PatchSiren

Mullvad CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW Mullvad CVE published 2026-08-10

CVE-2026-19380

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T01:16:48.163Z and has not been modified since then. The vulnerability in Mullvad wireguard.sys 0.10.1, specifically in the AdapterState function of the IOCTL Handler, leads to improper update of reference count. Local access is required for potential exploitation. The vulnerability has a low CVSS [truncated]

HIGH mullvad CVE published 2026-05-19

CVE-2026-32323

Published on 2026-05-19, CVE-2026-32323 affects Mullvad VPN on macOS versions 2026.1 and earlier. During installation or upgrade, the installer can execute binaries from /Applications/Mullvad VPN.app without first confirming that the bundle is legitimate or attacker-controlled. A user in the admin group may be able to pre-place a crafted application bundle at that path and obtain code execution as root. M [truncated]