🕵️ RESEARCH & DEEP DIVES
- Multiple use-after-free and memory corruption flaws in Google Chrome before 150.0.7871.128 — CVE ThreatInt
Google Chrome versions prior to 150.0.7871.128 contain multiple use-after-free vulnerabilities exploitable via crafted HTML or files.- Affects Google Chrome versions before 150.0.7871.128 on desktop, Linux, Android, and Mac platforms
- Vulnerabilities include use-after-free in Aura, Ozone, Cast, Network, GPU, CameraCapture components and out-of-bounds in V8 engine
- Exploitation vectors involve crafted HTML pages or malicious files leading to heap corruption, arbitrary code execution, or sandbox escape
- Some vulnerabilities require user interaction such as specific UI gestures on Linux
- Severity ranges from High to Critical depending on the component and impact
🔓 CVEs & KEV
-
CVE-2026-55833 Netty SPDY zlib header block continues decoded expansion after maxHeaderSize — CVSS 7.5
A vulnerability in Netty SPDY can cause decoded expansion beyond the maximum header size, risking resource exhaustion and potential denial of service. -
CVE-2026-55831 Netty SPDY SETTINGS frame count materializes unbounded settings map — CVSS 7.5
Netty SPDY SETTINGS frame count vulnerability may lead to unbounded settings map creation, potentially causing memory issues. -
CVE-2026-16327 D-Link DNS-320 upload.php unrestricted upload — CVSS 7.3
A vulnerability was determined in D-Link DNS-320 allowing unrestricted file uploads via upload.php, risking arbitrary file execution. -
CVE-2026-63728 Gitleaks Secret Exfiltration via Non-Hermetic Sprig Template Functions — CVSS 6.3
Gitleaks is vulnerable to secret exfiltration through non-hermetic Sprig template functions in repositories using Sprig templates.