ZeroHour

Search: “VirtualBox”

136 items

ZDI-26-641: Oracle VirtualBox VirtioSCSI Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI disclosed CVE-2026-71114, an out-of-bounds read in Oracle VirtualBox VirtioSCSI letting privileged local guest attackers disclose sensitive information.

The Zero Day Initiative published advisory ZDI-26-641 for an out-of-bounds read vulnerability in Oracle VirtualBox's VirtioSCSI component, assigned CVE-2026-71114 with a CVSS score of 6.1. The flaw allows local attackers to disclose sensitive information on affected installations. Exploitation requires an attacker to first obtain the ability to execute high-privileged code on the target guest system.

ZDI-26-644: Oracle VirtualBox VMSVGA Race Condition Local Privilege Escalation Vulnerability

ZDI publishes ZDI-26-644 for CVE-2026-60155, a race condition local privilege escalation in Oracle VirtualBox VMSVGA, rated CVSS 7.5.

Zero Day Initiative published advisory ZDI-26-644 describing a race condition in Oracle VirtualBox's VMSVGA component. Local attackers who already execute high-privileged code on the guest system can escalate privileges on affected installations. ZDI rated the issue CVSS 7.5 and assigned CVE-2026-60155.

ZDI-26-640: Oracle VirtualBox VirtioSCSI Uninitialized Memory Information Disclosure Vulnerability

ZDI detailed an uninitialized memory flaw in Oracle VirtualBox's VirtioSCSI (CVE-2026-71132) allowing local attackers to disclose sensitive information.

Zero Day Initiative published ZDI-26-640, a CVSS 5.3 information disclosure vulnerability in the VirtioSCSI component of Oracle VirtualBox. An attacker must first run high-privileged code on the guest system before the uninitialized memory issue can be used to disclose sensitive information. The flaw is tracked as CVE-2026-71132. The advisory reports no exploitation activity.

ZDI-26-643: Oracle VirtualBox VMSVGA Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI publishes ZDI-26-643 for CVE-2026-60162, an out-of-bounds read information disclosure flaw in Oracle VirtualBox VMSVGA, rated CVSS 6.1.

Zero Day Initiative published advisory ZDI-26-643 describing an out-of-bounds read in Oracle VirtualBox's VMSVGA component. Local attackers with the ability to execute high-privileged code on the guest system can disclose sensitive information. ZDI rated the issue CVSS 6.1 and assigned CVE-2026-60162.

ZDI-26-642: Oracle VirtualBox IDisplay Out-Of-Bounds Read Local Privilege Escalation Vulnerability

ZDI publishes ZDI-26-642 for CVE-2026-60159, an out-of-bounds read local privilege escalation in Oracle VirtualBox IDisplay, rated CVSS 7.5.

Zero Day Initiative published advisory ZDI-26-642 describing an out-of-bounds read in Oracle VirtualBox's IDisplay component that enables local privilege escalation. Attackers must first obtain the ability to execute high-privileged code on the target guest system. ZDI rated the issue CVSS 7.5 and assigned CVE-2026-60159.

ZDI-26-639: Oracle VirtualBox VMSVGA Heap-based Buffer Overflow Local Privilege Escalation Vulnerability

ZDI disclosed a heap-based buffer overflow in Oracle VirtualBox's VMSVGA component (CVE-2026-71116) enabling local privilege escalation.

Zero Day Initiative published ZDI-26-639, a CVSS 7.5 heap-based buffer overflow in the VMSVGA component of Oracle VirtualBox. Local attackers who already execute high-privileged code on the guest system can leverage the flaw to escalate privileges on affected installations. The vulnerability is tracked as CVE-2026-71116. No exploitation is reported.

The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions

Elastic details KREMLIN, a Brazilian banking malware whose malicious Chrome/Edge extension forges Chromium integrity checks to steal sessions.

Elastic Security Labs tracked operation REF9334 and its KREMLIN toolkit, a Brazilian banking malware campaign impersonating twelve banks across seven campaigns since May 2025. The infection chain uses multi-stage obfuscated JavaScript loaders with sandbox checks (file and process counting), scheduled-task persistence, and an Ethereum smart contract acting as a dead-drop resolver for C2 and payload URLs, abusing Archive.org for hosting. The malicious browser extension bypasses Chromium integrity mechanisms by manipulating Secure Preferences and regenerating required HMACs and App-Bound encrypted hashes. Threat Command disrupted over 1,500 infections by registering the kill-switch canary domain.

Elastic Security Labs · 2d agoMalware in the wild