Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2026-42836: Windows Elevation of Privilege via Race Condition in Function Discovery Service
On June 9, 2026, Microsoft released its monthly Patch Tuesday updates, tackling CVE-2026-42836—an elevation-of-privilege vulnerability in the Windows Function Discovery Service. The flaw, rated...
Patch NOW: CVE-2026-11097 Exposes Android WebView Data via Version 149.0.7827.53 Fix
Google has disclosed CVE-2026-11097, a medium-severity data leak vulnerability in Chrome for Android’s WebView component. The flaw, published June 4, 2026, affects versions prior to 149.0.7827.53...
CVE-2026-11035: Urgent Chrome Android Update Fixes Active Custom Tabs Attack
Google has issued an urgent update for Chrome on Android to address a high-severity privilege escalation flaw in Custom Tabs, tracked as CVE-2026-11035. The vulnerability, disclosed on June 4, 2026,...
CVE-2026-11290 Patching: Chrome Android WebView Integer Overflow Could Crash Apps on Windows
Google has assigned CVE-2026-11290 to a newly patched integer overflow vulnerability in Chrome for Android’s WebView component. The bug, published on June 4, 2026, is rated as low severity by...
Google Chrome Android CVE-2026-11278: Urgent Fix for Custom Tabs Data Leak
Google has confirmed CVE-2026-11278, a high-severity information disclosure vulnerability in Chrome for Android versions prior to 149.0.7827.53. The flaw resides in Chrome Custom Tabs and could allow...
CVE-2026-11270: Chrome for Android 149.0.7827.53+ Fixes Critical Cross-Origin Leak
Google has disclosed a critical security flaw in Chrome for Android that allows remote attackers to siphon cross-origin data from unsuspecting users. Designated CVE-2026-11270, the vulnerability...
CVE-2026-11247: Chrome for Android Custom Tabs Vulnerability Patched, Update Now
Google has patched a low-severity vulnerability in Chrome for Android that could have allowed malicious applications to leak sensitive data through the browser's Custom Tabs feature. Tracked as...
CVE-2026-11215: Chrome for Android Flaw Allows Domain Spoofing — Here's How to Patch
Google disclosed a medium-severity security flaw in Chrome for Android that allows attackers to spoof domain names, potentially tricking users into handing over credentials to phishing sites. Tracked...
Chrome Android CVE-2026-11172: Patch Critical Contact Picker Spoofing Flaw
Google has disclosed CVE-2026-11172, a medium-severity vulnerability in Chrome for Android that allows a remote attacker to spoof the Contact Picker security UI. Published on June 4, 2026, the flaw...
Google Fixes Chrome Android WebView Sandbox Escape—Update Now to 149.0.7827.53
Google has patched a sandbox escape vulnerability in Chrome’s WebView component for Android, disclosed June 4 under CVE-2026-11167. The flaw, rated “Medium” by Chromium engineers but scored 9.6...
CVE-2026-11163: Critical Chrome for Android Use-After-Free Flaw Fixed, Patch Now to Prevent Sandbox Escape
{ "title": "CVE-2026-11163: Critical Chrome for Android Use-After-Free Flaw Fixed, Patch Now to Prevent Sandbox Escape", "content": "Google has patched a critical use-after-free vulnerability in...
CVE-2026-11127: Chrome for Android WebAPK Domain Spoofing Flaw Patched in Version 149
Google has patched a medium-severity vulnerability in Chrome for Android that allowed remote attackers to spoof domain information inside WebAPK wrappers. Tracked as CVE-2026-11127, the flaw affects...