| Inappropriate implementation in Intents in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) cve CVE-2024-11919 | |
| Inappropriate implementation in Dawn in Google Chrome on Mac prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) cve CVE-2024-11920 | |
| chromium-browser: Inappropriate implementation in Fullscreen cve CVE-2024-13178 | cvss |
| Inappropriate implementation in Lens in Google Chrome on iOS prior to 136.0.7103.59 allowed a remote attacker to perform UI spoofing via a crafted QR code. (Chromium security severity: Low) cve CVE-2024-13983 | |
| chromium-browser: Inappropriate implementation in DevTools cve CVE-2024-7017 | cvss |
| Inappropriate implementation in Autofill in Google Chrome on Windows prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2024-7021 | |
| Use after free in Internals in Google Chrome on iOS prior to 127.0.6533.88 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a series of curated UI gestures. (Chromium security severity: Medium) cve CVE-2024-9126 | |
| Use after free in Serviceworker in Google Chrome on Desktop prior to 140.0.7339.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) cve CVE-2025-10200 | |
| Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 140.0.7339.127 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High) cve CVE-2025-10201 | |
| Use after free in Dawn in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) cve CVE-2025-10500 | |
| chromium-browser: Use after free in WebRTC cve CVE-2025-10501 | |
| Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) cve CVE-2025-10890 | |
| Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) cve CVE-2025-10891 | |
| chromium-browser: Out of bounds read in Media cve CVE-2025-11211 | cvss |
| Inappropriate implementation in Media in Google Chrome on Windows prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2025-11212 | |
| Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2025-11213 | |
| chromium-browser: Off by one error in V8 cve CVE-2025-11215 | cvss |
| Inappropriate implementation in Storage in Google Chrome on Mac prior to 141.0.7390.54 allowed a remote attacker to perform domain spoofing via a crafted video file. (Chromium security severity: Low) cve CVE-2025-11216 | |
| chromium-browser: Use after free in V8 cve CVE-2025-11219 | cvss |
| chromium-browser: Heap buffer overflow in Sync cve CVE-2025-11458 | cvss |
| chromium-browser: Use after free in Storage cve CVE-2025-11460 | |
| chromium-browser: Use after free in Safe Browsing cve CVE-2025-11756 | |
| chromium-browser: Out of bounds memory access in V8 cve CVE-2025-12036 | |
| chromium-browser: Type Confusion in V8 cve CVE-2025-12428 | |
| chromium-browser: Inappropriate implementation in V8 cve CVE-2025-12429 | |
| chromium-browser: Object lifecycle issue in Media cve CVE-2025-12430 | cvss |
| chromium-browser: Inappropriate implementation in Extensions cve CVE-2025-12431 | cvss |
| chromium-browser: Race in V8 cve CVE-2025-12432 | |
| chromium-browser: Inappropriate implementation in V8 cve CVE-2025-12433 | cvss |
| Race in Storage in Google Chrome on Windows prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2025-12434 | |
| Incorrect security UI in Omnibox in Google Chrome on Android prior to 142.0.7444.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2025-12435 | |
| chromium-browser: Policy bypass in Extensions cve CVE-2025-12436 | cvss |
| chromium-browser: Use after free in PageInfo cve CVE-2025-12437 | cvss |
| chromium-browser: Use after free in Ozone cve CVE-2025-12438 | |
| chromium-browser: Inappropriate implementation in App-Bound Encryption cve CVE-2025-12439 | cvss |
| chromium-browser: Inappropriate implementation in Autofill cve CVE-2025-12440 | cvss |
| chromium-browser: Out of bounds read in V8 cve CVE-2025-12441 | cvss |
| chromium-browser: Out of bounds read in WebXR cve CVE-2025-12443 | cvss |
| chromium-browser: Incorrect security UI in Fullscreen UI cve CVE-2025-12444 | cvss |
| chromium-browser: Policy bypass in Extensions cve CVE-2025-12445 | cvss |
| chromium-browser: Incorrect security UI in SplitView cve CVE-2025-12446 | cvss |
| Incorrect security UI in Omnibox in Google Chrome on Android prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) cve CVE-2025-12447 | |
| Out of bounds read in WebGPU in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) cve CVE-2025-12725 | |
| Inappropriate implementation in Views in Google Chrome on Windows prior to 142.0.7444.137 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: High) cve CVE-2025-12726 | |
| chromium-browser: Inappropriate implementation in V8 cve CVE-2025-12727 | |
| Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2025-12728 | |
| Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2025-12729 | |
| Inappropriate implementation in Downloads in Google Chrome on Windows prior to 140.0.7339.80 allowed a remote attacker to bypass Mark of the Web via a crafted HTML page. (Chromium security severity: Low) cve CVE-2025-12905 | |
| Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) cve CVE-2025-12906 | |
| Insufficient validation of untrusted input in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to execute arbitrary code via user action in Devtools. (Chromium security severity: Low) cve CVE-2025-12907 | |
| Insufficient validation of untrusted input in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low) cve CVE-2025-12908 | |
