<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Android OS</title>
  <link>https://cvedaily.com/pages/tags/android.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/android.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Android OS</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:35 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-10510 – Cross-Site Scripting (XSS) in GeniexWebView component in Transsion AI Assistant ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10510</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10510</guid>
    <pubDate>Tue, 02 Jun 2026 03:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10510</strong></p>
  <p>Cross-Site Scripting (XSS) in GeniexWebView component in Transsion AI Assistant Lifestyle application (com.transsion.aiassistantlifestyle) all versions on Android allows remote attacker to execute arbitrary JavaScript in the WebView context via crafted web_action_data URL parameter.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10510">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0072 – In addInputMethodListener of com.android.server.inputmethod.InputMethodManagerSe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0072</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0072</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0072</strong></p>
  <p>In addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0072">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45153 – Nextcloud is an open source content collaboration platform. From version 33.0.0 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45153</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45153</guid>
    <pubDate>Mon, 01 Jun 2026 17:17:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45153</strong></p>
  <p>Nextcloud is an open source content collaboration platform. From version 33.0.0 to before version 33.1.0, after unlocking a locked Android phone the back-button could be used to bypass the Nextcloud Files app PIN. This issue has been patched in version 33.1.0.</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45153">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44698 – Home Assistant is open source home automation software that puts local control a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44698</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44698</guid>
    <pubDate>Fri, 29 May 2026 14:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44698</strong></p>
  <p>Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he Home Assistant Companion apps for Android and iOS expose a JavaScript bridge to the in-app WebView window.externalApp on Android and webkit.messageHandlers.getExternalAuth (alongside revokeExternalAuth and externalBus) on iOS. Two flaws expose th…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44698">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9987 – Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9987</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9987</guid>
    <pubDate>Thu, 28 May 2026 23:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9987</strong></p>
  <p>Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 148.0.7778.216 allowed a local attacker to execute arbitrary code via a malicious file. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9987">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9977 – Insufficient validation of untrusted input in WebShare in Google Chrome on Andro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9977</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9977</guid>
    <pubDate>Thu, 28 May 2026 23:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9977</strong></p>
  <p>Insufficient validation of untrusted input in WebShare in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9977">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9943 – Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9943</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9943</guid>
    <pubDate>Thu, 28 May 2026 23:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9943</strong></p>
  <p>Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9943">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9929 – Inappropriate implementation in WebGL in Google Chrome on Android prior to 148.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9929</guid>
    <pubDate>Thu, 28 May 2026 23:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9929</strong></p>
  <p>Inappropriate implementation in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9921 – Uninitialized Use in WebGL in Google Chrome on Android prior to 148.0.7778.216 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9921</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9921</guid>
    <pubDate>Thu, 28 May 2026 23:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9921</strong></p>
  <p>Uninitialized Use in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin information via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-457</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9921">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-9920 – Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9920</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9920</guid>
    <pubDate>Thu, 28 May 2026 23:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-9920</strong></p>
  <p>Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-457</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9920">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9919 – Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9919</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9919</guid>
    <pubDate>Thu, 28 May 2026 23:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9919</strong></p>
  <p>Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9919">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9917 – Uninitialized Use in WebGL in Google Chrome on Android prior to 148.0.7778.216 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9917</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9917</guid>
    <pubDate>Thu, 28 May 2026 23:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9917</strong></p>
  <p>Uninitialized Use in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-457</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9917">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9912 – Inappropriate implementation in GPU in Google Chrome on Android prior to 148.0.7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9912</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9912</guid>
    <pubDate>Thu, 28 May 2026 23:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9912</strong></p>
  <p>Inappropriate implementation in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9912">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9898 – Insufficient validation of untrusted input in GPU in Google Chrome on Android pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9898</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9898</guid>
    <pubDate>Thu, 28 May 2026 23:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9898</strong></p>
  <p>Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9898">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9892 – Inappropriate implementation in Skia in Google Chrome on Android prior to 148.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9892</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9892</guid>
