Patch & vulnerability status
Google LLC
Google Chrome 148.0.7778.217
Latest tracked version 148.0.7778.217. Release status, tracked CVEs, and automated cross-platform patching for Google Chrome.
Category: Browsers
| Platform | Latest version | CVEs tracked | Last checked |
|---|---|---|---|
| Windows | 148.0.7778.217 | 6075 | 2024-08-27 |
Known vulnerabilities (CVEs) in Google Chrome
Lavawall tracks 6075 published CVEs affecting Google Chrome, and deploys the versions that fix them automatically across your fleet.
| CVE | Published | Severity | Details | Vector |
|---|---|---|---|---|
| CVE-2026-9999 | 2026-05-28 23:16:58 | HIGH (9) | Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9998 | 2026-05-28 23:16:58 | HIGH (8) | Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9997 | 2026-05-28 23:16:58 | HIGH (8) | Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9996 | 2026-05-28 23:16:58 | MEDIUM (7) | Out of bounds read in WebRTC in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9995 | 2026-05-28 23:16:58 | HIGH (9) | Use after free in WebXR in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9994 | 2026-05-28 23:16:58 | HIGH (8) | Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9993 | 2026-05-28 23:16:58 | HIGH (8) | Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. (Chromium security severity: High) | NETWORK |
| CVE-2026-9992 | 2026-05-28 23:16:57 | HIGH (9) | Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9991 | 2026-05-28 23:16:57 | LOW (3) | Inappropriate implementation in Media in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9990 | 2026-05-28 23:16:57 | HIGH (8) | Use after free in WebAppInstalls in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9989 | 2026-05-28 23:16:57 | MEDIUM (6) | Inappropriate implementation in Media in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to bypass same origin policy via a crafted video file. (Chromium security severity: High) | NETWORK |
| CVE-2026-9988 | 2026-05-28 23:16:57 | HIGH (8) | Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9987 | 2026-05-28 23:16:57 | HIGH (8) | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 148.0.7778.216 allowed a local attacker to execute arbitrary code via a malicious file. (Chromium security severity: High) | LOCAL |
| CVE-2026-9986 | 2026-05-28 23:16:57 | MEDIUM (4) | Insufficient validation of untrusted input in OptimizationGuide in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9985 | 2026-05-28 23:16:57 | MEDIUM (5) | Insufficient validation of untrusted input in Media in Google Chrome on ChromeOS prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9984 | 2026-05-28 23:16:57 | HIGH (9) | Use after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9983 | 2026-05-28 23:16:57 | HIGH (9) | Type Confusion in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9982 | 2026-05-28 23:16:56 | HIGH (8) | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9981 | 2026-05-28 23:16:56 | MEDIUM (7) | Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9980 | 2026-05-28 23:16:56 | MEDIUM (5) | Insufficient validation of untrusted input in Printing in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9979 | 2026-05-28 23:16:56 | MEDIUM (5) | Insufficient validation of untrusted input in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9978 | 2026-05-28 23:16:56 | HIGH (9) | Use after free in Glic in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9977 | 2026-05-28 23:16:56 | HIGH (8) | Insufficient validation of untrusted input in WebShare in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9976 | 2026-05-28 23:16:56 | HIGH (9) | Inappropriate implementation in USB in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9975 | 2026-05-28 23:16:56 | HIGH (8) | Out of bounds read and write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9974 | 2026-05-28 23:16:56 | HIGH (8) | Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9973 | 2026-05-28 23:16:56 | HIGH (9) | Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9972 | 2026-05-28 23:16:55 | HIGH (8) | Uninitialized Use in Gamepad in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9971 | 2026-05-28 23:16:55 | MEDIUM (5) | Inappropriate implementation in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9970 | 2026-05-28 23:16:55 | HIGH (8) | Use after free in WebGL in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9969 | 2026-05-28 23:16:55 | HIGH (9) | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9968 | 2026-05-28 23:16:55 | HIGH (9) | Integer overflow in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9967 | 2026-05-28 23:16:55 | CRITICAL (10) | Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9966 | 2026-05-28 23:16:55 | HIGH (8) | Integer overflow in XML in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9965 | 2026-05-28 23:16:55 | HIGH (9) | Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9964 | 2026-05-28 23:16:55 | HIGH (8) | Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: High) | NETWORK |