| Insufficient policy enforcement in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to leak cross-origin data via Devtools. (Chromium security severity: Low) cve CVE-2025-12909 | |
| Inappropriate implementation in Passkeys in Google Chrome prior to 140.0.7339.80 allowed a local attacker to obtain potentially sensitive information via debug logs. (Chromium security severity: Low) cve CVE-2025-12910 | |
| Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) cve CVE-2025-12911 | |
| chromium-browser: Inappropriate implementation in V8 cve CVE-2025-13042 | |
| chromium-browser: Inappropriate implementation in DevTools cve CVE-2025-13097 | cvss |
| Inappropriate implementation in WebApp Installs in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) cve CVE-2025-13102 | |
| chromium-browser: Inappropriate implementation in Compositing cve CVE-2025-13107 | |
| Inappropriate implementation in Google Updater in Google Chrome on Mac prior to 143.0.7499.41 allowed a remote attacker to perform privilege escalation via a crafted file. (Chromium security severity: High) cve CVE-2025-13631 | |
| chromium-browser: Use after free in Digital Credentials cve CVE-2025-13633 | |
| chromium-browser: Inappropriate implementation in Downloads cve CVE-2025-13635 | cvss |
| chromium-browser: Inappropriate implementation in Split View cve CVE-2025-13636 | |
| chromium-browser: Inappropriate implementation in Downloads cve CVE-2025-13637 | |
| chromium-browser: Use after free in Media Stream cve CVE-2025-13638 | cvss |
| chromium-browser: Inappropriate implementation in WebRTC cve CVE-2025-13639 | cvss |
| chromium-browser: Bad cast in Loader cve CVE-2025-13720 | cvss |
| chromium-browser: Race in v8 cve CVE-2025-13721 | cvss |
| chromium-browser: Side-channel information leakage in Navigation and Loading cve CVE-2025-13992 | cvss |
| Google Chromium Out of Bounds Memory Access Vulnerability cve CVE-2025-14174 | |
| Use after free in Password Manager in Google Chrome prior to 143.0.7499.110 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2025-14372 | |
| Inappropriate implementation in Toolbar in Google Chrome on Android prior to 143.0.7499.110 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2025-14373 | |
| chromium-browser: Chromium: Use after free in WebGPU allows remote attacker to exploit heap corruption cve CVE-2025-14765 | |
| chromium-browser: Google Chrome V8: Out-of-bounds read and write leads to heap corruption cve CVE-2025-14766 | |
| Google Chromium ANGLE and GPU Improper Input Validation Vulnerability cve CVE-2025-6558 | |
| chromium-browser: Out of bounds read in V8 cve CVE-2025-9479 | cvss |
| Inappropriate implementation in Extensions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2025-9866 | |
| chromium-browser: chromium-browser: Type confusion in V8 cve CVE-2026-102299 | |
| chromium-browser: chromium-browser: Uninitialized resource in WebGPU cve CVE-2026-102300 | cvss |
| chromium-browser: chromium-browser: Out of bounds write in GPU cve CVE-2026-102301 | |
| chromium-browser: chromium-browser: Buffer overflow in V8 cve CVE-2026-102302 | |
| chromium-browser: chromium-browser: Uninitialized resource in GPU cve CVE-2026-102303 | cvss |
| chromium-browser: chromium-browser: Use after free in Passwords cve CVE-2026-102304 | cvss severity |
| UI misrepresentation in SignIn in Google Chrome on on iOS prior to 154.0.8037.92 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-102305 | |
| Use after free in Bluetooth in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-102306 | |
| Uninitialized resource in Dawn in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-102307 | |
| Use after free in Views in Google Chrome prior to 154.0.8037.92 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-102308 | |
| chromium-browser: chromium-browser: Use after free in FullScreen cve CVE-2026-102309 | cvss severity |
| chromium-browser: chromium-browser: Missing authorization in Payments cve CVE-2026-102310 | cvss |
| chromium-browser: chromium-browser: Uninitialized resource in GPU cve CVE-2026-102311 | cvss severity |
| chromium-browser: chromium-browser: UI misrepresentation in Omnibox cve CVE-2026-102312 | |
| Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-102313 | |
| UI misrepresentation in TabStrip in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-102314 | |
| Uninitialized resource in Media in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-102315 | |
| Use after free in Views in Google Chrome prior to 154.0.8037.92 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-102316 | |
| Improper privilege management in Mojo in Google Chrome on on Windows prior to 154.0.8037.92 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) cve CVE-2026-102317 | |
| chromium-browser: chromium-browser: Out of bounds read in WebGL cve CVE-2026-102318 | cvss severity |
| Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-102319 | |
| chromium-browser: chromium-browser: Missing authorization in CORS cve CVE-2026-102320 | |
| chromium-browser: chromium-browser: Type confusion in V8 cve CVE-2026-102321 | |
| chromium-browser: chromium-browser: Type confusion in V8 cve CVE-2026-102323 | |
| chromium-browser: chromium-browser: Use after free in PictureInPicture cve CVE-2026-102324 | cvss |
| Uninitialized resource in Skia in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-102325 | |
| Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-102326 | |
| chromium-browser: chromium-browser: Incorrect authorization in WebView cve CVE-2026-102327 | cvss |
| Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-102328 | |
| chromium-browser: chromium-browser: Cross-site scripting in WebUI cve CVE-2026-102329 | cvss severity |
| chromium-browser: chromium-browser: Incorrect authorization in SiteIsolation cve CVE-2026-102330 | cvss severity |
| Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) cve CVE-2026-102331 | |
| Insufficient validation of untrusted input in Codecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially perform out of bounds memory access via a crafted video file. (Chromium security severity: Low) cve CVE-2026-13018 | |
| chromium-browser: angle: chromium-browser: Out of bounds read in ANGLE cve CVE-2026-17701 | cvss |
| chromium-browser: chromium-browser: Insufficient validation of untrusted input in Accessibility cve CVE-2026-17713 | cvss |
| chromium-browser: chromium-browser: Insufficient validation of untrusted input in Isolated Web Apps cve CVE-2026-17909 | cvss |
| chromium-browser: Use after free in Media cve CVE-2026-5883 | cvss |
| Missing authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: Medium) cve CVE-2026-78953 | |
| Google Chromium V8 Type Confusion Vulnerability cve CVE-2026-85046 | |
| Missing authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-87429 | |
| Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-87430 | |
| Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium) cve CVE-2026-87431 | |
| Race condition in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87433 | |
| Incomplete cleanup in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Medium) cve CVE-2026-87436 | |
| Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) cve CVE-2026-87438 | |
| Out of bounds read in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-87440 | |
| Missing authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium) cve CVE-2026-87441 | |
| Confused deputy in Prerender in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87442 | |
| chromium-browser: chromium-browser: Memory corruption in Codecs cve CVE-2026-87444 | |
| UI misrepresentation in Session in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87445 | |
| Incomplete cleanup in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium) cve CVE-2026-87446 | |
| Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: High) cve CVE-2026-87447 | |
| Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-87448 | |
| Incorrect authorization in Permissions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium) cve CVE-2026-87450 | |
| Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87455 | |
| Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium) cve CVE-2026-87457 | |
| chromium-browser: chromium-browser: Use after free in Platform cve CVE-2026-87460 | |
| Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) cve CVE-2026-87464 | |
| Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) cve CVE-2026-87467 | |
| chromium-browser: chromium-browser: Incorrect authorization in Isolated cve CVE-2026-87468 | cvss |
| Improper input validation in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy into a privileged page via crafted network traffic. (Chromium security severity: Low) cve CVE-2026-87469 | |
| chromium-browser: chromium-browser: Improper quantity validation in Tint cve CVE-2026-87470 | |
| chromium-browser: chromium-browser: Incorrect authorization in ServiceWorker cve CVE-2026-87471 | cvss |
| Improper input validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87472 | |
| Incorrect authorization in FileHandling in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-87473 | |
| Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-87474 | |
| chromium-browser: chromium-browser: Missing authorization in Omnibox cve CVE-2026-87475 | cvss |
| Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87479 | |
| Use after free in Printing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-87480 | |
| Incorrect authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87481 | |
| Cleartext transmission of sensitive data in HttpsUpgrades in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via crafted network traffic. (Chromium security severity: Medium) cve CVE-2026-87482 | |
| Incorrect authorization in Browser in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87483 | |
| UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87484 | |
| Clickjacking in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to spoof address bar via a co-installed app. (Chromium security severity: Medium) cve CVE-2026-87486 | |
| Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87487 | |
| Use after free in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) cve CVE-2026-87488 | |
| Memory corruption in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Low) cve CVE-2026-87489 | |
| Google Chromium V8 Out of Bounds Write Vulnerability cve CVE-2026-87491 | |
| Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-87492 | |
| Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87493 | |
| UI misrepresentation in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87496 | |
| chromium-browser: chromium-browser: Uninitialized resource in Codecs cve CVE-2026-87497 | |
