CVE-2021-22538High· 8.8▾ TwilightPrivilege escalation in rbac
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.7%
Using a carefully crafted request or malicious proxy, a user with UserWrite permissions could create another user with higher privileges than their own due to insufficient checks on the allowed set of permissions. The event would be captured in the Event Log.
The issue has been fixed in 0.24.0 and 0.23.1.
For users who are unable to upgrade, we recommend auditing users who have UserWrite permissions and regularly reviewing the Event Log for malicious activity.
Thank you to Michael Mazzolini (Ethical Hacker at WHO) for finding and disclosing this vulnerability.
github.com/google/exposure-notifications-verification-server < 0.23.1Upgrade to a patched release:
github.com/google/exposure-notifications-verification-server 0.23.1Connected by shared product, vendor, weakness, or advisory.
CVE-2021-22565Medium· 6.5Insufficient Granularity of Access Control in github.com/google/exposure-notifications-verification-server
CVE-2026-19202Critical· 9.1A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-python SDK causes the same Google ID token to be cached and reused across different audiences
CVE-2026-93387Medium· 4.3Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-origin data via a crafted HTML page
CVE-2026-93386Medium· 5.4UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page
CVE-2026-93385Medium· 6.5Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive information via a crafted HTML page
CVE-2026-93384Low· 3.7Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic