Use after free in WebView in Google Chrome on Android prior to 146
Description
Use after free in WebView in Google Chrome on Android prior to 146
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Genealogy
PRODUCT: Genealogy
AFFECTED_VERSIONS: Prior to 5.9.1
---END_METADATA---
Description Summary:
A broken access control flaw in the Genealogy PHP application allows authenticated users to transfer ownership of arbitrary non-personal team workspaces to their own accounts.
Executive Summary:
A critical access control vulnerability in Genealogy permits authenticated users to perform unauthorized team ownership takeovers.
Vulnerability Details
CVE-ID: CVE-2026-39355
Affected Software: Genealogy
Affected Versions: Prior to 5.9.1
Vulnerability: The application fails to properly validate permissions when transferring team ownership. This allows any authenticated user to escalate their privileges by claiming ownership of teams they do not manage.
Business Impact
This vulnerability presents a significant risk of data exfiltration and unauthorized administrative control over team workspaces. With a CVSS score of 9.9, the impact on organizational data privacy is extreme, as attackers can gain access to all data associated with compromised teams.
Remediation Plan
Immediate Action: Update the Genealogy application to version 5.9.1 or later to remediate the access control logic.
Proactive Monitoring: Audit ownership change logs to identify any unauthorized transfers of team workspaces that occurred prior to patching.
Compensating Controls: Restrict access to the application to trusted internal networks and implement strict session monitoring for unusual account activity.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of Apr 7, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
The ability for a standard user to seize control of arbitrary workspaces is a critical security failure. Organizations should prioritize updating to version 5.9.1 to ensure that authorization checks are correctly enforced across all team management functions.