    <pubDate>Thu, 28 May 2026 23:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9892</strong></p>
  <p>Inappropriate implementation in Skia in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9892">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9889 – Out of bounds read and write in Dawn in Google Chrome on Android prior to 148.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9889</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9889</guid>
    <pubDate>Thu, 28 May 2026 23:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9889</strong></p>
  <p>Out of bounds read and write in Dawn in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9889">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9888 – Use after free in WebView in Google Chrome on Android prior to 148.0.7778.216 al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9888</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9888</guid>
    <pubDate>Thu, 28 May 2026 23:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9888</strong></p>
  <p>Use after free in WebView in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9888">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9876 – Use after free in WebGL in Google Chrome on Android prior to 148.0.7778.216 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9876</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9876</guid>
    <pubDate>Thu, 28 May 2026 23:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9876</strong></p>
  <p>Use after free in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9876">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9875 – Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9875</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9875</guid>
    <pubDate>Thu, 28 May 2026 23:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9875</strong></p>
  <p>Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9875">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9872 – Out of bounds write in GPU in Google Chrome on Android prior to 148.0.7778.216 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9872</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9872</guid>
    <pubDate>Thu, 28 May 2026 23:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9872</strong></p>
  <p>Out of bounds write in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9872">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10020 – Insufficient validation of untrusted input in Skia in Google Chrome on Android p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10020</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10020</guid>
    <pubDate>Thu, 28 May 2026 23:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10020</strong></p>
  <p>Insufficient validation of untrusted input in Skia in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10020">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10014 – Use after free in WebMIDI in Google Chrome on Android prior to 148.0.7778.216 al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10014</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10014</guid>
    <pubDate>Thu, 28 May 2026 23:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10014</strong></p>
  <p>Use after free in WebMIDI in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10014">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10010 – Inappropriate implementation in Input in Google Chrome on Android prior to 148.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10010</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10010</guid>
    <pubDate>Thu, 28 May 2026 23:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10010</strong></p>
  <p>Inappropriate implementation in Input in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10010">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10008 – Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10008</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10008</guid>
    <pubDate>Thu, 28 May 2026 23:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10008</strong></p>
  <p>Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-457</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10008">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-68712 – SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68712</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68712</guid>
    <pubDate>Wed, 27 May 2026 17:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-68712</strong></p>
  <p>SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerprint or PIN authentication. Although the app integrates Android's biometric mechanisms, the lock is implemented with a custom overlay that fails to consistently enforce authentication. By navigating cascading interface flows - insecure navigation through exposed routes facilitat…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68712">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42184 – Tauri is a framework for building binaries for all major desktop platforms. From...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42184</guid>
    <pubDate>Wed, 27 May 2026 15:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42184</strong></p>
  <p>Tauri is a framework for building binaries for all major desktop platforms. From 2.0 to 2.11.0, a flaw in Tauri's is_local_url() function causes it to incorrectly classify remote URLs as trusted local origins on Windows and Android. On these systems, Tauri maps custom URI scheme protocols to http://<scheme>.localhost/ because those platforms' WebView implementations cannot serve custom URI scheme…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-68711 – AppLockZ App Lock and Fingerprint Lock (applock.passwordfingerprint.applockz) 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68711</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68711</guid>
    <pubDate>Tue, 26 May 2026 21:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-68711</strong></p>
  <p>AppLockZ App Lock and Fingerprint Lock (applock.passwordfingerprint.applockz) 4.2.11 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's secure authentication APIs. By navigating cascading interface flows - insecure navigation through exposed routes facilitates app control evasion {I.N.T.E.R.F.A.C.E]…</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68711">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-68708 – SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68708</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68708</guid>
    <pubDate>Tue, 26 May 2026 21:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-68708</strong></p>
  <p>SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's secure authentication APIs. By navigating cascading interface flows - insecure navigation through exposed routes facilitates app control evasion {I.N.T.E.R.F.A.C.E] via advertisement or browser intent…</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68708">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-68710 – Easyelife App lock (aka Fingerprint,Applock or locker.app.safe.applocker) 1.9.2 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68710</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68710</guid>
    <pubDate>Tue, 26 May 2026 20:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-68710</strong></p>