| chromium-browser: chromium-browser: Incorrect authorization in Network cve CVE-2026-87499 | cvss |
| chromium-browser: angle: ANGLE in Google Chrome: Arbitrary code execution via crafted HTML page cve CVE-2026-87500 | |
| chromium-browser: chromium-browser: UI misrepresentation in Passwords cve CVE-2026-87501 | |
| Inappropriate implementation in Downloads in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87503 | |
| Use after free in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium) cve CVE-2026-87504 | |
| Incorrect authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: Medium) cve CVE-2026-87505 | |
| Privilege elevation in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87506 | |
| UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87507 | |
| Incorrect authorization in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Low) cve CVE-2026-87509 | |
| Improper input validation in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87510 | |
| Missing authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Low) cve CVE-2026-87511 | |
| chromium-browser: angle: Chromium-browser: Arbitrary code execution via use-after-free vulnerability in ANGLE cve CVE-2026-87512 | |
| Missing authorization in ControlledFrame in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87513 | |
| Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) cve CVE-2026-87514 | |
| Incorrect authorization in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87515 | |
| Incorrect authorization in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-87519 | |
| Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-87520 | |
| Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially bypass system access restrictions via crafted network traffic. (Chromium security severity: Low) cve CVE-2026-87522 | |
| Use after free in Core in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-87524 | |
| Out of bounds read in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to read memory outside the sandbox via a local program. (Chromium security severity: High) cve CVE-2026-87525 | |
| Use after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Medium) cve CVE-2026-87526 | |
| Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) cve CVE-2026-87527 | |
| chromium-browser: chromium-browser: Type confusion in Rust cve CVE-2026-87528 | |
| Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87529 | |
| Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium) cve CVE-2026-87530 | |
| Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87532 | |
| Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium) cve CVE-2026-87533 | |
| Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium) cve CVE-2026-87534 | |
| Information loss or omission in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87535 | |
| Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-87536 | |
| Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium) cve CVE-2026-87537 | |
| Clickjacking in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-87538 | |
| Observable discrepancy in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87539 | |
| Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87540 | |
| Information leak in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87541 | |
| Use after free in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-87542 | |
| Missing authorization in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-87543 | |
| Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-87544 | |
| Incorrect type conversion or cast in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted file. (Chromium security severity: Low) cve CVE-2026-87546 | |
| Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87547 | |
| Improper state validation in Installer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87548 | |
| Incomplete cleanup in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87549 | |
| Improper certificate validation in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low) cve CVE-2026-87551 | |
| Missing authorization in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: High) cve CVE-2026-87552 | |
| Improper input validation in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87553 | |
| Race condition in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) cve CVE-2026-87554 | |
| Missing authorization in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87556 | |
| Missing authorization in LocalNetworkAccess in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87557 | |
| Use after free in Payments in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-87558 | |
| Missing authorization in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87560 | |
| Incorrect authorization in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Low) cve CVE-2026-87561 | |
| Missing authorization in Views in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-87569 | |
| Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted file. (Chromium security severity: Medium) cve CVE-2026-87570 | |
| Improper certificate validation in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low) cve CVE-2026-87571 | |
| Injection in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-87572 | |
| Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-87575 | |
| Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87577 | |
