072</strong></p>
  <p>In addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0072">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44698 – Home Assistant is open source home automation software that puts local control a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44698</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44698</guid>
    <pubDate>Fri, 29 May 2026 14:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44698</strong></p>
  <p>Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he Home Assistant Companion apps for Android and iOS expose a JavaScript bridge to the in-app WebView window.externalApp on Android and webkit.messageHandlers.getExternalAuth (alongside revokeExternalAuth and externalBus) on iOS. Two flaws expose th…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44698">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9987 – Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9987</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9987</guid>
    <pubDate>Thu, 28 May 2026 23:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9987</strong></p>
  <p>Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 148.0.7778.216 allowed a local attacker to execute arbitrary code via a malicious file. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9987">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9977 – Insufficient validation of untrusted input in WebShare in Google Chrome on Andro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9977</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9977</guid>
    <pubDate>Thu, 28 May 2026 23:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9977</strong></p>
  <p>Insufficient validation of untrusted input in WebShare in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9977">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9898 – Insufficient validation of untrusted input in GPU in Google Chrome on Android pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9898</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9898</guid>
    <pubDate>Thu, 28 May 2026 23:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9898</strong></p>
  <p>Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9898">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9892 – Inappropriate implementation in Skia in Google Chrome on Android prior to 148.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9892</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9892</guid>
    <pubDate>Thu, 28 May 2026 23:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9892</strong></p>
  <p>Inappropriate implementation in Skia in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9892">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9889 – Out of bounds read and write in Dawn in Google Chrome on Android prior to 148.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9889</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9889</guid>
    <pubDate>Thu, 28 May 2026 23:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9889</strong></p>
  <p>Out of bounds read and write in Dawn in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9889">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9888 – Use after free in WebView in Google Chrome on Android prior to 148.0.7778.216 al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9888</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9888</guid>
    <pubDate>Thu, 28 May 2026 23:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9888</strong></p>
  <p>Use after free in WebView in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9888">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9876 – Use after free in WebGL in Google Chrome on Android prior to 148.0.7778.216 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9876</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9876</guid>
    <pubDate>Thu, 28 May 2026 23:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9876</strong></p>
  <p>Use after free in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9876">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9875 – Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9875</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9875</guid>
    <pubDate>Thu, 28 May 2026 23:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9875</strong></p>
  <p>Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9875">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9872 – Out of bounds write in GPU in Google Chrome on Android prior to 148.0.7778.216 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9872</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9872</guid>
    <pubDate>Thu, 28 May 2026 23:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9872</strong></p>
  <p>Out of bounds write in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9872">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10020 – Insufficient validation of untrusted input in Skia in Google Chrome on Android p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10020</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10020</guid>
    <pubDate>Thu, 28 May 2026 23:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10020</strong></p>
  <p>Insufficient validation of untrusted input in Skia in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10020">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10014 – Use after free in WebMIDI in Google Chrome on Android prior to 148.0.7778.216 al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10014</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10014</guid>
    <pubDate>Thu, 28 May 2026 23:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10014</strong></p>
  <p>Use after free in WebMIDI in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10014">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42184 – Tauri is a framework for building binaries for all major desktop platforms. From...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42184</guid>
    <pubDate>Wed, 27 May 2026 15:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42184</strong></p>
  <p>Tauri is a framework for building binaries for all major desktop platforms. From 2.0 to 2.11.0, a flaw in Tauri's is_local_url() function causes it to incorrectly classify remote URLs as trusted local origins on Windows and Android. On these systems, Tauri maps custom URI scheme protocols to http://<scheme>.localhost/ because those platforms' WebView implementations cannot serve custom URI scheme…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9123 – Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9123</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9123</guid>
    <pubDate>Wed, 20 May 2026 20:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9123</strong></p>
  <p>Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148.0.7778.179 allowed a local attacker to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9123">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8945 – Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8945</guid>
    <pubDate>Tue, 19 May 2026 14:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8945</strong></p>
  <p>Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8571 – Insufficient policy enforcement in GPU in Google Chrome on Android prior to 148...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8571</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8571</guid>
    <pubDate>Thu, 14 May 2026 20:17:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8571</strong></p>
