Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.3 CVE-2026-5589

Out-of-bounds write caused by an integer underflow in the Bluetooth Mesh subsystem._CVE-2026-5589

An integer underflow in bt_mesh_sol_recv() in the Bluetooth Mesh solicitation handling (subsys/bluetooth/mesh/solicitation.c) leads to an out-of-bo...

zephyrproject-rtos Zephyr * CVE
MEDIUM 4.3 CVE-2026-11178

CVE-2026-11178_CVE-2026-11178

Insufficient policy enforcement in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data v...

Google Chrome 149.0.7827.53 CVE
HIGH 8.8 CVE-2026-11177

CVE-2026-11177_CVE-2026-11177

Use after free in Omnibox in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures ...

Google Chrome 149.0.7827.53 CVE
MEDIUM 6.5 CVE-2026-11176

CVE-2026-11176_CVE-2026-11176

Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTM...

Google Chrome 149.0.7827.53 CVE
HIGH 8.8 CVE-2026-11175

CVE-2026-11175_CVE-2026-11175

Incorrect security UI in Messages in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted...

Google Chrome 149.0.7827.53 CVE
MEDIUM 5.3 CVE-2026-11174

CVE-2026-11174_CVE-2026-11174

Inappropriate implementation in Site Isolation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer p...

Google Chrome 149.0.7827.53 CVE
HIGH 8.8 CVE-2026-11172

CVE-2026-11172_CVE-2026-11172

Incorrect security UI in Contact Picker in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a c...

Google Chrome 149.0.7827.53 CVE
HIGH 8.1 CVE-2026-11170

CVE-2026-11170_CVE-2026-11170

Inappropriate implementation in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to perform OS-level privilege...

Google Chrome 149.0.7827.53 CVE
HIGH 8.1 CVE-2026-11169

CVE-2026-11169_CVE-2026-11169

Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) vi...

Google Chrome 149.0.7827.53 CVE
MEDIUM 6.5 CVE-2026-11168

CVE-2026-11168_CVE-2026-11168

Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer proce...

Google Chrome 149.0.7827.53 CVE