CVE-2026-28577
In addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to local
CVSS
7.8
Alto
EPSS
0.1%
p0
KEV
—
Exploit Today
0
0-100
Publicado: 1 jun 2026 · Última mod.: 22 jul 2026 · CWE-1021
0.1%EPSS · 30 días0.1%
2026-08-022026-08-30
In addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-755485.4 MED6.7%
——2The affected Ebyte device web management interface does not restrict the
interface from being rendered within an external frame. An
unauthenticated remote attacker could use a crafted webpage to mislead
an authenticated administrator into initiating unintended configuration
changes or disruptive actions.3dCVE-2026-749806.5 MED7.0%
——2Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.6dCVE-2026-749788.1 ALT13.5%
——4Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.6dCVE-2026-749587.5 ALT18.0%
——5Information disclosure in the WebRTC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.12dCVE-2026-749516.5 MED5.5%
——2Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154.12dCVE-2026-447623.7 BAJ3.8%
——1SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration and lacks certain restrictive directives, which could enable an authenticated malicious user to leverage this weakness in combination with another vulnerability to inject and execute malicious scripts within the application's context. Successful exploitation may result in a low impact on confidentiality and integrity, with no impact on the availability of the application.5d