  <p>Insufficient policy enforcement in GPU in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8571">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8513 – Use after free in Input in Google Chrome on Android prior to 148.0.7778.168 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8513</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8513</guid>
    <pubDate>Thu, 14 May 2026 20:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8513</strong></p>
  <p>Use after free in Input in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8513">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21020 – Improper export of android application components in OmaCP prior to SMR May-2026...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21020</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21020</guid>
    <pubDate>Wed, 13 May 2026 06:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21020</strong></p>
  <p>Improper export of android application components in OmaCP prior to SMR May-2026 Release 1 allows local attackers to trigger privileged functions.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21020">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33362 – In Meari IoT SDK builds embedded in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33362</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33362</guid>
    <pubDate>Mon, 11 May 2026 17:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33362</strong></p>
  <p>In Meari IoT SDK builds embedded in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and white-label Android apps <= 1.8.x (latest observed), multiple security-critical secrets are hardcoded and shared, including API signing material, password-transport keying, and service access keys.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33362">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-30496 – The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30496</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30496</guid>
    <pubDate>Thu, 07 May 2026 14:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-30496</strong></p>
  <p>The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes an HTTP API on TCP port 2345 that allows full unauthenticated remote control of the device. The API supports both reading configuration (74 endpoints) and writing/modifying settings including volume, mute, brightness, power, network protocols enable/disable (including TELNET), display modes, and other projector…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30496">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30495 – The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30495</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30495</guid>
    <pubDate>Thu, 07 May 2026 14:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30495</strong></p>
  <p>The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes Android Debug Bridge (ADB) on TCP port 5555 over the network without requiring authentication. The device is configured with ro.adb.secure=0, which disables RSA key verification. Additionally, a functional su binary exists at /system/xbin/su that grants root privileges without authentication. An attacker on the…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30495">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7913 – Insufficient policy enforcement in DevTools in Google Chrome on Android prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7913</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7913</guid>
    <pubDate>Wed, 06 May 2026 19:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7913</strong></p>
  <p>Insufficient policy enforcement in DevTools in Google Chrome on Android prior to 148.0.7778.96 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7913">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7905 – Insufficient validation of untrusted input in Media in Google Chrome on Android ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7905</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7905</guid>
    <pubDate>Wed, 06 May 2026 19:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7905</strong></p>
  <p>Insufficient validation of untrusted input in Media in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7905">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42090 – Notesnook is a note-taking app focused on user privacy &amp; ease of use. Prior to N...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42090</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42090</guid>
    <pubDate>Mon, 04 May 2026 17:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42090</strong></p>
  <p>Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and prior to Notesnook iOS/Android version 3.3.20, a stored XSS vulnerability in the note export flow can be escalated to remote code execution in the desktop app. The root cause is that exported note fields such as title, headline, and content are inserted into the generated HTML t…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42090">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7352 – Use after free in Media in Google Chrome on Android prior to 147.0.7727.138 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7352</guid>
    <pubDate>Tue, 28 Apr 2026 23:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7352</strong></p>
  <p>Use after free in Media in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7342 – Use after free in WebView in Google Chrome on Android prior to 147.0.7727.138 al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7342</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7342</guid>
    <pubDate>Tue, 28 Apr 2026 23:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7342</strong></p>
  <p>Use after free in WebView in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7342">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-6920 – Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6920</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6920</guid>
    <pubDate>Thu, 23 Apr 2026 18:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-6920</strong></p>
  <p>Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6920">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6756 – Mitigation bypass in Firefox for Android. This vulnerability was fixed in Firefo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6756</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6756</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6756</strong></p>
  <p>Mitigation bypass in Firefox for Android. This vulnerability was fixed in Firefox 150.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6756">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39973 – Apktool is a tool for reverse engineering Android APK files. In versions 3.0.0 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39973</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39973</guid>
    <pubDate>Tue, 21 Apr 2026 02:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39973</strong></p>
  <p>Apktool is a tool for reverse engineering Android APK files. In versions 3.0.0 and 3.0.1, a path traversal vulnerability in `brut/androlib/res/decoder/ResFileDecoder.java` allows a maliciously crafted APK to write arbitrary files to the filesystem during standard decoding (`apktool d`). This is a security regression introduced in commit e10a045 (PR #4041, December 12, 2025), which removed the `Br…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39973">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39866 – Lawnchair is a free, open-source home app for Android. Prior to commit fcba413f5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39866</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39866</guid>
