|
581
|
4.0 |
MEDIUM
Local
|
google
|
android
|
In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a logic error in the code. This could lead to local with null execution privileg…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-28581
|
2026-06-3 22:29 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
582
|
3.3 |
LOW
Local
|
google
|
android
|
In multiple functions of AppOpsService.java, there is a possible missing permission check due to a permissions bypass. This could lead to local information disclosure with no additional execution pri…
New
|
CWE-269
Improper Privilege Management
|
CVE-2026-28586
|
2026-06-3 22:26 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
583
|
8.0 |
HIGH
Adjacent
|
-
|
-
|
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and…
Update
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2026-3012
|
2026-06-3 15:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
584
|
8.8 |
HIGH
Network
|
-
|
-
|
@pensar/apex <= 0.0.58 is vulnerable to OS command injection via the smart_enumerate tool. The createSmartEnumerateTool() function in src/core/agent/tools.ts constructs a shell command by concatenati…
Update
|
CWE-78
OS Command
|
CVE-2026-36044
|
2026-06-3 13:17 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
585
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in Passwords in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafte…
Update
|
CWE-416
Use After Free
|
CVE-2026-10000
|
2026-06-3 11:32 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
586
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromi…
Update
|
CWE-457
Use of Uninitialized Variable
|
CVE-2026-10008
|
2026-06-3 11:31 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
587
|
5.0 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Input in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTM…
Update
|
CWE-346
Origin Validation Error
|
CVE-2026-10010
|
2026-06-3 11:31 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
588
|
3.1 |
LOW
Network
|
google
|
chrome
|
Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Ch…
Update
|
CWE-200
Information Exposure
|
CVE-2026-10011
|
2026-06-3 11:30 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
589
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Out of bounds read in Headless in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML p…
Update
|
CWE-125
Out-of-bounds Read
|
CVE-2026-10017
|
2026-06-3 11:30 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
590
|
9.0 |
CRITICAL
Network
|
google
|
chrome
|
Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a cra…
Update
|
CWE-416
Use After Free
|
CVE-2026-9881
|
2026-06-3 11:30 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|