MajorCritical vulnerability
CVE-2026-85082 (CVSS 8.5)
NVD · officialPublished Sep 25, 2026Risk 37/100
Root Browser Classic 3.3.0 passes the path of a selected SQLite database to an operating-system shell without safely separating the filename from the command.
Technical details
CVSS
8.5
AV:LocalAC:LowPR:NoneUI:Passive
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source