Author: Monika Panwar

  • CVE-2026-2316: Insufficient policy enforcement in Frames

    CVE-2026-2316: Insufficient policy enforcement in Frames

    Vulnerbility: Insufficient policy enforcement in Frames in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) CVE CVE-2026-2316 CVSSv3 6.5 Medium Published date 11-Feb-2026 Impact Google Chrome <145.0.7632.45 Explotation None Solution: Update to latest version of Google Chrome

  • CVE-2025-60021: Apache Remote Code Execution

    CVE-2025-60021: Apache Remote Code Execution

    Vulnerability Remote command injection vulnerability in heap profiler built-in service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to inject remote command. Root Cause: The bRPC heap profiler built-in service (/pprof/heap) does not validate the user-provided extra_options parameter and executes it as a command-line argument. Attackers can execute remote commands using…

  • CVE-2025-30401: WhatsApp Security Advisory

    CVE-2025-30401: WhatsApp Security Advisory

    Vulnerability: A spoofing issue in Whatapp for window prior to version 2.2450.6 displayed attachments according to their MIME type but selected the file opening handler based on the attachments file name extension.A malicious crafted mismatch could have caused the recipient to inadvertently excute arbitrary code rather than view the attachment when mannually opening the attachment…

  • CVE-2025-55177: WhatsApp Zero click vulnerbility on Apple devices

    CVE-2025-55177: WhatsApp Zero click vulnerbility on Apple devices

    Vulnerbilites: Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability…

  • CVE-2025-55179 WhatsApp security advisiorey

    CVE-2025-55179 WhatsApp security advisiorey

    Vulnerability: Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.83 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device. We have not seen evidence of exploitation in the wild. CVE CVE-2025-55179…