Vulnerabilities
715 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-58704 | Permission Bypass in Google Pixel Cellular Modem Allows Proximal Privilege Escalation A logic error in the cellular modem component causes an improper authorization check (CWE-285/CWE-693), allowing a permission bypass. An attacker who already has low privileges and is on an adjacent network (proximal, e.g., a hostile local or cellular-adjacent network) can trigger the flaw without any user interaction, and successful exploitation yields remote escalation of privilege with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.0). The flaw was assigned through Google's device security CNA ([email protected]), consistent with modem firmware shipped in Google Pixel-class devices; specific affected firmware versions were not provided in the source data. No public proof-of-concept is known, the issue is not listed in CISA's KEV catalog, and there is no evidence of exploitation in the wild. Defenders should treat this as a patch-on-next-bulletin item unless devices operate in high-risk adjacent-network environments. Do: Install the latest Google monthly security update that includes the cellular modem firmware patch and verify the device's security patch level reflects it. Because exploitation requires network adjacency plus some existing privilege, prioritize devices used in high-risk or shared-network settings and watch for indicators of rogue femtocell/base-station or hostile local-network activity. With no public PoC or KEV listing, standard monthly patch cadence is reasonable outside those high-risk scenarios. | 8.8 | — | KEV |
| masstens of millions of devices (≈10M+ active Pixel-class handsets worldwide) | |
| CVE-2026-87595 | SSRF in Google Chrome for Mobile before 153.0.8010.36 CVE-2026-87595 is a server-side request forgery (SSRF) flaw in Google Chrome on mobile platforms, fixed in version 153.0.8010.36. It is triggered when a victim is socially engineered into visiting a crafted HTML page, which causes the browser to issue requests that bypass system access restrictions. Successful exploitation could let a remote attacker reach or interact with resources that should be inaccessible from the victim's device context. All users of Chrome on mobile operating systems (Android/iOS) running versions prior to 153.0.8010.36 are affected. Chromium assesses the severity as Low, despite a published CVSS 3.1 score of 9.8; no public proof of concept exists and no exploitation in the wild has been reported (EPSS ~0.2%, not in CISA KEV). Do: Update Chrome on Android and iOS to 153.0.8010.36 or later via Google Play or the App Store, and confirm automatic updates are enabled for the browser. Enterprise administrators should verify managed mobile fleets have pulled the patched build. Weigh the vendor's Low severity rating over the externally assigned CVSS 9.8 when prioritizing, but patch promptly since exploitation requires only a user clicking a crafted link. | 9.8 group max | <1% |
| mass≈3+ billion users (Chrome mobile install base, majority of ~3-4 billion total Chrome users) |