| Use after free in Receiver in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High) cve CVE-2026-87578 | |
| Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87579 | |
| Incorrect authorization in WebAppInstalls in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87580 | |
| Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-87581 | |
| Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87582 | |
| UI misrepresentation in Passwords in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-87583 | |
| Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87584 | |
| Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High) cve CVE-2026-87585 | |
| chromium-browser: angle: ANGLE in Google Chrome: Information disclosure via crafted HTML page cve CVE-2026-87586 | cvss |
| Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-87587 | |
| chromium-browser: chromium-browser: Use after free in Chromecast cve CVE-2026-87588 | |
| Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87589 | |
| Improper input validation in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially leak sensitive information via crafted network traffic. (Chromium security severity: Medium) cve CVE-2026-87590 | |
| Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium) cve CVE-2026-87591 | |
| Out of bounds read in Tint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-87592 | |
| Server-side request forgery in Mobile in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-87595 | |
| chromium-browser: angle: ANGLE in Google Chrome: Information disclosure via out-of-bounds read cve CVE-2026-87596 | cvss |
| UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to spoof address bar via a co-installed app. (Chromium security severity: Low) cve CVE-2026-87597 | |
| Improper input validation in Interstitials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87599 | |
| Improper input validation in Safebrowsing in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87600 | |
| Race condition in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-87601 | |
| Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87603 | |
| chromium-browser: angle: ANGLE in Google Chrome: Arbitrary code execution via out-of-bounds read cve CVE-2026-87604 | cvss |
| Missing authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87606 | |
| Use after free in Device in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-87607 | |
| Improper certificate validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low) cve CVE-2026-87608 | |
| Use after free in Sharing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium) cve CVE-2026-87609 | |
| Incorrect authorization in Omnibox in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87610 | |
| chromium-browser: chromium-browser: Type confusion in V8 cve CVE-2026-87612 | |
| Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium) cve CVE-2026-87613 | |
| Race condition in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87615 | |
| chromium-browser: chromium-browser: Improper initialization in Views cve CVE-2026-87616 | cvss |
| Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-87617 | |
| Incorrect reference resolution in Storage in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-87618 | |
| chromium-browser: angle: Google Chrome (ANGLE): Arbitrary Code Execution vulnerability cve CVE-2026-87621 | |
| UI misrepresentation in Passwords in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-87624 | |
| Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium) cve CVE-2026-87625 | |
| chromium-browser: chromium-browser: Incorrect authorization in DeviceBoundSessionCredentials cve CVE-2026-87626 | |
| Interpretation conflict in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted file. (Chromium security severity: Low) cve CVE-2026-87627 | |
| Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Critical) cve CVE-2026-87628 | |
| Integer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87630 | |
| Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High) cve CVE-2026-87633 | |
| Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-87634 | |
| chromium-browser: chromium-browser: Type confusion in XML cve CVE-2026-87636 | |
| chromium-browser: chromium-browser: Use after free in Extensions cve CVE-2026-87637 | |
| Out of bounds write in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87638 | |
| Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-87639 | |
| Out of bounds read in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87640 | |
| Race condition in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87641 | |
| Integer overflow in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87643 | |
| Incorrect authorization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87644 | |
| chromium-browser: chromium-browser: Improper state validation in Safebrowsing cve CVE-2026-87645 | |
| Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-87646 | |
| chromium-browser: angle: ANGLE: Arbitrary code execution in Google Chrome due to use-after-free cve CVE-2026-87648 | cvss |
| UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-87649 | |
| Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-87650 | |
| chromium-browser: angle: Chromium: Arbitrary code execution via buffer overflow in ANGLE cve CVE-2026-87654 | |
| Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-87656 | |