    <pubDate>Tue, 21 Apr 2026 02:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39866</strong></p>
  <p>Lawnchair is a free, open-source home app for Android. Prior to commit fcba413f55dd47f8a3921445252849126c6266b2, command injection in release_update.yml workflow dispatch input allows arbitrary code execution. Commit fcba413f55dd47f8a3921445252849126c6266b2 patches the issue.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39866">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21733 – Vulnerability in Imagination Technologies Graphics DDK on Linux, Android -- 
RES...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21733</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21733</guid>
    <pubDate>Fri, 17 Apr 2026 17:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21733</strong></p>
  <p>Vulnerability in Imagination Technologies Graphics DDK on Linux, Android --  RESERVED</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21733">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6358 – Use after free in XR in Google Chrome on Android prior to 147.0.7727.101 allowed...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6358</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6358</guid>
    <pubDate>Wed, 15 Apr 2026 20:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6358</strong></p>
  <p>Use after free in XR in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6358">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6319 – Use after free in Payments in Google Chrome on Android prior to 147.0.7727.101 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6319</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6319</guid>
    <pubDate>Wed, 15 Apr 2026 20:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6319</strong></p>
  <p>Use after free in Payments in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6319">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6315 – Use after free in Permissions in Google Chrome on Android prior to 147.0.7727.10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6315</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6315</guid>
    <pubDate>Wed, 15 Apr 2026 20:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6315</strong></p>
  <p>Use after free in Permissions in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6315">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35643 – OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35643</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35643</guid>
    <pubDate>Fri, 10 Apr 2026 17:17:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35643</strong></p>
  <p>OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vulnerability allowing attackers to inject arbitrary instructions. Untrusted pages can invoke the canvas bridge to execute malicious code within the Android application context.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-940</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35643">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5777 – This vulnerability exists in the Atom 3x Projector due to improper exposure of t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5777</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5777</guid>
    <pubDate>Fri, 10 Apr 2026 12:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5777</strong></p>
  <p>This vulnerability exists in the Atom 3x Projector due to improper exposure of the Android Debug Bridge (ADB) service over the local network without authentication or access controls. An unauthenticated attacker on the same network can exploit this vulnerability to obtain root-level access, leading to complete compromise of the targeted device.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5777">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-5902 – Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5902</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5902</guid>
    <pubDate>Wed, 08 Apr 2026 22:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-5902</strong></p>
  <p>Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to corrupt media stream metadata via a crafted HTML page. (Chromium security severity: Low)</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5902">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40027 – ALEAPP (Android Logs Events And Protobuf Parser) through 3.4.0 contains a path t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40027</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40027</guid>
    <pubDate>Wed, 08 Apr 2026 22:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40027</strong></p>
  <p>ALEAPP (Android Logs Events And Protobuf Parser) through 3.4.0 contains a path traversal vulnerability in the NQ_Vault.py artifact parser that uses attacker-controlled file_name_from values from a database directly as the output filename, allowing arbitrary file writes outside the report output directory. An attacker can embed a path traversal payload such as ../../../outside_written.bin in the d…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40027">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-69515 – An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-69515</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-69515</guid>
    <pubDate>Tue, 07 Apr 2026 20:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-69515</strong></p>
  <p>An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system into accepting falsified GPS signals as legitimate, resulting in the device reporting an incorrect or static location.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-941</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-69515">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35394 – Mobile Next is an MCP server for mobile development and automation. Prior to 0.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35394</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35394</guid>
    <pubDate>Mon, 06 Apr 2026 21:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35394</strong></p>
  <p>Mobile Next is an MCP server for mobile development and automation. Prior to 0.0.50, the mobile_open_url tool in mobile-mcp passes user-supplied URLs directly to Android's intent system without any scheme validation, allowing execution of arbitrary Android intents, including USSD codes, phone calls, SMS messages, and content provider access. This vulnerability is fixed in 0.0.50.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-939</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35394">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0634 – Code execution in AssistFeedbackService of TECNO Pova7 Pro 5G on Android allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0634</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0634</guid>
    <pubDate>Thu, 02 Apr 2026 09:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0634</strong></p>
  <p>Code execution in AssistFeedbackService of TECNO Pova7 Pro 5G on Android allows local apps to execute arbitrary code as system via command injection.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0634">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-5288 – Use after free in WebView in Google Chrome on Android prior to 146.0.7680.178 al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5288</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5288</guid>
