Complete feed
No mitigation yet
No fix, workaround or mitigation extracted yet
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-19141] Sandbox escape due to use-after-free vulnerability
Sandbox escape due to use-after-free vulnerability. Red Hat rates this important (CVSS 8.2). Weakness: CWE-825.
High [CVE-2026-19138] Sandbox escape via heap buffer overflow in CrashReporting
Sandbox escape via heap buffer overflow in CrashReporting. Red Hat rates this important (CVSS 8.3). Weakness: CWE-120.
High [CVE-2026-19168] Arbitrary Code Execution via crafted HTML page
Arbitrary Code Execution via crafted HTML page. Red Hat rates this important (CVSS 8.8). Weakness: CWE-823.
High [CVE-2026-19169] Privilege escalation via crafted HTML page in Contextual Tasks
Privilege escalation via crafted HTML page in Contextual Tasks. Red Hat rates this important (CVSS 8.3). Weakness: CWE-79.
High [CVE-2026-19172] Sandbox escape via use after free in Views
Sandbox escape via use after free in Views. Red Hat rates this important (CVSS 8.2). Weakness: CWE-825.
High [CVE-2026-19170] Sandbox escape via use after free in WebGL
Sandbox escape via use after free in WebGL. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.
High [CVE-2026-19157] Sandbox escape via out-of-bounds write in Google Chrome on Android
Sandbox escape via out-of-bounds write in Google Chrome on Android. Red Hat rates this important (CVSS 8.4). Weakness: CWE-787.
High [CVE-2026-19149] Sandbox escape via use-after-free vulnerability in Aura
Sandbox escape via use-after-free vulnerability in Aura. Red Hat rates this important (CVSS 8.3). Weakness: CWE-825.
High [CVE-2026-34502] Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3.
High [CVE-2026-68480] Safe RET Interrupt Vulnerability
Safe RET Interrupt Vulnerability. Red Hat rates this important (CVSS 8.8). Weakness: CWE-201. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-71498] Information disclosure via out-of-bounds read with malformed UTF-8 input
Information disclosure via out-of-bounds read with malformed UTF-8 input. Red Hat rates this moderate (CVSS 5.1). Weakness: CWE-125.
Medium [CVE-2026-19167] Cross-origin data leakage via integer overflow in GPU
Cross-origin data leakage via integer overflow in GPU. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-190.
Medium [CVE-2026-19146] Google Chrome (Android): Information disclosure via uninitialized GPU memory use
Google Chrome (Android): Information disclosure via uninitialized GPU memory use. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-824.
Medium [CVE-2026-19139] OS-level privilege escalation due to a race condition via a malicious file
OS-level privilege escalation due to a race condition via a malicious file. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-367.
Medium [CVE-2026-71439] Denial of Service via Radar Diagrams 'ticks' parameter
Denial of Service via Radar Diagrams 'ticks' parameter. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1050.
Medium [CVE-2026-50159] CSS injection allows altering page elements via diagram input
CSS injection allows altering page elements via diagram input. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-79.
Medium [CVE-2026-64654] Terminal escape sequence injection allows command execution
Terminal escape sequence injection allows command execution. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-78.
Medium [CVE-2026-64653] Path traversal via unescaped URL variables
Path traversal via unescaped URL variables. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-22.
Medium [CVE-2026-64640] Apache Polaris did not consistently validate storage locations supplied during table and view registration
Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permission to register a table or view could, depending on the affected release and registration path, cause Polaris to use the catalog's storage credentials to read a caller-selected Iceberg metadata file before verifying that the file was within the catalog's allowed storage locations. If the catalog's underlying credentials could read an object outside that boundary, this could disclose limited information from the object. Polaris could also accept registration metadata located within an allowed location that contained references to storage locations outside the allowed boundary. This second condition did not itself cause Polaris to read the referenced external locations during registration. The demonstrated impact is limited to confidentiality. No unauthorized data modification or availability impact has been demonstrated. The server-side read requires a deployment using S3 credential vending and an object outside the allowed locations that the catalog's underlying storage credentials can read. Exploitation requires an authenticated principal with table- or view-registration privileges.
High [CVE-2026-34966] Information disclosure via Server-Side Request Forgery (SSRF) bypass
Information disclosure via Server-Side Request Forgery (SSRF) bypass. Red Hat rates this important (CVSS 7.6). Weakness: CWE-918.