Two unpatched vulnerabilities in Anthropic's Claude for Chrome extension let any malicious browser extension hijack Claude's agentic workflows and silently access Gmail, Google Docs, and Calendar data.
CVEs, exploits, and security flaws in AI frameworks, models, and infrastructure.
Two unpatched vulnerabilities in Anthropic's Claude for Chrome extension let any malicious browser extension hijack Claude's agentic workflows and silently access Gmail, Google Docs, and Calendar data.
A critical heap out-of-bounds read in Ollama's model loader lets unauthenticated attackers drain server memory in three API calls. Around 300,000 internet-facing instances are estimated at risk.
Nebula Security's VEGA AI tool uncovered CVE-2026-43499 in the Linux kernel, a use-after-free flaw present since 2011 that grants root access to any logged-in user and escapes containers. Public exploit code is now available and a chain with a Firefox bug enables full remote compromise on Android.
Sand Security Research disclosed a critical cross-tenant vulnerability in Writer's agent preview feature that let attackers steal session tokens and take over enterprise accounts with a single malicious link.
CISA added CVE-2026-55255 to the Known Exploited Vulnerabilities catalog on July 7, 2026, after confirming active exploitation of an insecure direct object reference in Langflow that let authenticated users execute workflows belonging to other tenants.