    <pubDate>Wed, 01 Apr 2026 05:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-5288</strong></p>
  <p>Use after free in WebView in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5288">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5278 – Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5278</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5278</guid>
    <pubDate>Wed, 01 Apr 2026 05:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5278</strong></p>
  <p>Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5278">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33976 – Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33976</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33976</guid>
    <pubDate>Fri, 27 Mar 2026 22:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33976</strong></p>
  <p>Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the Web Clipper rendering flow can be escalated to remote code execution in the desktop app. The root cause is that the clipper preserves attacker-controlled attributes from the source page’s root element and stores them inside web-clip HTML. When the clip is later opened, Notesnook r…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33976">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4756 – Out-of-bounds Write vulnerability in MolotovCherry Android-ImageMagick7.This iss...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4756</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4756</guid>
    <pubDate>Tue, 24 Mar 2026 07:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4756</strong></p>
  <p>Out-of-bounds Write vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4756">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-4755 – CWE-20 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects An...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4755</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4755</guid>
    <pubDate>Tue, 24 Mar 2026 07:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-4755</strong></p>
  <p>CWE-20 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4755">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33852 – Missing Release of Memory after Effective Lifetime vulnerability in MolotovCherr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33852</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33852</guid>
    <pubDate>Tue, 24 Mar 2026 07:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33852</strong></p>
  <p>Missing Release of Memory after Effective Lifetime vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33852">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33856 – Missing Release of Memory after Effective Lifetime vulnerability in MolotovCherr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33856</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33856</guid>
    <pubDate>Tue, 24 Mar 2026 06:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33856</strong></p>
  <p>Missing Release of Memory after Effective Lifetime vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33856">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33854 – Out-of-bounds Write vulnerability in MolotovCherry Android-ImageMagick7.This iss...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33854</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33854</guid>
    <pubDate>Tue, 24 Mar 2026 06:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33854</strong></p>
  <p>Out-of-bounds Write vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-10.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33854">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25605 – EquityPandit 1.0 contains an insecure logging vulnerability that allows attacker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25605</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25605</guid>
    <pubDate>Sun, 22 Mar 2026 14:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25605</strong></p>
  <p>EquityPandit 1.0 contains an insecure logging vulnerability that allows attackers to capture sensitive user credentials by accessing developer console logs via Android Debug Bridge. Attackers can use adb logcat to extract plaintext passwords logged during the forgot password function, exposing user account credentials.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-612</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25605">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2378 – ArcSearch for Android versions prior to 1.12.7 could display a different domain ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2378</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2378</guid>
    <pubDate>Fri, 20 Mar 2026 22:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2378</strong></p>
  <p>ArcSearch for Android versions prior to 1.12.7 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2378">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32317 – Cryptomator for Android offers multi-platform transparent client-side encryption...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32317</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32317</guid>
    <pubDate>Fri, 20 Mar 2026 19:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32317</strong></p>
  <p>Cryptomator for Android offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 1.12.3, an integrity check vulnerability allows an attacker tamper with the vault configuration file leading to a man-in-the-middle vulnerability in Hub key loading mechanism. Before this fix, the client trusted endpoints from the vault config without host authenticity checks,…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32317">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4439 – Out of bounds memory access in WebGL in Google Chrome on Android prior to 146.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4439</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4439</guid>
    <pubDate>Fri, 20 Mar 2026 02:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4439</strong></p>
  <p>Out of bounds memory access in WebGL in Google Chrome on Android prior to 146.0.7680.153 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4439">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20990 – Improper export of android application components in Secure Folder prior to SMR ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20990</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20990</guid>
    <pubDate>Mon, 16 Mar 2026 14:18:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20990</strong></p>
  <p>Improper export of android application components in Secure Folder prior to SMR Mar-2026 Release 1 allows local attackers to launch arbitrary activity with Secure Folder privilege.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20990">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3936 – Use after free in WebView in Google Chrome on Android prior to 146.0.7680.71 all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3936</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3936</guid>
    <pubDate>Wed, 11 Mar 2026 22:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3936</strong></p>
  <p>Use after free in WebView in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3936">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3932 – Insufficient policy enforcement in PDF in Google Chrome on Android prior to 146...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3932</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3932</guid>
