Aggregator
First Public macOS Kernel Exploit on Apple M5 Prepared Using Mythos Preview in Five Days
1 month ago
Apple’s M5 silicon has reportedly been exploited for the first time in a public macOS kernel memory corruption attack, successfully bypassing the company’s notable hardware-level memory protection. Researchers from Calif, Bruce Dang, Dion Blazakis, and Josh Maine, developed a working kernel local privilege escalation (LPE) exploit targeting macOS 26.4.1 (25E253) on bare-metal M5 hardware. The […]
The post First Public macOS Kernel Exploit on Apple M5 Prepared Using Mythos Preview in Five Days appeared first on Cyber Security News.
Guru Baran
电信日特稿|绿盟科技汤旭:智能体安全不再是可选项,产业亟待共建可信生态
1 month ago
阅读: 10筑牢智能体安全护城河,守护运营商数字生命线。2026年世界电信和信息社会日以“数字生命线:在互联世界中加强复原力”
CVE-2026-8576 | Google Chrome up to 148.0.7778.96 on Linux CORS cross-domain policy (ID 496231 / WID-SEC-2026-1542)
1 month ago
A vulnerability, which was classified as problematic, has been found in Google Chrome on Linux. This impacts an unknown function of the component CORS. The manipulation leads to permissive cross-domain policy with untrusted domains.
This vulnerability is listed as CVE-2026-8576. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-8575 | Google Chrome up to 148.0.7778.96 UI use after free (ID 496217 / WID-SEC-2026-1542)
1 month ago
A vulnerability identified as critical has been detected in Google Chrome. Affected by this issue is some unknown functionality of the component UI. The manipulation leads to use after free.
This vulnerability is traded as CVE-2026-8575. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2026-8572 | Google Chrome up to 148.0.7778.96 on Android Network cross-domain policy (ID 495405 / WID-SEC-2026-1542)
1 month ago
A vulnerability was found in Google Chrome on Android. It has been classified as critical. Affected is an unknown function of the component Network. This manipulation causes permissive cross-domain policy with untrusted domains.
This vulnerability appears as CVE-2026-8572. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-8574 | Google Chrome up to 148.0.7778.96 on Windows Core use after free (ID 495902 / WID-SEC-2026-1542)
1 month ago
A vulnerability categorized as critical has been discovered in Google Chrome on Windows. Affected by this vulnerability is an unknown functionality of the component Core. Executing a manipulation can lead to use after free.
This vulnerability appears as CVE-2026-8574. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-8573 | Google Chrome up to 148.0.7778.96 on Windows Codecs integer overflow (ID 495417 / Nessus ID 314866)
1 month ago
A vulnerability was found in Google Chrome on Windows. It has been rated as problematic. Affected is an unknown function of the component Codecs. Performing a manipulation results in integer overflow.
This vulnerability is reported as CVE-2026-8573. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-8571 | Google Chrome up to 148.0.7778.96 on Android GPU sandbox (ID 491422 / WID-SEC-2026-1542)
1 month ago
A vulnerability was found in Google Chrome on Android and classified as critical. This impacts an unknown function of the component GPU. The manipulation results in sandbox issue.
This vulnerability is reported as CVE-2026-8571. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-8568 | Google Chrome up to 148.0.7778.96 AI access control (ID 488728 / WID-SEC-2026-1542)
1 month ago
A vulnerability classified as critical was found in Google Chrome. This affects an unknown function of the component AI. Executing a manipulation can lead to improper access controls.
This vulnerability is tracked as CVE-2026-8568. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-8569 | Google Chrome up to 148.0.7778.96 on macOS Codecs out-of-bounds write (ID 490229 / Nessus ID 314886)
1 month ago
A vulnerability was found in Google Chrome on macOS. It has been classified as critical. This affects an unknown function of the component Codecs. This manipulation causes out-of-bounds write.
This vulnerability is registered as CVE-2026-8569. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-8570 | Google Chrome up to 148.0.7778.96 V8 type confusion (ID 490353 / WID-SEC-2026-1542)
1 month ago
A vulnerability was found in Google Chrome. It has been declared as problematic. This impacts an unknown function of the component V8. Such manipulation leads to type confusion.
This vulnerability is documented as CVE-2026-8570. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-8566 | Google Chrome up to 148.0.7778.96 on Android Payments access control (ID 470646 / WID-SEC-2026-1542)
1 month ago
A vulnerability has been found in Google Chrome on Android and classified as critical. This affects an unknown function of the component Payments. The manipulation leads to improper access controls.
This vulnerability is documented as CVE-2026-8566. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-8567 | Google Chrome up to 148.0.7778.96 on Windows ANGLE integer overflow (ID 484986 / Nessus ID 314878)
1 month ago
A vulnerability was found in Google Chrome on Windows and classified as critical. The impacted element is an unknown function of the component ANGLE. The manipulation results in integer overflow.
This vulnerability is cataloged as CVE-2026-8567. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-30903 | Zoom Workplace/VDI Client on Windows file inclusion (WID-SEC-2026-0653)
1 month ago
A vulnerability was found in Zoom Workplace and VDI Client on Windows and classified as critical. Impacted is an unknown function. Executing a manipulation can lead to file inclusion.
This vulnerability appears as CVE-2026-30903. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-30901 | Zoom Rooms up to 6.6.4 on Windows input validation (Nessus ID 302114 / WID-SEC-2026-0653)
1 month ago
A vulnerability was found in Zoom Rooms up to 6.6.4 on Windows. It has been declared as problematic. The impacted element is an unknown function. The manipulation results in improper input validation.
This vulnerability is known as CVE-2026-30901. Attacking locally is a requirement. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-23817 | HPE AOS-CX up to 10.10.1170/10.13.1101/10.16.1020/10.17.0001 Web-based Management Interface improper authentication (WID-SEC-2026-0686)
1 month ago
A vulnerability classified as critical was found in HPE AOS-CX up to 10.10.1170/10.13.1101/10.16.1020/10.17.0001. Impacted is an unknown function of the component Web-based Management Interface. The manipulation results in improper authentication.
This vulnerability is reported as CVE-2026-23817. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2026-1497 | neo4j Enterprise Edition up to 5.26.21/2026.1 Composite Databases authorization
1 month ago
A vulnerability labeled as critical has been found in neo4j Enterprise Edition up to 5.26.21/2026.1. The affected element is an unknown function of the component Composite Databases. Such manipulation leads to incorrect authorization.
This vulnerability is traded as CVE-2026-1497. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-2673 | OpenSSL up to 3.5.5/3.6.1 TLS 1.3 downgrade (EUVD-2026-12033 / Nessus ID 302195)
1 month ago
A vulnerability, which was classified as critical, has been found in OpenSSL up to 3.5.5/3.6.1. This issue affects some unknown processing of the component TLS 1.3. The manipulation leads to algorithm downgrade.
This vulnerability is documented as CVE-2026-2673. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-29796 | IGL-Technologies eParking.fi WebSocket Endpoint missing authentication (icsa-26-078-08)
1 month ago
A vulnerability classified as critical has been found in IGL-Technologies eParking.fi. This vulnerability affects unknown code of the component WebSocket Endpoint. This manipulation causes missing authentication.
This vulnerability is tracked as CVE-2026-29796. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com