Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Android" — 144 resultados ✕ Limpiar búsqueda
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1012
Esta semana
RSS
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89836] In the Linux kernel, the following vulnerability has been resolved: f2fs: fix folio_nr_pages() race…
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix folio_nr_pages() race after put in large folio invalidate Our v6.18 based Android system is continuely suffering livelock and bad page stat as shown in[1] which related to broken xarray slot status. By investigating big folio operations within f2fs, we find below races and fix it by get the nr_pages before drop the ref…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92033] Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156.
Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-59569] An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allow…
An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-18994] A potential improper authorization vulnerability was reported in the Lenovo File Manager Android App…
A potential improper authorization vulnerability was reported in the Lenovo File Manager Android Application, distributed exclusively in the Chinese market, that could allow a local authenticated user to read or modify protected files within the application.
G Alto vulnerabilidad
09/09/2026
[CVE-2026-87481] Incorrect authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a r…
Incorrect authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85094] The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin ru…
The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84117] Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155.
Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
25/08/2026
[CVE-2026-79286] Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a …
Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a co-installed app. (Chromium security severity: Medium)
M Alto vulnerabilidad
25/08/2026
[CVE-2026-79256] Externally controlled reference in WebView in Google Chrome on on Android prior to 152.0.7977.65 all…
Externally controlled reference in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
25/08/2026
[CVE-2026-79210] Use after free in Audio in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attac…
Use after free in Audio in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
25/08/2026
[CVE-2026-79142] Buffer overflow in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote atta…
Buffer overflow in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
25/08/2026
[CVE-2026-79132] Improper input validation in Input in Google Chrome on on Android prior to 152.0.7977.65 allowed a r…
Improper input validation in Input in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
25/08/2026
[CVE-2026-79057] Race condition in Start in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attack…
Race condition in Start in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a co-installed app. (Chromium security severity: Medium)
M Alto vulnerabilidad
25/08/2026
[CVE-2026-79008] Improper input validation in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a rem…
Improper input validation in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
24/08/2026
[CVE-2026-59566] A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected ver…
A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Client Connector on Android and ChromeOS.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
11/08/2026
[CVE-2026-67558] The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a…
The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against the BLE advertisement name only, with no cryptographic peripheral authentication, MAC allowlist, or bonded-identity check. An attacker could capture live session token information and inject forged hormone measurements into the victim's cloud record and clinical trend view.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-65768] Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams fo…
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-65767] Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Te…
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-70638] llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android …
llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max parameter without overflow validation, causing heap buffer allocation to wrap and allocate insufficient memory. Attackers can exploit this by providing a crafted n_seq_max value through a …
M Alto vulnerabilidad
06/08/2026
[CVE-2026-70640] llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LL…
llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JNI wrapper where bench_1model() and free_1context() lack synchronization, allowing Thread A to operate on freed memory while Thread B concurrently frees the llama_context. Attackers can exploit this by performing heap spray with attacker-controlled data containing a fake vtable to hijac…