    <pubDate>Wed, 11 Mar 2026 22:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3932</strong></p>
  <p>Insufficient policy enforcement in PDF in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3932">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3845 – Heap buffer overflow in the Audio/Video: Playback component in Firefox for Andro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3845</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3845</guid>
    <pubDate>Tue, 10 Mar 2026 18:19:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3845</strong></p>
  <p>Heap buffer overflow in the Audio/Video: Playback component in Firefox for Android. This vulnerability was fixed in Firefox 148.0.2.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3845">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-13476 – Rakuten Viber Cloak mode in Android v25.7.2.0g and Windows v25.6.0.0–v25.8.1.0 u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13476</guid>
    <pubDate>Thu, 05 Mar 2026 19:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-13476</strong></p>
  <p>Rakuten Viber Cloak mode in Android v25.7.2.0g and Windows v25.6.0.0–v25.8.1.0 uses a static and predictable TLS ClientHello fingerprint lacking extension diversity, allowing Deep Packet Inspection (DPI) systems to trivially identify and block proxy traffic, undermining censorship circumvention. (CWE-327)</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30798 – Insufficient Verification of Data Authenticity, Improper Handling of Exceptional...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30798</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30798</guid>
    <pubDate>Thu, 05 Mar 2026 16:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30798</strong></p>
  <p>Insufficient Verification of Data Authenticity, Improper Handling of Exceptional Conditions vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Heartbeat sync loop, strategy processing modules) allows Protocol Manipulation. This vulnerability is associated with program files src/hbbs_http/sync.Rs and program routines stop-service handler in hea…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30798">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30797 – Missing Authorization vulnerability in rustdesk-client RustDesk Client rustdesk-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30797</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30797</guid>
    <pubDate>Thu, 05 Mar 2026 16:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30797</strong></p>
  <p>Missing Authorization vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, config import modules) allows Application API Message Manipulation via Man-in-the-Middle. This vulnerability is associated with program files flutter/lib/common.Dart and program routines importConfig() via URI handler.  This issue affects RustD…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-749</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30797">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30795 – Cleartext Transmission of Sensitive Information vulnerability in rustdesk-client...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30795</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30795</guid>
    <pubDate>Thu, 05 Mar 2026 16:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30795</strong></p>
  <p>Cleartext Transmission of Sensitive Information vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Heartbeat sync loop modules) allows Sniffing Attacks. This vulnerability is associated with program files src/hbbs_http/sync.Rs and program routines Heartbeat JSON payload construction (preset-address-book-password).  This issue affects RustDesk…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30795">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30794 – Improper Certificate Validation vulnerability in rustdesk-client RustDesk Client...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30794</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30794</guid>
    <pubDate>Thu, 05 Mar 2026 16:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30794</strong></p>
  <p>Improper Certificate Validation vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (HTTP API client, TLS transport modules) allows Adversary in the Middle (AiTM). This vulnerability is associated with program files src/hbbs_http/http_client.Rs and program routines TLS retry with danger_accept_invalid_certs(true).  This issue affects RustDesk Cl…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30794">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-30793 – Cross-Site Request Forgery (CSRF) vulnerability in rustdesk-client RustDesk Clie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30793</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30793</guid>
    <pubDate>Thu, 05 Mar 2026 16:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-30793</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, FFI bridge modules) allows Privilege Escalation. This vulnerability is associated with program files flutter/lib/common.Dart, src/flutter_ffi.Rs and program routines URI handler for rustdesk://password/, bind.MainSetPermanentPasswor…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30793">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30792 – A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, M...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30792</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30792</guid>
    <pubDate>Thu, 05 Mar 2026 16:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30792</strong></p>
  <p>A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Strategy sync, HTTP API client, config options engine modules) allows Application API Message Manipulation via Man-in-the-Middle. This vulnerability is associated with program files src/hbbs_http/sync.Rs, hbb_common/src/config.Rs and program routines Strategy merge loop in sync.Rs…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-657</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30792">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-30789 – Authentication Bypass by Capture-replay, Use of Password Hash With Insufficient ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30789</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30789</guid>
    <pubDate>Thu, 05 Mar 2026 16:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-30789</strong></p>
  <p>Authentication Bypass by Capture-replay, Use of Password Hash With Insufficient Computational Effort vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Client login, peer authentication modules) allows Reusing Session IDs (aka Session Replay). This vulnerability is associated with program files src/client.Rs and program routines hash_password(…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-294</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30789">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-30783 – A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, M...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30783</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30783</guid>
    <pubDate>Thu, 05 Mar 2026 16:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-30783</strong></p>
