<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Use After Free</title><description>Cybersecurity articles tagged #Use After Free on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Chrome, Firefox, Thunderbird Updates Patch Dozens of High-Severity Flaws</title><link>https://runtimerebel.com/blog/chrome-firefox-thunderbird-updates-patch-dozens-of-high-severity-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/chrome-firefox-thunderbird-updates-patch-dozens-of-high-severity-flaws</guid><description>Google and Mozilla release urgent updates for Chrome 151, Firefox 154, and Thunderbird 154, addressing critical and high-severity vulnerabilities including RCE.</description><pubDate>Wed, 19 Aug 2026 08:26:41 GMT</pubDate><category>Chrome</category><category>Firefox</category><category>Buffer Overflow</category><category>Use After Free</category><category>Privilege Escalation</category></item><item><title>Chrome 151 Update Patches 41 Critical, High-Severity Flaws</title><link>https://runtimerebel.com/blog/chrome-151-update-patches-41-critical-high-severity-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/chrome-151-update-patches-41-critical-high-severity-flaws</guid><description>Google&apos;s Chrome 151 update addresses 41 critical and high-severity vulnerabilities, including memory safety bugs potentially leading to RCE.</description><pubDate>Sun, 09 Aug 2026 16:24:44 GMT</pubDate><category>Google Chrome</category><category>Vulnerabilities</category><category>Memory Safety</category><category>Use After Free</category><category>Out of Bounds Write</category></item><item><title>Pixel 9 0-Click Sandbox Escape: BigWave UAF to Kernel R/W</title><link>https://runtimerebel.com/blog/pixel-9-0-click-sandbox-escape-bigwave-uaf-to-kernel-r-w</link><guid isPermaLink="true">https://runtimerebel.com/blog/pixel-9-0-click-sandbox-escape-bigwave-uaf-to-kernel-r-w</guid><description>A critical 0-click exploit chain targets Google Pixel 9 devices, leveraging a Use-After-Free in the BigWave driver for kernel arbitrary read/write.</description><pubDate>Sat, 08 Aug 2026 01:02:16 GMT</pubDate><category>Use After Free</category><category>Sandbox Escape</category><category>Zero Click</category><category>Pixel 9</category><category>BigWave Driver</category></item><item><title>Chrome 150 Update: Patching 27 Vulnerabilities, Critical Use-After-Free Flaws</title><link>https://runtimerebel.com/blog/chrome-150-update-patching-27-vulnerabilities-critical-use-after-free-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/chrome-150-update-patching-27-vulnerabilities-critical-use-after-free-flaws</guid><description>Google Chrome 150 update patches 27 vulnerabilities, including two critical use-after-free bugs.</description><pubDate>Thu, 09 Jul 2026 07:44:34 GMT</pubDate><category>Chrome 150</category><category>Use After Free</category><category>Browser Security</category><category>Vulnerability Patching</category><category>Google Chrome</category></item><item><title>CVE-2026-53359: Linux KVM Guest-to-Host Escape via Januscape Flaw</title><link>https://runtimerebel.com/blog/cve-2026-53359-linux-kvm-guest-to-host-escape-via-januscape-flaw</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-53359-linux-kvm-guest-to-host-escape-via-januscape-flaw</guid><description>A critical 16-year-old use-after-free vulnerability, Januscape (CVE-2026-53359), in Linux KVM allows guest VMs to escape to the host on Intel and AMD x86 systems.</description><pubDate>Mon, 06 Jul 2026 21:39:13 GMT</pubDate><category>CVE-2026-53359</category><category>Linux KVM</category><category>Virtualization</category><category>Guest to Host Escape</category><category>Use After Free</category><category>Januscape</category><category>Intel X86</category><category>AMD X86</category></item><item><title>Chrome 149 Update Patches 18 High-Severity UAF Vulnerabilities</title><link>https://runtimerebel.com/blog/chrome-149-update-patches-18-high-severity-uaf-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/chrome-149-update-patches-18-high-severity-uaf-vulnerabilities</guid><description>Google releases Chrome 149 to address 18 severe vulnerabilities, including multiple use-after-free defects in Graphics, Dawn, and Mojo components.</description><pubDate>Thu, 25 Jun 2026 09:15:58 GMT</pubDate><category>Google Chrome</category><category>CVE-2024-11812</category><category>Use After Free</category><category>Browser Security</category><category>RCE</category></item><item><title>Samsung KNOX Kernel Attack Flaw: Millions of Galaxy Devices Exposed</title><link>https://runtimerebel.com/blog/samsung-knox-kernel-attack-flaw-millions-of-galaxy-devices-exposed</link><guid isPermaLink="true">https://runtimerebel.com/blog/samsung-knox-kernel-attack-flaw-millions-of-galaxy-devices-exposed</guid><description>High-severity use-after-free vulnerability in Samsung KNOX exposed millions of Galaxy devices (S9-S25) to kernel attacks for years.