| chromium-browser: chromium-browser: Race condition in Network cve CVE-2026-91708 | cvss |
| chromium-browser: chromium-browser: Type confusion in ServiceWorker cve CVE-2026-91709 | |
| chromium-browser: chromium-browser: Use after free in WebAppInstalls cve CVE-2026-91710 | |
| chromium-browser: chromium-browser: Out of bounds write in ServiceWorker cve CVE-2026-91711 | |
| chromium-browser: chromium-browser: Race condition in Extensions cve CVE-2026-91712 | cvss |
| chromium-browser: chromium-browser: Missing authorization in Browser cve CVE-2026-91713 | cvss |
| chromium-browser: chromium-browser: Observable discrepancy in Fonts cve CVE-2026-91714 | cvss |
| chromium-browser: chromium-browser: Type confusion in ServiceWorker cve CVE-2026-91715 | |
| chromium-browser: chromium-browser: Use after free in Auth cve CVE-2026-91716 | |
| chromium-browser: chromium-browser: Missing authorization in Android cve CVE-2026-91717 | cvss |
| chromium-browser: chromium-browser: Use after free in Core cve CVE-2026-91718 | |
| chromium-browser: chromium-browser: Code injection in XML cve CVE-2026-91719 | cvss |
| chromium-browser: angle: chromium-browser: Uninitialized resource in ANGLE cve CVE-2026-91720 | cvss |
| chromium-browser: chromium-browser: Use after free in Internals cve CVE-2026-91721 | cvss |
| chromium-browser: chromium-browser: Use after free in Input cve CVE-2026-91722 | cvss |
| chromium-browser: chromium-browser: Race condition in WebAppInstalls cve CVE-2026-91723 | cvss |
| chromium-browser: chromium-browser: Use after free in Input cve CVE-2026-91724 | cvss |
| chromium-browser: chromium-browser: Observable discrepancy in CSS cve CVE-2026-91725 | cvss |
| chromium-browser: chromium-browser: Out of bounds read in WebGL cve CVE-2026-91726 | cvss |
| chromium-browser: chromium-browser: Incorrect reference resolution in Extensions cve CVE-2026-91727 | cvss |
| chromium-browser: chromium-browser: Integer overflow in V8 cve CVE-2026-91728 | cvss |
| Use after free in DigitalCredentials in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-91729 | |
| chromium-browser: chromium-browser: Incomplete cleanup in GetUserMedia cve CVE-2026-91730 | cvss |
| chromium-browser: chromium-browser: Type confusion in Compositing cve CVE-2026-91731 | |
| chromium-browser: chromium-browser: Missing authorization in AppManifest cve CVE-2026-91732 | cvss |
| chromium-browser: skia: Skia in chromium-browser: Information disclosure via improper state validation cve CVE-2026-91733 | cvss |
| chromium-browser: chromium-browser: Incorrect authorization in Core cve CVE-2026-91734 | cvss |
| chromium-browser: chromium-browser: Incorrect authorization in WebUI cve CVE-2026-91735 | cvss |
| chromium-browser: chromium-browser: Use after free in DOM cve CVE-2026-91736 | |
| Use after free in PDF in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-91737 | |
| chromium-browser: angle: chromium-browser: Improper input validation in ANGLE cve CVE-2026-91738 | |
| chromium-browser: chromium-browser: Missing authorization in Transactions Platform cve CVE-2026-91739 | cvss |
| chromium-browser: skia: Google Chrome: Cross-origin data disclosure due to uninitialized resource in Skia cve CVE-2026-91740 | cvss |
| chromium-browser: chromium-browser: Type confusion in CacheStorage cve CVE-2026-91741 | |
| Confused deputy in PriceTracking in Google Chrome on on iOS prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to bypass system access restrictions into a privileged page via crafted network traffic. (Chromium security severity: Medium) cve CVE-2026-91742 | |
| chromium-browser: chromium-browser: Race condition in Core cve CVE-2026-91743 | cvss |
| chromium-browser: chromium-browser: Race condition in PlatformIntegration cve CVE-2026-91744 | cvss |
| chromium-browser: chromium-browser: Use after free in V8 cve CVE-2026-91745 | |
| chromium-browser: chromium-browser: Integer overflow in Compositing cve CVE-2026-91746 | cvss |
| chromium-browser: skia: Skia: Cross-origin data disclosure via use-after-free vulnerability cve CVE-2026-91747 | cvss |
| chromium-browser: chromium-browser: Race condition in Extensions cve CVE-2026-91748 | cvss |
| chromium-browser: chromium-browser: Use after free in Workers cve CVE-2026-91749 | |
| Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) cve CVE-2026-93372 | |
| Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: High) cve CVE-2026-93373 | |
| Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) cve CVE-2026-93374 | |
| Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) cve CVE-2026-93375 | |
| Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social engineering to read memory outside the sandbox via a local program. (Chromium security severity: Medium) cve CVE-2026-93376 | |
| Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-93377 | |
| Missing authorization in Storage in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: Medium) cve CVE-2026-93378 | |
| Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-93379 | |
| chromium-browser: chromium-browser: Race condition in FileSystem cve CVE-2026-93380 | cvss |
| Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High) cve CVE-2026-93381 | |
| Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-93382 | |
| Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-93383 | |
| Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium) cve CVE-2026-93384 | |
| Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-93385 | |
| UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-93386 | |
| chromium-browser: skia: Google Chrome Skia: Cross-origin data disclosure via improper state validation cve CVE-2026-93387 | cvss |
| chromium-browser: chromium-browser: Improper output encoding in DevTools cve CVE-2026-95274 | cvss |
| Improper input validation in Themes in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code inside the sandbox via crafted network traffic. (Chromium security severity: Medium) cve CVE-2026-95276 | |
| Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-95277 | |
| UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-95279 | |
| Race condition in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-95280 | |
| Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) cve CVE-2026-95281 | |
| chromium-browser: chromium-browser: Use after free in Platform cve CVE-2026-95282 | |
| Buffer overflow in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-95283 | |
| Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) cve CVE-2026-95284 | |
| Type confusion in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-95286 | |
| Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-95287 | |
| UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-95288 | |
| Incorrect authorization in Scroll in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-95289 | |
| Missing authorization in NFC in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-95290 | |
| chromium-browser: chromium-browser: UI misrepresentation in SecurityIndicators cve CVE-2026-95291 | cvss |
| Incorrect authorization in Safebrowsing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: Low) cve CVE-2026-95292 | |
| chromium-browser: chromium-browser: Uninitialized resource in GPU cve CVE-2026-95293 | cvss severity |
| UI misrepresentation in Browser in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-95294 | |
| Information leak in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a local attacker to leak sensitive information via physical access. (Chromium security severity: Medium) cve CVE-2026-95295 | |
| Missing authorization in Core in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-95296 | |
| chromium-browser: chromium-browser: Missing authorization in Contextual Tasks cve CVE-2026-95297 | |
| Use after free in Browser in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High) cve CVE-2026-95298 | |
| Use after free in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-95299 | |
| Missing authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium) cve CVE-2026-95300 | |
| chromium-browser: chromium-browser: Missing authorization in Extensions cve CVE-2026-95301 | |
| Incorrect authorization in WebAPKs in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to obtain cross-origin data via a co-installed app. (Chromium security severity: Medium) cve CVE-2026-95302 | |
| chromium-browser: chromium-browser: Out of bounds write in V8 cve CVE-2026-95304 | |
| UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic. (Chromium security severity: Low) cve CVE-2026-95305 | |
| chromium-browser: chromium-browser: Type confusion in V8 cve CVE-2026-95306 | |
| UI misrepresentation in ExtensionsMenu in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-95307 | |
| Integer overflow in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-95308 | |
| UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-95309 | |
| chromium-browser: chromium-browser: Use after free in AdFilter cve CVE-2026-95310 | severity |
| Free of non-heap memory in Fonts in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-95311 | |
| Information leak in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-95312 | |
| Use after free in Fullscreen in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) cve CVE-2026-95313 | |
| chromium-browser: chromium-browser: Use after free in Aura cve CVE-2026-95315 | cvss |
| chromium-browser: chromium-browser: Unchecked return value in Performance cve CVE-2026-95316 | cvss |
| chromium-browser: chromium-browser: Incorrect authorization in MediaCapture cve CVE-2026-95317 | cvss severity |
| Buffer overflow in Video in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-95318 | |
| Use after free in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-95319 | |
| Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-95320 | |
| UI misrepresentation in Payments in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-95321 | |
| Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) cve CVE-2026-95322 | |
| UI misrepresentation in Chromium in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof address bar via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-95323 | |
| chromium-browser: chromium-browser: Uninitialized resource in GPU cve CVE-2026-95324 | cvss severity |
| Use after free in ANGLE in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-95325 | |
| Information leak in Networking in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-95327 | |
| Confused deputy in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker leveraging social engineering to obtain sensitive information via a co-installed app. (Chromium security severity: Low) cve CVE-2026-95328 | |
| chromium-browser: chromium-browser: Out of bounds write in WebGL cve CVE-2026-95329 | severity |