  <p>A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Client signaling, API sync loop, config management modules) allows Privilege Abuse. This vulnerability is associated with program files src/rendezvous_mediator.Rs, src/hbbs_http/sync.Rs and program routines API sync loop, api-server config handling.  This issue affects RustDesk Cl…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-602</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30783">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30791 – Use of a Broken or Risky Cryptographic Algorithm vulnerability in rustdesk-clien...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30791</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30791</guid>
    <pubDate>Thu, 05 Mar 2026 15:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30791</strong></p>
  <p>Use of a Broken or Risky Cryptographic Algorithm vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Config import, URI scheme handler, CLI --config modules) allows Retrieve Embedded Sensitive Data. This vulnerability is associated with program files flutter/lib/common.Dart, hbb_common/src/config.Rs and program routines parseRustdesk…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30791">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3537 – Object lifecycle issue in PowerVR in Google Chrome on Android prior to 145.0.763...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3537</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3537</guid>
    <pubDate>Wed, 04 Mar 2026 20:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3537</strong></p>
  <p>Object lifecycle issue in PowerVR in Google Chrome on Android prior to 145.0.7632.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3537">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23233 – In the Linux kernel, the following vulnerability has been resolved:

f2fs: fix t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23233</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23233</guid>
    <pubDate>Wed, 04 Mar 2026 15:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23233</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  f2fs: fix to avoid mapping wrong physical block for swapfile  Xiaolong Guo reported a f2fs bug in bugzilla [1]  [1] https://bugzilla.kernel.org/show_bug.cgi?id=220951  Quoted:  "When using stress-ng's swap stress test on F2FS filesystem with kernel 6.6+, the system experiences data corruption leading to either: 1 dm-verity corru…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23233">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-27510 – Unitree Go2 firmware versions 1.1.7 through 1.1.11, when used with the Unitree G...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27510</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27510</guid>
    <pubDate>Thu, 26 Feb 2026 20:31:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-27510</strong></p>
  <p>Unitree Go2 firmware versions 1.1.7 through 1.1.11, when used with the Unitree Go2 Android application (com.unitree.doggo2), are vulnerable to remote code execution due to missing integrity protection and validation of user-created programmes. The Android application stores programs in a local SQLite database (unitree_go2.db, table dog_programme) and transmits the programme_text content, includin…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27510">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-2800 – Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2800</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2800</guid>
    <pubDate>Tue, 24 Feb 2026 14:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-2800</strong></p>
  <p>Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Firefox 148 and Thunderbird 148.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2800">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2794 – Information disclosure due to uninitialized memory in Firefox and Firefox Focus ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2794</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2794</guid>
    <pubDate>Tue, 24 Feb 2026 14:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2794</strong></p>
  <p>Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 148.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2794">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23194 – In the Linux kernel, the following vulnerability has been resolved:

rust_binder...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23194</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23194</guid>
    <pubDate>Sat, 14 Feb 2026 17:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23194</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  rust_binder: correctly handle FDA objects of length zero  Fix a bug where an empty FDA (fd array) object with 0 fds would cause an out-of-bounds error. The previous implementation used `skip == 0` to mean "this is a pointer fixup", but 0 is also the correct skip length for an empty FDA. If the FDA is at the end of the buffer, th…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23194">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26214 – Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android) version 3.0.8 and prior d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26214</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26214</guid>
    <pubDate>Thu, 12 Feb 2026 16:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26214</strong></p>
  <p>Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android) version 3.0.8 and prior disable TLS hostname verification when HTTPS is enabled (the default configuration). In GalaxyFDSClientImpl.createHttpClient(), the SDK configures Apache HttpClient with SSLSocketFactory.ALLOW_ALL_HOSTNAME_VERIFIER, which accepts any valid TLS certificate regardless of hostname mismatch. Because HTTPS is enabled by def…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-297</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26214">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20983 – Improper export of android application components in Samsung Dialer prior to SMR...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20983</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20983</guid>
    <pubDate>Wed, 04 Feb 2026 07:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20983</strong></p>
  <p>Improper export of android application components in Samsung Dialer prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitrary activity with Samsung Dialer privilege.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20983">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24490 – MobSF is a mobile application security testing tool used. Prior to version 4.4.5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24490</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24490</guid>
    <pubDate>Tue, 27 Jan 2026 01:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24490</strong></p>
  <p>MobSF is a mobile application security testing tool used. Prior to version 4.4.5, a Stored Cross-site Scripting (XSS) vulnerability in MobSF's Android manifest analysis allows an attacker to execute arbitrary JavaScript in the context of a victim's browser session by uploading a malicious APK. The `android:host` attribute from `<data android:scheme="android_secret_code">` elements is rendered in…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24490">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-0906 – Incorrect security UI  in Google Chrome on Android prior to 144.0.7559.59 allowe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0906</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0906</guid>
