Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Android" — 109 resultados ✕ Limpiar búsqueda
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Alto vulnerabilidad
17/07/2026
[CVE-2026-45799] Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.3.0 and 7.0…
Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.3.0 and 7.0.0-alpha03, ByteArrayProtoReader32.skipGroup() and ProtoReader.skipGroup() in wire-runtime do not validate that a LENGTH_DELIMITED field length is non-negative before skip(), allowing a crafted protobuf varint encoding -128 as a signed Int to make skip(-128) move the internal position negative and m…
G Alto vulnerabilidad
14/07/2026
[CVE-2026-15772] Use after free in GPU in Google Chrome on Android prior to 150.0.7871.125 allowed a remote attacker …
Use after free in GPU in Google Chrome on Android prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
13/07/2026
[CVE-2026-58500] MCP Appium is an MCP server that provides AI assistants with tools to automate mobile app testing on…
MCP Appium is an MCP server that provides AI assistants with tools to automate mobile app testing on Android and iOS. In versions prior to 1.85.10, the createLocatorGeneratorUI function interpolates attacker-controlled element attributes — text, content-desc, resource-id, and locator selector values — directly into an HTML template literal without any HTML or JavaScript context escaping. An attack…
M Alto vulnerabilidad
09/07/2026
[CVE-2026-13462] PayRange Android app, version 7.0.7 and below, contains an SSL bypass vulnerability that allows inva…
PayRange Android app, version 7.0.7 and below, contains an SSL bypass vulnerability that allows invalid certificates to be accepted in application webviews. A remote and unauthenticated attacker can steal information that the user sends.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-58296] Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allo…
Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-58297] Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allo…
Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-58299] Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthoriz…
Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
G Alto vulnerabilidad
01/07/2026
[CVE-2026-14428] Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.4…
Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
01/07/2026
[CVE-2026-14401] Insufficient validation of untrusted input in ANGLE in Google Chrome on Android prior to 150.0.7871.…
Insufficient validation of untrusted input in ANGLE in Google Chrome on Android prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
30/06/2026
[CVE-2026-14114] Inappropriate implementation in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 al…
Inappropriate implementation in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium security severity: Low)
G Alto vulnerabilidad
30/06/2026
[CVE-2026-14064] Use after free in PageInfo in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attac…
Use after free in PageInfo in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)
G Alto vulnerabilidad
30/06/2026
[CVE-2026-14005] Use after free in Omnibox in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attack…
Use after free in Omnibox in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
G Alto vulnerabilidad
30/06/2026
[CVE-2026-13927] Insufficient validation of untrusted input in UI in Google Chrome on Android prior to 150.0.7871.47 …
Insufficient validation of untrusted input in UI in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)
G Alto vulnerabilidad
30/06/2026
[CVE-2026-13885] Use after free in Skia in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker …
Use after free in Skia in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
G Alto vulnerabilidad
30/06/2026
[CVE-2026-13870] Use after free in WebView in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attack…
Use after free in WebView in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
G Alto vulnerabilidad
30/06/2026
[CVE-2026-13856] Insufficient validation of untrusted input in Speech in Google Chrome on Android prior to 150.0.7871…
Insufficient validation of untrusted input in Speech in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
G Alto vulnerabilidad
30/06/2026
[CVE-2026-13863] Insufficient validation of untrusted input in CustomTabs in Google Chrome on Android prior to 150.0.…
Insufficient validation of untrusted input in CustomTabs in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)
G Alto vulnerabilidad
30/06/2026
[CVE-2026-13788] Use after free in Fullscreen in Google Chrome on Android prior to 150.0.7871.47 allowed a remote att…
Use after free in Fullscreen in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
M Alto vulnerabilidad
26/06/2026
[CVE-2026-9220] Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests bet…
Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and its backend with static hardcoded AES keys and initialization vectors. This allows an attacker to decrypt Setracker2 watch traffic.
M Alto vulnerabilidad
26/06/2026
[CVE-2026-9221] The Setracker2 Android Companion App (com.tgelec.setracker) versions 3.1.5 and earlier uses MD5 to g…
The Setracker2 Android Companion App (com.tgelec.setracker) versions 3.1.5 and earlier uses MD5 to generate a request signature for authenticating communications between the mobile client and the backend REST API. Attackers could potentially reverse the signature to recover the session ID. With the session ID exposed, an attacker could impersonate the legitimate user and issue authenticated API re…