  <p>Easyelife App lock (aka Fingerprint,Applock or locker.app.safe.applocker) 1.9.2 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's secure authentication APIs. By navigating cascading interface flows - insecure navigation through exposed routes facilitates app control evasion {I.N.T.E.R.F.A.C.E] via…</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68710">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-68709 – SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68709</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68709</guid>
    <pubDate>Tue, 26 May 2026 20:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-68709</strong></p>
  <p>SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker to trigger arbitrary JavaScript execution via BrowserMainActivity, which accepts VIEW intents with javascript: URIs. This unsafe navigation path results in script execution and may allow UI spoofing or privilege escalation.</p>
  <p><strong>CVSS:</strong> 5.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68709">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-47782 – Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handles ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47782</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47782</guid>
    <pubDate>Wed, 20 May 2026 23:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-47782</strong></p>
  <p>Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handles Android intents without sufficient URL validation, user confirmation nor notification. If a URL to some malicious web page is given through an intent, RoboForm may silently download files without user confirmation nor notification.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-357</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47782">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9123 – Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9123</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9123</guid>
    <pubDate>Wed, 20 May 2026 20:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9123</strong></p>
  <p>Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148.0.7778.179 allowed a local attacker to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9123">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8951 – Spoofing issue in the Toolbar component in Firefox for Android. This vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8951</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8951</guid>
    <pubDate>Tue, 19 May 2026 14:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8951</strong></p>
  <p>Spoofing issue in the Toolbar component in Firefox for Android. This vulnerability was fixed in Firefox 151.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8951">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8945 – Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8945</guid>
    <pubDate>Tue, 19 May 2026 14:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8945</strong></p>
  <p>Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8583 – Insufficient policy enforcement in WebXR in Google Chrome on Android prior to 14...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8583</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8583</guid>
    <pubDate>Thu, 14 May 2026 20:17:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8583</strong></p>
  <p>Insufficient policy enforcement in WebXR in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8583">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-8572 – Insufficient policy enforcement in Network in Google Chrome on Android prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8572</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8572</guid>
    <pubDate>Thu, 14 May 2026 20:17:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-8572</strong></p>
  <p>Insufficient policy enforcement in Network in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8572">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8571 – Insufficient policy enforcement in GPU in Google Chrome on Android prior to 148...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8571</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8571</guid>
    <pubDate>Thu, 14 May 2026 20:17:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8571</strong></p>
  <p>Insufficient policy enforcement in GPU in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8571">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8566 – Insufficient policy enforcement in Payments in Google Chrome on Android prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8566</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8566</guid>
    <pubDate>Thu, 14 May 2026 20:17:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8566</strong></p>
  <p>Insufficient policy enforcement in Payments in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8566">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8564 – Incorrect security UI in Downloads in Google Chrome on Android and Mac prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8564</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8564</guid>
    <pubDate>Thu, 14 May 2026 20:17:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8564</strong></p>
  <p>Incorrect security UI in Downloads in Google Chrome on Android and Mac prior to 148.0.7778.168 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-451</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8564">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8552 – Heap buffer overflow in GPU in Google Chrome on Android prior to 148.0.7778.168 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8552</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8552</guid>
    <pubDate>Thu, 14 May 2026 20:17:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8552</strong></p>
  <p>Heap buffer overflow in GPU in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8552">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8539 – Script injection in SanitizerAPI in Google Chrome on Android prior to 148.0.7778...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8539</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8539</guid>
    <pubDate>Thu, 14 May 2026 20:17:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8539</strong></p>
  <p>Script injection in SanitizerAPI in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8539">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8513 – Use after free in Input in Google Chrome on Android prior to 148.0.7778.168 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8513</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8513</guid>
    <pubDate>Thu, 14 May 2026 20:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8513</strong></p>
  <p>Use after free in Input in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8513">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-41281 – Android App "あんしんフィルター for au" provided by KDDI CORPORATION contains Cleartext T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41281</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41281</guid>
    <pubDate>Thu, 14 May 2026 00:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-41281</strong></p>
  <p>Android App "あんしんフィルター for au" provided by KDDI CORPORATION contains Cleartext Transmission of Sensitive Information (CWE-319) vulnerability. A man-in-the-middle attacker may access and modify communications transmitted in plaintext, potentially resulting in information disclosure or data tampering.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41281">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0251 – Multiple local privilege escalation vulnerabilities in the Palo Alto Networks Gl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0251</guid>
