Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Android" — 24 resultados ✕ Limpiar búsqueda
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1017
Esta semana
RSS
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-79797] An improper access control vulnerability exists in the Android client application for HPE Networking…
An improper access control vulnerability exists in the Android client application for HPE Networking ClearPass Policy Manager, where application functionality may be invoked by untrusted sources. Successful exploitation could allow an unauthenticated remote attacker, with user interaction, to obtain sensitive information from the affected user.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106371] Incorrect authorization in Transactions Platform in Google Chrome on on Android prior to 155.0.8059.…
Incorrect authorization in Transactions Platform in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
G Alto vulnerabilidad
Hace 3 días
[CVE-2026-106367] Vulnerabilidad Android en Android OS - CVSS 8.4
Vulnerabilidad de seguridad en Android (Android OS): Vulnerabilidad de seguridad en Android. CVSS: 8.4. Afecta dispositivos Android, 80%+ del mercado movil en Mexico y LATAM. Actualiza tu dispositivo en Ajustes - Actualizacion del sistema.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106308] Incorrect reference resolution in Autofill in Google Chrome on on Android prior to 155.0.8059.39 all…
Incorrect reference resolution in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106256] Information leak in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote…
Information leak in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106249] Incorrect authorization in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a …
Incorrect authorization in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
G Alto vulnerabilidad
Hace 3 días
[CVE-2026-106221] Vulnerabilidad Android en Android OS - CVSS 8.3
Vulnerabilidad de seguridad en Android (Android OS): Vulnerabilidad de seguridad en Android. CVSS: 8.3. Afecta dispositivos Android, 80%+ del mercado movil en Mexico y LATAM. Actualiza tu dispositivo en Ajustes - Actualizacion del sistema.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
G Alto vulnerabilidad
Hace 3 días
[CVE-2026-106199] Vulnerabilidad Android en Android OS - CVSS 8.2
Vulnerabilidad de seguridad en Android (Android OS): Vulnerabilidad de seguridad en Android. CVSS: 8.2. Afecta dispositivos Android, 80%+ del mercado movil en Mexico y LATAM. Actualiza tu dispositivo en Ajustes - Actualizacion del sistema.
G Alto vulnerabilidad
Hace 3 días
[CVE-2026-106205] Vulnerabilidad Android en Android OS - CVSS 8.1
Vulnerabilidad de seguridad en Android (Android OS): Vulnerabilidad de seguridad en Android. CVSS: 8.1. Afecta dispositivos Android, 80%+ del mercado movil en Mexico y LATAM. Actualiza tu dispositivo en Ajustes - Actualizacion del sistema.
G Alto vulnerabilidad
Hace 3 días
[CVE-2026-106188] Vulnerabilidad Android en Android System - CVSS 7.1
Vulnerabilidad de seguridad en Android (Android System): Vulnerabilidad de seguridad en Android. CVSS: 7.1. Afecta dispositivos Android, 80%+ del mercado movil en Mexico y LATAM. Actualiza tu dispositivo en Ajustes - Actualizacion del sistema.
G Alto vulnerabilidad
Hace 3 días
[CVE-2026-105788] Vulnerabilidad Android en Android Framework - CVSS 8.8
Vulnerabilidad de seguridad en Android (Android Framework): Vulnerabilidad de seguridad en Android. CVSS: 8.8. Afecta dispositivos Android, 80%+ del mercado movil en Mexico y LATAM. Actualiza tu dispositivo en Ajustes - Actualizacion del sistema.
M Alto vulnerabilidad
02/10/2026
[CVE-2026-103097] An API key is hardcoded and retrievable from the application package. Since Android applications can…
An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.
M Alto vulnerabilidad
02/10/2026
[CVE-2026-103096] API key is hardcoded and retrievable from the application package. Since Android applications can be…
API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102327] Incorrect authorization in WebView in Google Chrome on on Android prior to 154.0.8037.92 allowed a r…
Incorrect authorization in WebView in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
M Alto vulnerabilidad
29/09/2026
[CVE-2026-95322] Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote at…
Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
G Alto vulnerabilidad
29/09/2026
[CVE-2026-95285] Vulnerabilidad Android en Android OS - CVSS 8.4
Vulnerabilidad de seguridad en Android (Android OS): Vulnerabilidad de seguridad en Android. CVSS: 8.4. Afecta dispositivos Android, 80%+ del mercado movil en Mexico y LATAM. Actualiza tu dispositivo en Ajustes - Actualizacion del sistema.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-94183] Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page…
Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in the background. A remote attacker can exploit this via a specially crafted website to render fake UI elements, such as a spoofed address bar, misleading the user about the origin of displayed content and increasing the risk of phishing.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-61695] Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.1 and 7.0…
Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.1 and 7.0.0-alpha04, Wire's Swift runtime ProtoReader.skipGroup(expectedEndTag:unknownFieldsWriter:) accepts a negative length for a LENGTH_DELIMITED field inside an unknown START_GROUP field. ProtoReader.readData() forwards the negative count to ReadBuffer.readData(count:), whose upper-bound-only check perm…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-68928] Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.r…
Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.TerminalService is declared as an exported service in src/plugins/terminal/plugin.xml without a binding permission, and src/plugins/terminal/src/android/TerminalService.java does not verify the caller. Any installed Android application can bind the service and send MSG_EXEC with an a…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-63126] Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.5 and 7.0…
Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.5 and 7.0.0-alpha04, Wire protobuf readers do not consistently validate attacker-controlled lengths against the current logical message boundary before advancing cursors, pointers, limits, slices, or allocations. In Kotlin, ProtoAdapter.decode(ByteArray) and ProtoAdapter.decode(ByteString) use ByteArrayProto…