CVE-2026-17872
Cryptographic Flaw in WebAppInstalls in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to potentially perform a sa
CVSS
6.1
Medio
EPSS
—
KEV
—
Exploit Today
0
0-100
Publicado: 30 jul 2026 · Última mod.: 30 jul 2026 · CWE-347
Sin historial EPSS suficiente todavía.
Cryptographic Flaw in WebAppInstalls in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-441049.8 CRÍ—
——0The firmware update process for the basemodule of the charging controller only validates the
CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise.16hCVE-2026-133056.4 MED—
——0Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of software updates. The issue results from the lack of proper validation of a user-supplied software update image. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-29062.12hCVE-2026-592439.8 CRÍ9.3%
——3The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and log in as an arbitrary user, including one holding the Admin role (CWE-347). Deployments running the FAB auth manager with the Azure AD OAuth login path under its default configuration are affected; the Authentik path already defaulted to `True`. This issue affects `apache-airflow-providers-fab` before 3.7.3. Users are advised to upgrade to `apache-airflow-providers-fab` 3.7.3, which defaults `verify_signature=True`.16hCVE-2026-632374.8 MED8.1%
——2A TOTP two-factor authentication bypass vulnerability in
Koollab LMS allowed an
attacker to supply a client-controlled seed to generate a matching one-time
password and bypass the second authentication factor, potentially enabling
unauthorised access to administrator accounts.14hCVE-2026-656168.8 ALT8.7%
——3Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administrator token.16hCVE-2026-148377.8 ALT0.3%
——0Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local attacker can bypass verification of the SSH enable file signature and enable SSH access on the device. Successful exploitation may result in unauthorized administrative access and complete system compromise.17h