    <pubDate>Wed, 13 May 2026 19:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0251</strong></p>
  <p>Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allow a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges.  The GlobalProtect app on iOS, Android, Chrome OS and GlobalProtect UWP app are not affect…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0248 – An improper certificate validation vulnerability in the Prisma Access Agent® for...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0248</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0248</guid>
    <pubDate>Wed, 13 May 2026 19:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0248</strong></p>
  <p>An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. By presenting a certificate for any domain issued by a trusted Certificate Authority, the attacker can capture sensitive device information.    The Prisma Access Agent on macOS, Windows, Linux and iOS are…</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0248">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0246 – A vulnerability with a privilege management mechanism in the Palo Alto Networks ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0246</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0246</guid>
    <pubDate>Wed, 13 May 2026 19:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0246</strong></p>
  <p>A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a locally authenticated non-administrative user to escalate their privileges to root on macOS and Linux or NT AUTHORITY\SYSTEM on Windows. This allows the user to execute arbitrary code and read sensitive information otherwise accessible only to privileged accounts.    The Prisma Access Ag…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0246">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0245 – Multiple information disclosure vulnerabilities in Prisma Access Agent® allow a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0245</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0245</guid>
    <pubDate>Wed, 13 May 2026 19:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0245</strong></p>
  <p>Multiple information disclosure vulnerabilities in Prisma Access Agent® allow a local user to access sensitive configuration data and credentials.    The Prisma Access Agent on Linux, ChromeOS, Android, and iOS are not affected.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0245">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2026-43488 – In the Linux kernel, the following vulnerability has been resolved:

usb: xhci: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43488</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43488</guid>
    <pubDate>Wed, 13 May 2026 16:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2026-43488</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  usb: xhci: Prevent interrupt storm on host controller error (HCE)  The xHCI controller reports a Host Controller Error (HCE) in UAS Storage Device plug/unplug scenarios on Android devices. HCE is checked in xhci_irq() function and causes an interrupt storm (since the interrupt isn’t cleared), leading to severe system-level fault…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43488">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21020 – Improper export of android application components in OmaCP prior to SMR May-2026...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21020</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21020</guid>
    <pubDate>Wed, 13 May 2026 06:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21020</strong></p>
  <p>Improper export of android application components in OmaCP prior to SMR May-2026 Release 1 allows local attackers to trigger privileged functions.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21020">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44279 – A improper export of android application components vulnerability in Fortinet Fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44279</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44279</guid>
    <pubDate>Tue, 12 May 2026 18:17:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44279</strong></p>
  <p>A improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions, FortiTokenAndroid 5.2 all versions may allow attacker to improper access control via <insert attack vector here></p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-926</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44279">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33362 – In Meari IoT SDK builds embedded in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33362</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33362</guid>
    <pubDate>Mon, 11 May 2026 17:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33362</strong></p>
  <p>In Meari IoT SDK builds embedded in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and white-label Android apps <= 1.8.x (latest observed), multiple security-critical secrets are hardcoded and shared, including API signing material, password-transport keying, and service access keys.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33362">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-43439 – In the Linux kernel, the following vulnerability has been resolved:

cgroup: fix...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43439</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43439</guid>
    <pubDate>Fri, 08 May 2026 15:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-43439</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  cgroup: fix race between task migration and iteration  When a task is migrated out of a css_set, cgroup_migrate_add_task() first moves it from cset->tasks to cset->mg_tasks via:      list_move_tail(&task->cg_list, &cset->mg_tasks);  If a css_task_iter currently has it->task_pos pointing to this task, css_set_move_task() calls cs…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43439">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-30496 – The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30496</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30496</guid>
    <pubDate>Thu, 07 May 2026 14:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-30496</strong></p>
  <p>The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes an HTTP API on TCP port 2345 that allows full unauthenticated remote control of the device. The API supports both reading configuration (74 endpoints) and writing/modifying settings including volume, mute, brightness, power, network protocols enable/disable (including TELNET), display modes, and other projector…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30496">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30495 – The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30495</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30495</guid>
    <pubDate>Thu, 07 May 2026 14:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30495</strong></p>
  <p>The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes Android Debug Bridge (ADB) on TCP port 5555 over the network without requiring authentication. The device is configured with ro.adb.secure=0, which disables RSA key verification. Additionally, a functional su binary exists at /system/xbin/su that grants root privileges without authentication. An attacker on the…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30495">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3291 – Samsung Print Service Plugin for Android is potentially vulnerable to informatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3291</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3291</guid>
