CVE-2026-85082
Root Browser Classic 3.3.0 passes the path of a selected SQLite database to an operating-system shell without safely separating the filename from the command.
- Published Sep 25, 2026
- CVSS 8.5 high
- 0.1% chance of exploitation in the next 30 days (EPSS)