| Improper state validation in Downloads in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-95330 | |
| Out of bounds write in ANGLE in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-95331 | |
| chromium-browser: chromium-browser: Use of uninitialized variable in Tint cve CVE-2026-95332 | cvss |
| chromium-browser: chromium-browser: Use after free in Metrics cve CVE-2026-95333 | |
| Incorrect reference resolution in WebProtect in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-95334 | |
| Use after free in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-95335 | |
| Information leak in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-95336 | |
| UI misrepresentation in Messages in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-95337 | |
| Use after free in PDFium in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High) cve CVE-2026-95338 | |
| Use after free in ServiceWorker in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) cve CVE-2026-95339 | |
| Incorrect authorization in PictureInPicture in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-95340 | |
| Improper input validation in Desktop in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium) cve CVE-2026-95341 | |
| chromium-browser: chromium-browser: Missing authorization in V8 cve CVE-2026-95342 | |
| Use after free in WebAudio in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-95343 | |
| Race condition in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass site isolation via a crafted Chrome extension. (Chromium security severity: Medium) cve CVE-2026-95344 | |
| Use after free in Actor in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-95345 | |
| UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via crafted network traffic. (Chromium security severity: Medium) cve CVE-2026-95346 | |
| chromium-browser: chromium-browser: Use after free in Updater cve CVE-2026-95347 | cvss severity |
| Use after free in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-95348 | |
| Buffer overflow in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) cve CVE-2026-95349 | |
| Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) cve CVE-2026-95350 | |
| chromium-browser: chromium-browser: Use after free in Views cve CVE-2026-95351 | cvss |
| Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Low) cve CVE-2026-95352 | |
| Use after free in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-95353 | |
| chromium-browser: chromium-browser: Use after free in Verifier cve CVE-2026-95354 | cvss |
| chromium-browser: chromium-browser: Incorrect authorization in Navigation cve CVE-2026-95355 | cvss |
| Use after free in WindowDialog in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) cve CVE-2026-95356 | |
| chromium-browser: chromium-browser: Out of bounds write in GPU cve CVE-2026-95357 | severity |
| Incorrect authorization in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to bypass system access restrictions into a privileged page via a co-installed app. (Chromium security severity: Medium) cve CVE-2026-95358 | |
| chromium-browser: chromium-browser: Uninitialized resource in GPU cve CVE-2026-95359 | cvss severity |
| Race condition in Editing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-95360 | |
| Confused deputy in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-95361 | |
| Cross-site request forgery in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-95362 | |
| UI misrepresentation in FileSystem in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-95363 | |
| Improper input validation in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-95364 | |
| Type confusion in IndexedDB in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-95365 | |
| Use of released resource in Core in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-95366 | |
| Information leak in DataTransfer in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-95367 | |
| Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-95368 | |
| Inappropriate implementation in XML in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-95369 | |
| Inappropriate implementation in NFC in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-95370 | |
| Missing authorization in Views in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-95371 | |
| Use after free in Chromecast in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-95372 | |
| chromium-browser: chromium-browser: Use after free in DevTools cve CVE-2026-95373 | |
| Incorrect authorization in Network in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-95374 | |
| Incorrect authorization in BrowserTag in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-95375 | |
| Externally controlled reference in DevTools in Google Chrome prior to 154.0.8037.57 allowed an adjacent attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium) cve CVE-2026-95376 | |
| chromium-browser: chromium: type confusion in V8 cve CVE-2026-95380 | |
| Improper input validation in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-95381 | |
| chromium-browser: chromium-browser: Improper input validation in Auth cve CVE-2026-95382 | cvss |
| Race condition in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2026-95384 | |
| Inappropriate implementation in PlatformIntegration in Google Chrome on on Windows prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) cve CVE-2026-95385 | |