    <pubDate>Wed, 06 May 2026 22:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3291</strong></p>
  <p>Samsung Print Service Plugin for Android is potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices. HP is releasing updates to mitigate these potential vulnerabilities.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-926</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3291">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8020 – Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.96 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8020</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8020</guid>
    <pubDate>Wed, 06 May 2026 19:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8020</strong></p>
  <p>Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-457</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8020">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7993 – Insufficient validation of untrusted input in Payments in Google Chrome on Andro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7993</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7993</guid>
    <pubDate>Wed, 06 May 2026 19:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7993</strong></p>
  <p>Insufficient validation of untrusted input in Payments in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7993">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7941 – Insufficient validation of untrusted input in Mobile in Google Chrome on Android...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7941</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7941</guid>
    <pubDate>Wed, 06 May 2026 19:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7941</strong></p>
  <p>Insufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 148.0.7778.96 allowed a local attacker to inject arbitrary scripts or HTML (UXSS) via a crafted Chrome Extension. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7941">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7915 – Insufficient data validation in DevTools in Google Chrome on Android prior to 14...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7915</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7915</guid>
    <pubDate>Wed, 06 May 2026 19:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7915</strong></p>
  <p>Insufficient data validation in DevTools in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7915">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7913 – Insufficient policy enforcement in DevTools in Google Chrome on Android prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7913</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7913</guid>
    <pubDate>Wed, 06 May 2026 19:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7913</strong></p>
  <p>Insufficient policy enforcement in DevTools in Google Chrome on Android prior to 148.0.7778.96 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7913">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7912 – Integer overflow in GPU in Google Chrome on Android prior to 148.0.7778.96 allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7912</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7912</guid>
    <pubDate>Wed, 06 May 2026 19:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7912</strong></p>
  <p>Integer overflow in GPU in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7912">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7905 – Insufficient validation of untrusted input in Media in Google Chrome on Android ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7905</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7905</guid>
    <pubDate>Wed, 06 May 2026 19:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7905</strong></p>
  <p>Insufficient validation of untrusted input in Media in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7905">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42090 – Notesnook is a note-taking app focused on user privacy &amp; ease of use. Prior to N...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42090</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42090</guid>
    <pubDate>Mon, 04 May 2026 17:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42090</strong></p>
  <p>Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and prior to Notesnook iOS/Android version 3.3.20, a stored XSS vulnerability in the note export flow can be escalated to remote code execution in the desktop app. The root cause is that exported note fields such as title, headline, and content are inserted into the generated HTML t…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42090">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-7671 – A vulnerability has been found in CodeWise Tornet Scooter Mobile App 4.75 on iOS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7671</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7671</guid>
    <pubDate>Sun, 03 May 2026 00:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-7671</strong></p>
  <p>A vulnerability has been found in CodeWise Tornet Scooter Mobile App 4.75 on iOS/Android. The impacted element is an unknown function of the file /TwoFactor. Such manipulation leads to improper restriction of excessive authentication attempts. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is regarded as difficult. The exploit has been discl…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7671">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7638 – The App Builder – Create Native Android &amp; iOS Apps On The Flight plugin for Word...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7638</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7638</guid>
    <pubDate>Sat, 02 May 2026 04:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7638</strong></p>
  <p>The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Insecure Direct Object Reference  in all versions up to and including 5.6.0. This is due to missing authorization validation in the `upload_avatar()` function, which accepts an attacker-controlled `user_id` parameter from the POST request body and uses it to update user meta without verifying th…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7638">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-23866 – Incomplete validation of AI rich response messages for Instagram Reels in WhatsA...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23866</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23866</guid>
    <pubDate>Fri, 01 May 2026 16:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-23866</strong></p>
  <p>Incomplete validation of AI rich response messages for Instagram Reels in WhatsApp for iOS v2.25.8.0 to v2.26.15.72 and WhatsApp for Android v2.25.8.0 to v2.26.7.10 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device, including triggering OS-controlled custom URL scheme handlers. We have not seen evidence of exploitation in the wild.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-940</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23866">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7352 – Use after free in Media in Google Chrome on Android prior to 147.0.7727.138 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7352</guid>
    <pubDate>Tue, 28 Apr 2026 23:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7352</strong></p>