    <pubDate>Tue, 20 Jan 2026 05:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-0906</strong></p>
  <p>Incorrect security UI  in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-451</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0906">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14317 – In Crazy Bubble Tea mobile application authenticated attacker can obtain persona...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14317</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14317</guid>
    <pubDate>Wed, 14 Jan 2026 14:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14317</strong></p>
  <p>In Crazy Bubble Tea mobile application authenticated attacker can obtain personal information about other users by enumerating a `loyaltyGuestId` parameter. Server does not verify the permissions required to obtain the data.   This issue was fixed in version 915 (Android) and 7.4.1 (iOS).</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-359</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14317">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-50053 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-50053</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-50053</guid>
    <pubDate>Wed, 31 Dec 2025 20:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-50053</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nebelhorn Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App yournewsapp allows Reflected XSS.This issue affects Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App: from n/a through <= 0.8.8.8.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50053">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14809 – ArcSearch for Android versions prior to 1.12.6 could display a different domain ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14809</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14809</guid>
    <pubDate>Fri, 19 Dec 2025 17:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14809</strong></p>
  <p>ArcSearch for Android versions prior to 1.12.6 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14809">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14553 – Exposure of password hashes through an unauthenticated API response in TP-Link T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14553</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14553</guid>
    <pubDate>Tue, 16 Dec 2025 19:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14553</strong></p>
  <p>Exposure of password hashes through an unauthenticated API response in TP-Link Tapo app on iOS and Android for Tapo cameras, allowing attackers to brute force the password in the local network. Issue can be mitigated through mobile application updates. Device firmware remains unchanged.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14553">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-65820 – An issue was discovered in Meatmeet Android Mobile Application 1.1.2.0. An expor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65820</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65820</guid>
    <pubDate>Wed, 10 Dec 2025 21:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-65820</strong></p>
  <p>An issue was discovered in Meatmeet Android Mobile Application 1.1.2.0. An exported activity can be spawned with the mobile application which opens a hidden page. This page, which is not available through the normal flows of the application, contains several devices which can be added to your account, two of which have not been publicly released. As a result of this vulnerability, the attacker ca…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65820">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-63895 – An issue in the Bluetooth firmware of JXL 9 Inch Car Android Double Din Player A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-63895</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-63895</guid>
    <pubDate>Wed, 10 Dec 2025 20:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-63895</strong></p>
  <p>An issue in the Bluetooth firmware of JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted Link Manager Protocol (LMP) packet.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-404</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-63895">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-63896 – An issue in the Bluetooth Human Interface Device (HID) of JXL 9 Inch Car Android...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-63896</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-63896</guid>
    <pubDate>Thu, 04 Dec 2025 21:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-63896</strong></p>
  <p>An issue in the Bluetooth Human Interface Device (HID) of JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to inject arbitrary keystrokes via a spoofed Bluetooth HID device.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-63896">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12385 – Allocation of Resources Without Limits or Throttling, Improper Validation of Spe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12385</guid>
    <pubDate>Wed, 03 Dec 2025 20:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12385</strong></p>
  <p>Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability in The Qt Company Qt on Windows, MacOS, Linux, iOS, Android, x86, ARM, 64 bit, 32 bit allows Excessive Allocation. This issue affects users of the Text component in Qt Quick. Missing validation of the width and height in the <img> tag could cause an application to become unrespon…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10971 – Insecure Storage of Sensitive Information vulnerability in MeetMe on iOS, Androi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10971</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10971</guid>
    <pubDate>Tue, 02 Dec 2025 08:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10971</strong></p>
  <p>Insecure Storage of Sensitive Information vulnerability in MeetMe on iOS, Android allows Retrieve Embedded Sensitive Data. This issue affects MeetMe: through v2.2.5.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-922</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10971">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-56400 – Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-56400</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-56400</guid>
    <pubDate>Mon, 24 Nov 2025 20:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-56400</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, affects the Tuya Smart and Smartlife mobile applications, as well as other third-party applications that integrate the SDK, allows an attacker to link their own Amazon Alexa account to a victim's Tuya account. The applications fail to validate the OAuth state parameter during the…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-56400">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-63434 – The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-63434</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-63434</guid>
    <pubDate>Mon, 24 Nov 2025 17:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-63434</strong></p>
