Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
16.663 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.6) | 0.38% | — | Google Chrome | 15/9/2026 | 24/9/2026 | Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | |
| Analizada | Media (4.8) | 0.19% | — | Google Chrome | 15/9/2026 | 21/9/2026 | Confused deputy in PriceTracking in Google Chrome on on iOS prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to bypass system access restrictions into a privileged page via crafted network traffic. (Chromium security severity: Medium) | |
| Modificada | Alta (8.1) | 0.26% | — | Google Chrome | 15/9/2026 | 18/9/2026 | Missing authorization in AppManifest in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Baja (3.1) | 0.17% | — | Google Chrome | 15/9/2026 | 18/9/2026 | Race condition in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Alta (8.1) | 0.23% | — | Google Chrome | 15/9/2026 | 18/9/2026 | Code injection in XML in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) | |
| Analizada | Media (6.7) | 0.10% | — | Google Android | 15/9/2026 | 18/9/2026 | In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (6.7) | 0.10% | — | Google Android | 15/9/2026 | 18/9/2026 | In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7.8) | 0.10% | — | Google Android | 15/9/2026 | 18/9/2026 | In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (6.7) | 0.10% | — | Google Android | 15/9/2026 | 18/9/2026 | In GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (6.7) | 0.10% | — | Google Android | 15/9/2026 | 18/9/2026 | In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (6.7) | 0.10% | — | Google Android | 15/9/2026 | 18/9/2026 | In multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (6.7) | 0.10% | — | Google Android | 15/9/2026 | 18/9/2026 | In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7.8) | 0.10% | — | Google Android | 15/9/2026 | 18/9/2026 | In multiple locations, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (6.7) | 0.09% | — | Google Android | 15/9/2026 | 18/9/2026 | In platform_msg_handler_init of default_msg_handlers.c, there is a possible confused deputy due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7) | 0.07% | — | Google Android | 15/9/2026 | 18/9/2026 | In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (6.2) | 0.10% | — | Google Android | 15/9/2026 | 18/9/2026 | In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7) | 0.07% | — | Google Android | 15/9/2026 | 18/9/2026 | In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (6.7) | 0.10% | — | Google Android | 15/9/2026 | 18/9/2026 | In FsmReleaseKey of fsm.c, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7) | 0.07% | — | Google Android | 15/9/2026 | 18/9/2026 | In multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (4.4) | 0.09% | — | Google Android | 15/9/2026 | 18/9/2026 | In multiple locations, there is a possible information disclosure due to uninitialized memory use. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (6.7) | 0.10% | — | Google Android | 15/9/2026 | 18/9/2026 | In smmu_detach_dev_nested of arm-smmu-v3.c, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (6.7) | 0.08% | — | Google Android | 15/9/2026 | 18/9/2026 | In multiple locations, there is a possible time-of-check to time-of-use due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (8.8) | 0.37% | — | Google Android | 15/9/2026 | 18/9/2026 | In DecodeFilmGrainParams of film_grain_dec.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (8.8) | 0.59% | ⚠ Explotación activa | Google Android | 15/9/2026 | 7/10/2026 | In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7) | 0.07% | — | Google Android | 15/9/2026 | 18/9/2026 | In trusty_dputc of generic-arm64-smcall.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. |