  <p>Use after free in Media in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7342 – Use after free in WebView in Google Chrome on Android prior to 147.0.7727.138 al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7342</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7342</guid>
    <pubDate>Tue, 28 Apr 2026 23:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7342</strong></p>
  <p>Use after free in WebView in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7342">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-6920 – Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6920</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6920</guid>
    <pubDate>Thu, 23 Apr 2026 18:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-6920</strong></p>
  <p>Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6920">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6756 – Mitigation bypass in Firefox for Android. This vulnerability was fixed in Firefo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6756</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6756</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6756</strong></p>
  <p>Mitigation bypass in Firefox for Android. This vulnerability was fixed in Firefox 150.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6756">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39973 – Apktool is a tool for reverse engineering Android APK files. In versions 3.0.0 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39973</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39973</guid>
    <pubDate>Tue, 21 Apr 2026 02:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39973</strong></p>
  <p>Apktool is a tool for reverse engineering Android APK files. In versions 3.0.0 and 3.0.1, a path traversal vulnerability in `brut/androlib/res/decoder/ResFileDecoder.java` allows a maliciously crafted APK to write arbitrary files to the filesystem during standard decoding (`apktool d`). This is a security regression introduced in commit e10a045 (PR #4041, December 12, 2025), which removed the `Br…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39973">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39866 – Lawnchair is a free, open-source home app for Android. Prior to commit fcba413f5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39866</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39866</guid>
    <pubDate>Tue, 21 Apr 2026 02:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39866</strong></p>
  <p>Lawnchair is a free, open-source home app for Android. Prior to commit fcba413f55dd47f8a3921445252849126c6266b2, command injection in release_update.yml workflow dispatch input allows arbitrary code execution. Commit fcba413f55dd47f8a3921445252849126c6266b2 patches the issue.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39866">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21733 – Vulnerability in Imagination Technologies Graphics DDK on Linux, Android -- 
RES...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21733</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21733</guid>
    <pubDate>Fri, 17 Apr 2026 17:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21733</strong></p>
  <p>Vulnerability in Imagination Technologies Graphics DDK on Linux, Android --  RESERVED</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21733">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6358 – Use after free in XR in Google Chrome on Android prior to 147.0.7727.101 allowed...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6358</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6358</guid>
    <pubDate>Wed, 15 Apr 2026 20:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6358</strong></p>
  <p>Use after free in XR in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6358">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6319 – Use after free in Payments in Google Chrome on Android prior to 147.0.7727.101 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6319</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6319</guid>
    <pubDate>Wed, 15 Apr 2026 20:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6319</strong></p>
  <p>Use after free in Payments in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6319">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6315 – Use after free in Permissions in Google Chrome on Android prior to 147.0.7727.10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6315</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6315</guid>
    <pubDate>Wed, 15 Apr 2026 20:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6315</strong></p>
  <p>Use after free in Permissions in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6315">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35643 – OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35643</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35643</guid>
    <pubDate>Fri, 10 Apr 2026 17:17:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35643</strong></p>
  <p>OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vulnerability allowing attackers to inject arbitrary instructions. Untrusted pages can invoke the canvas bridge to execute malicious code within the Android application context.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-940</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35643">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5777 – This vulnerability exists in the Atom 3x Projector due to improper exposure of t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5777</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5777</guid>
    <pubDate>Fri, 10 Apr 2026 12:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5777</strong></p>
  <p>This vulnerability exists in the Atom 3x Projector due to improper exposure of the Android Debug Bridge (ADB) service over the local network without authentication or access controls. An unauthenticated attacker on the same network can exploit this vulnerability to obtain root-level access, leading to complete compromise of the targeted device.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5777">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-5906 – Incorrect security UI in Omnibox in Google Chrome on Android prior to 147.0.7727...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5906</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5906</guid>
    <pubDate>Wed, 08 Apr 2026 22:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-5906</strong></p>
  <p>Incorrect security UI in Omnibox in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-451</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5906">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-5902 – Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5902</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5902</guid>
    <pubDate>Wed, 08 Apr 2026 22:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-5902</strong></p>
  <p>Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to corrupt media stream metadata via a crafted HTML page. (Chromium security severity: Low)</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5902">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40027 – ALEAPP (Android Logs Events And Protobuf Parser) through 3.4.0 contains a path t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40027</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40027</guid>
    <pubDate>Wed, 08 Apr 2026 22:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40027</strong></p>