</description><pubDate>Tue, 23 Jun 2026 13:11:12 GMT</pubDate><category>Samsung</category><category>KNOX</category><category>Galaxy Devices</category><category>Use After Free</category><category>Kernel Attack</category></item><item><title>CVE-2026-42530 &amp; -42531: NGINX RCE via Use-After-Free</title><link>https://runtimerebel.com/blog/cve-2026-42530-42531-nginx-rce-via-use-after-free</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-42530-42531-nginx-rce-via-use-after-free</guid><description>F5 addresses critical RCE flaws [CVE-2026-42530, CVE-2026-42531] in NGINX Open Source. Unauthenticated attackers can exploit use-after-free issues. Patch now.</description><pubDate>Thu, 18 Jun 2026 20:54:37 GMT</pubDate><category>NGINX</category><category>F5</category><category>RCE</category><category>CVE-2026-42530</category><category>CVE-2026-42531</category><category>Use After Free</category><category>HTTP 3</category><category>HTTP 2</category></item><item><title>Chrome 149 Update Patches 28 Vulnerabilities — Mitigation Guide</title><link>https://runtimerebel.com/blog/chrome-149-update-patches-28-vulnerabilities-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/chrome-149-update-patches-28-vulnerabilities-mitigation-guide</guid><description>Google addresses 28 security flaws in Chrome 149, including critical use-after-free bugs. Learn about technical impacts and enterprise patching requirements.</description><pubDate>Fri, 12 Jun 2026 09:36:27 GMT</pubDate><category>Google Chrome</category><category>Chrome 149</category><category>Use After Free</category><category>Memory Corruption</category><category>Browser Security</category></item><item><title>Chrome 148 Update: Patching Critical Use-After-Free Vulnerabilities</title><link>https://runtimerebel.com/blog/chrome-148-update-patching-critical-use-after-free-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/chrome-148-update-patching-critical-use-after-free-vulnerabilities</guid><description>Google releases Chrome 148 addressing critical-severity use-after-free vulnerabilities.</description><pubDate>Fri, 15 May 2026 09:12:15 GMT</pubDate><category>Chrome 148</category><category>Chromium</category><category>Use After Free</category><category>Memory Corruption</category><category>Google Chrome</category></item><item><title>CISA KEV Update: Exchange Server, Adobe, MS Windows Exploits</title><link>https://runtimerebel.com/blog/cisa-kev-update-exchange-server-adobe-ms-windows-exploits</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-kev-update-exchange-server-adobe-ms-windows-exploits</guid><description>CISA adds seven vulnerabilities, including critical Microsoft Exchange Server deserialization, to its Known Exploited Vulnerabilities Catalog, urging immediate…</description><pubDate>Tue, 14 Apr 2026 00:47:03 GMT</pubDate><category>CVE-2012-1854</category><category>CVE-2020-9715</category><category>CVE-2023-21529</category><category>CVE-2023-36424</category><category>CVE-2025-60710</category><category>CVE-2026-21643</category><category>CVE-2026-34621</category><category>Microsoft Exchange Server</category><category>Adobe Acrobat</category><category>Microsoft Windows</category><category>Fortinet</category><category>CISA</category><category>KEV Catalog</category><category>Deserialization</category><category>Use After Free</category><category>SQL Injection</category></item><item><title>CVE-2026-5281: Google Dawn RCE via Use-After-Free — Mitigation Guide</title><link>https://runtimerebel.com/blog/cve-2026-5281-google-dawn-rce-via-use-after-free-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-5281-google-dawn-rce-via-use-after-free-mitigation-guide</guid><description>CISA adds CVE-2026-5281 to the Known Exploited Vulnerabilities Catalog following evidence of active exploitation in Google Dawn&apos;s WebGPU implementation.</description><pubDate>Thu, 02 Apr 2026 08:32:17 GMT</pubDate><category>CVE-2026-5281</category><category>Google Dawn</category><category>CISA KEV</category><category>Use After Free</category><category>Chromium</category><category>WebGPU</category></item><item><title>CISA KEV Update: Five Actively Exploited CVEs in Apple, Hikvision, Rockwell</title><link>https://runtimerebel.com/blog/cisa-kev-update-five-actively-exploited-cves-in-apple-hikvision-rockwell</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-kev-update-five-actively-exploited-cves-in-apple-hikvision-rockwell</guid><description>CISA adds five actively exploited vulnerabilities, including Apple iOS/iPadOS use-after-free and Hikvision improper authentication, to its KEV Catalog.</description><pubDate>Thu, 05 Mar 2026 20:18:17 GMT</pubDate><category>CVE-2017-7921</category><category>CVE-2021-22681</category><category>CVE-2021-30952</category><category>CVE-2023-41974</category><category>CVE-2023-43000</category><category>CISA KEV Catalog</category><category>Hikvision</category><category>Rockwell Automation</category><category>Apple iOS</category><category>Apple iPadOS</category><category>Vulnerability Management</category><category>Active Exploitation</category><category>Improper Authentication</category><category>Use After Free</category></item></channel></rss>