  <p>The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The application downloads and extracts update packages containing executable code without performing a cryptographic integrity or authenticity check on their contents. An attacker who can control the update metadata can serve a malicious package, which the application will accept, extract, and later…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-494</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-63434">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-64741 – Improper authorization handling in Zoom Workplace for Android before version 6.5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64741</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64741</guid>
    <pubDate>Thu, 13 Nov 2025 15:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-64741</strong></p>
  <p>Improper authorization handling in Zoom Workplace for Android before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network access.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64741">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-63289 – Sogexia Android App Compile Affected SDK v35, Max SDK 32 and fixed in v36, was d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-63289</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-63289</guid>
    <pubDate>Wed, 12 Nov 2025 16:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-63289</strong></p>
  <p>Sogexia Android App Compile Affected SDK v35, Max SDK 32 and fixed in v36, was discovered to contain hardcoded encryption keys in the encryption_helper.dart file</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-63289">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12725 – Out of bounds read in WebGPU in Google Chrome on Android prior to 142.0.7444.137...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12725</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12725</guid>
    <pubDate>Mon, 10 Nov 2025 20:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12725</strong></p>
  <p>Out of bounds read in WebGPU in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12725">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-11209 – Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11209</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11209</guid>
    <pubDate>Thu, 06 Nov 2025 22:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-11209</strong></p>
  <p>Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11209">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-27918 – An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27918</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27918</guid>
    <pubDate>Thu, 06 Nov 2025 18:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-27918</strong></p>
  <p>An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7.0.0, AnyDesk for iOS before 7.1.2, and AnyDesk for Android before 8.0.0. It has an integer overflow and resultant heap-based buffer overflow via a UDP packet during processing of an Identity user image within the Discovery feature, or when establishing a connection between any t…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27918">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27917 – An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27917</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27917</guid>
    <pubDate>Thu, 06 Nov 2025 18:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27917</strong></p>
  <p>An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7.0.0, AnyDesk for iOS before 7.1.2, and AnyDesk for Android before 8.0.0. Remote Denial of Service can occur because of incorrect deserialization that results in failed memory allocation and a NULL pointer dereference.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27917">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27916 – An issue was discovered in AnyDesk for Windows before 9.0.6 and AnyDesk for Andr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27916</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27916</guid>
    <pubDate>Thu, 06 Nov 2025 18:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27916</strong></p>
  <p>An issue was discovered in AnyDesk for Windows before 9.0.6 and AnyDesk for Android before 8.0.0. When the connection between two clients is established via an IP address, it is possible to manipulate the data and spoof the AnyDesk ID.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27916">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61121 – Mobile Scanner Android App version 2.12.38 (package name com.glority.everlens), ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61121</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61121</guid>
    <pubDate>Thu, 30 Oct 2025 17:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61121</strong></p>
  <p>Mobile Scanner Android App version 2.12.38 (package name com.glority.everlens), developed by Glority Global Group Ltd., contains a credential leakage vulnerability. Improper handling of cloud service credentials may allow attackers to obtain them and carry out unauthorized actions, such as sensitive information disclosure and abuse of cloud resources. Successful exploitation could result in priva…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-523</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61121">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61120 – AG Life Logger Android App version v1.0.2.72 and before (package name com.donki...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61120</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61120</guid>
    <pubDate>Thu, 30 Oct 2025 17:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61120</strong></p>
  <p>AG Life Logger Android App version v1.0.2.72 and before (package name com.donki.healthy), developed by IO FIT, K.K., contains improper access control vulnerabilities. Exposed credentials in traffic may allow attackers to misuse cloud resources, and predictable verification codes make brute-force account logins feasible. Successful exploitation could result in account compromise, privacy breaches,…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61120">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61119 – Kanova Android App version 1.0.27 (package name com.karelane), developed by Kare...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61119</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61119</guid>
    <pubDate>Thu, 30 Oct 2025 17:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61119</strong></p>
  <p>Kanova Android App version 1.0.27 (package name com.karelane), developed by Karely L.L.C., contains improper access control vulnerabilities. Attackers may gain unauthorized access to user details and obtain group information, including entry codes, by manipulating API request parameters. Successful exploitation could result in privacy breaches, unauthorized group access, and misuse of the platfor…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61119">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61114 – 2nd Line Android App version v1.2.92 and before (package name com.mysecondline.a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61114</guid>
    <pubDate>Thu, 30 Oct 2025 17:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61114</strong></p>
  <p>2nd Line Android App version v1.2.92 and before (package name com.mysecondline.app), developed by AutoBizLine, Inc., contains an improper access control vulnerability in its authentication mechanism. The server only validates the first character of the user_token, enabling attackers to brute force tokens and perform unauthorized queries on other user accounts. Successful exploitation could result…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61114">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