  <p>ALEAPP (Android Logs Events And Protobuf Parser) through 3.4.0 contains a path traversal vulnerability in the NQ_Vault.py artifact parser that uses attacker-controlled file_name_from values from a database directly as the output filename, allowing arbitrary file writes outside the report output directory. An attacker can embed a path traversal payload such as ../../../outside_written.bin in the d…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40027">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-69515 – An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-69515</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-69515</guid>
    <pubDate>Tue, 07 Apr 2026 20:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-69515</strong></p>
  <p>An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system into accepting falsified GPS signals as legitimate, resulting in the device reporting an incorrect or static location.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-941</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-69515">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35394 – Mobile Next is an MCP server for mobile development and automation. Prior to 0.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35394</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35394</guid>
    <pubDate>Mon, 06 Apr 2026 21:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35394</strong></p>
  <p>Mobile Next is an MCP server for mobile development and automation. Prior to 0.0.50, the mobile_open_url tool in mobile-mcp passes user-supplied URLs directly to Android's intent system without any scheme validation, allowing execution of arbitrary Android intents, including USSD codes, phone calls, SMS messages, and content provider access. This vulnerability is fixed in 0.0.50.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-939</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35394">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-5682 – A vulnerability has been found in Meesho Online Shopping App up to 27.3 on Andro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5682</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5682</guid>
    <pubDate>Mon, 06 Apr 2026 20:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-5682</strong></p>
  <p>A vulnerability has been found in Meesho Online Shopping App up to 27.3 on Android. Affected is an unknown function of the file /api/endpoint of the component com.meesho.supply. Such manipulation leads to risky cryptographic algorithm. The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-310</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5682">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-5471 – A vulnerability was detected in Investory Toy Planet Trouble App up to 1.5.5 on ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5471</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5471</guid>
    <pubDate>Fri, 03 Apr 2026 16:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-5471</strong></p>
  <p>A vulnerability was detected in Investory Toy Planet Trouble App up to 1.5.5 on Android. Impacted is an unknown function of the file assets/google-services-desktop.json of the component app.investory.toyfactory. The manipulation of the argument current_key results in use of hard-coded cryptographic key . The attack must be initiated from a local position. The exploit is now public and may be use…</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-320</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5471">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-5462 – A vulnerability was identified in Wahoo Fitness SYSTM App up to 7.2.1 on Android...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5462</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5462</guid>
    <pubDate>Fri, 03 Apr 2026 08:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-5462</strong></p>
  <p>A vulnerability was identified in Wahoo Fitness SYSTM App up to 7.2.1 on Android. Impacted is an unknown function of the file com/WahooFitness/SYSTM/BuildConfig.java of the component com.WahooFitness.SYSTM. Such manipulation of the argument SEGMENT_WRITE_KEY leads to use of hard-coded cryptographic key . Local access is required to approach this attack. The exploit is publicly available and migh…</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-320</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5462">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-5458 – A weakness has been identified in Noelse Individuals &amp; Pro App up to 2.1.7 on An...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5458</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5458</guid>
    <pubDate>Fri, 03 Apr 2026 07:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-5458</strong></p>
  <p>A weakness has been identified in Noelse Individuals & Pro App up to 2.1.7 on Android. This impacts an unknown function of the file com/reactnative/antelop/BuildConfig.java of the component com.afone.noelse. This manipulation of the argument SEGMENT_WRITE_KEY causes use of hard-coded cryptographic key . The attack needs to be launched locally. The exploit has been made available to the public an…</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-320</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5458">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-5457 – A security flaw has been discovered in PropertyGuru AgentNet Singapore App up to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5457</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5457</guid>
    <pubDate>Fri, 03 Apr 2026 07:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-5457</strong></p>
  <p>A security flaw has been discovered in PropertyGuru AgentNet Singapore App up to 23.7.10 on Android. This affects an unknown function of the file com/allproperty/android/agentnet/BuildConfig.java of the component com.allproperty.android.agentnet. The manipulation of the argument SEGMENT_ANDROID_WRITE_KEY/SEGMENT_TOS_WRITE_KEY results in use of hard-coded cryptographic key . The attack must be in…</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-320</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5457">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-5456 – A vulnerability was identified in Align Technology My Invisalign App 3.12.4 on A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5456</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5456</guid>
    <pubDate>Fri, 03 Apr 2026 07:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-5456</strong></p>
  <p>A vulnerability was identified in Align Technology My Invisalign App 3.12.4 on Android. The impacted element is an unknown function of the file com/aligntech/myinvisalign/BuildConfig.java of the component com.aligntech.myinvisalign.emea. The manipulation of the argument CDAACCESS_TOKEN leads to use of hard-coded cryptographic key . The attack must be carried out locally. The exploit is publicly…</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-320</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5456">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-5455 – A vulnerability was determined in Dialogue App up to 4.3.2 on Android. The affec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5455</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5455</guid>
    <pubDate>Fri, 03 Apr 2026 07:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-5455</strong></p>
  <p>A vulnerability was determined in Dialogue App up to 4.3.2 on Android. The affected element is an unknown function of the file file res/raw/config.json of the component ca.diagram.dialogue. Executing a manipulation of the argument SEGMENT_WRITE_KEY can lead to use of hard-coded cryptographic key . The attack is restricted to local execution. The exploit has been publicly disclosed and may be uti…</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-320</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5455">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-5454 – A vulnerability was found in GRID Organiser App up to 1.0.5 on Android. Impacted...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5454</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5454</guid>
    <pubDate>Fri, 03 Apr 2026 05:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-5454</strong></p>
  <p>A vulnerability was found in GRID Organiser App up to 1.0.5 on Android. Impacted is an unknown function of the file file res/raw/app.json of the component co.gridapp.organiser. Performing a manipulation of the argument SegmentWriteKey results in use of hard-coded cryptographic key . The attack is only possible with local access. The exploit has been made public and could be used.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-320</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5454">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-5453 – A vulnerability has been found in Rico só vantagem pra investir App up to 4.58.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5453</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5453</guid>
    <pubDate>Fri, 03 Apr 2026 05:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-5453</strong></p>
  <p>A vulnerability has been found in Rico só vantagem pra investir App up to 4.58.32.12421 on Android. This issue affects some unknown processing of the file br/com/rico/mobile/di/SegmentSettingsModule.java of the component br.com.rico.mobile. Such manipulation of the argument SEGMENT_WRITE_KEY leads to use of hard-coded cryptographic key . The attack can only be performed from a local environment.…</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-320</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5453">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-5452 – A flaw has been found in UCC CampusConnect App up to 14.3.5 on Android. This vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5452</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5452</guid>
    <pubDate>Fri, 03 Apr 2026 04:17:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-5452</strong></p>
  <p>A flaw has been found in UCC CampusConnect App up to 14.3.5 on Android. This vulnerability affects unknown code of the file campusconnect/BuildConfig.java of the component campusconnect.ucc. This manipulation causes use of hard-coded cryptographic key . The attack can only be executed locally. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-320</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5452">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0634 – Code execution in AssistFeedbackService of TECNO Pova7 Pro 5G on Android allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0634</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0634</guid>
    <pubDate>Thu, 02 Apr 2026 09:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0634</strong></p>
  <p>Code execution in AssistFeedbackService of TECNO Pova7 Pro 5G on Android allows local apps to execute arbitrary code as system via command injection.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0634">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33978 – Notesnook is a note-taking app focused on user privacy &amp; ease of use. Prior to v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33978</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33978</guid>
    <pubDate>Wed, 01 Apr 2026 17:28:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33978</strong></p>
  <p>Notesnook is a note-taking app focused on user privacy & ease of use. Prior to version 3.3.17, a stored XSS vulnerability exists in the mobile share / web clip flow because attacker-controlled clip metadata is concatenated into HTML without escaping and then rendered with innerHTML inside the mobile share editor WebView. An attacker can control the shared title metadata (for example through Andro…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33978">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-5288 – Use after free in WebView in Google Chrome on Android prior to 146.0.7680.178 al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5288</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5288</guid>
    <pubDate>Wed, 01 Apr 2026 05:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-5288</strong></p>
  <p>Use after free in WebView in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5288">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5278 – Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5278</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5278</guid>
    <pubDate>Wed, 01 Apr 2026 05:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5278</strong></p>
  <p>Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5278">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-23400 – In the Linux kernel, the following vulnerability has been resolved:

rust_binder...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23400</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23400</guid>
    <pubDate>Sun, 29 Mar 2026 13:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-23400</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  rust_binder: call set_notification_done() without proc lock  Consider the following sequence of events on a death listener: 1. The remote process dies and sends a BR_DEAD_BINDER message. 2. The local process invokes the BC_CLEAR_DEATH_NOTIFICATION command. 3. The local process then invokes the BC_DEAD_BINDER_DONE. Then, the kern…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-667</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23400">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33976 – Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33976</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33976</guid>
    <pubDate>Fri, 27 Mar 2026 22:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33976</strong></p>
  <p>Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the Web Clipper rendering flow can be escalated to remote code execution in the desktop app. The root cause is that the clipper preserves attacker-controlled attributes from the source page’s root element and stores them inside web-clip HTML. When the clip is later opened, Notesnook r…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33976">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33045 – Home Assistant is open source home automation software that puts local control a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33045</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33045</guid>
    <pubDate>Fri, 27 Mar 2026 20:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33045</strong></p>
  <p>Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2025.02 and prior to version 2026.01 the "remaining charge time"-sensor for mobile phones (imported/included from Android Auto it appears) is vulnerable cross-site scripting, similar to CVE-2025-62172. Version 2026.01 fixes the issue.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33045">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