| CVE-2026-9963 | 2026-05-28 23:16:55 | HIGH (8) | Uninitialized Use in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9962 | 2026-05-28 23:16:54 | HIGH (9) | Use after free in WebRTC in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9961 | 2026-05-28 23:16:54 | HIGH (9) | Use after free in SurfaceCapture in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9960 | 2026-05-28 23:16:54 | HIGH (8) | Integer overflow in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted font file. (Chromium security severity: High) | NETWORK |
| CVE-2026-9959 | 2026-05-28 23:16:54 | LOW (3) | Race in WebRTC in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9958 | 2026-05-28 23:16:54 | HIGH (9) | Use after free in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High) | NETWORK |
| CVE-2026-9957 | 2026-05-28 23:16:54 | HIGH (9) | Use after free in PDF in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High) | NETWORK |
| CVE-2026-9956 | 2026-05-28 23:16:54 | HIGH (8) | Use after free in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9955 | 2026-05-28 23:16:54 | MEDIUM (4) | Inappropriate implementation in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9954 | 2026-05-28 23:16:54 | HIGH (8) | Use after free in TabStrip in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9953 | 2026-05-28 23:16:53 | MEDIUM (7) | Out of bounds read in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9952 | 2026-05-28 23:16:53 | HIGH (9) | Use after free in WebAudio in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9951 | 2026-05-28 23:16:53 | HIGH (8) | Use after free in UI in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9950 | 2026-05-28 23:16:53 | LOW (3) | Insufficient validation of untrusted input in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9949 | 2026-05-28 23:16:53 | HIGH (8) | Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9948 | 2026-05-28 23:16:53 | HIGH (8) | Use after free in Views in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9947 | 2026-05-28 23:16:53 | HIGH (9) | Use after free in XML in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9946 | 2026-05-28 23:16:53 | HIGH (8) | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9945 | 2026-05-28 23:16:53 | HIGH (9) | Use after free in Media in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9944 | 2026-05-28 23:16:53 | LOW (3) | Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9943 | 2026-05-28 23:16:52 | MEDIUM (4) | Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9942 | 2026-05-28 23:16:52 | MEDIUM (5) | Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9941 | 2026-05-28 23:16:52 | HIGH (9) | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9940 | 2026-05-28 23:16:52 | HIGH (9) | Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9939 | 2026-05-28 23:16:52 | HIGH (9) | Heap buffer overflow in WebCodecs in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9938 | 2026-05-28 23:16:52 | HIGH (9) | Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9937 | 2026-05-28 23:16:52 | HIGH (8) | Use after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9936 | 2026-05-28 23:16:52 | HIGH (8) | Use after free in GFX in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9935 | 2026-05-28 23:16:52 | MEDIUM (4) | Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9934 | 2026-05-28 23:16:52 | HIGH (8) | Use after free in Aura in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9933 | 2026-05-28 23:16:51 | HIGH (8) | Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9932 | 2026-05-28 23:16:51 | HIGH (8) | Use after free in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9931 | 2026-05-28 23:16:51 | HIGH (8) | Use after free in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9930 | 2026-05-28 23:16:51 | MEDIUM (4) | Out of bounds write in Dawn in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9929 | 2026-05-28 23:16:51 | MEDIUM (4) | Inappropriate implementation in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9928 | 2026-05-28 23:16:51 | HIGH (9) | Out of bounds read in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9927 | 2026-05-28 23:16:51 | HIGH (9) | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9926 | 2026-05-28 23:16:51 | HIGH (8) | Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9925 | 2026-05-28 23:16:51 | HIGH (8) | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9924 | 2026-05-28 23:16:51 | HIGH (8) | Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9923 | 2026-05-28 23:16:50 | HIGH (9) | Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9922 | 2026-05-28 23:16:50 | HIGH (8) | Use after free in GPU in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9921 | 2026-05-28 23:16:50 | MEDIUM (4) | Uninitialized Use in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin information via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9920 | 2026-05-28 23:16:50 | LOW (3) | Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9919 | 2026-05-28 23:16:50 | MEDIUM (4) | Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9918 | 2026-05-28 23:16:50 | CRITICAL (10) | Inappropriate implementation in Tint in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9917 | 2026-05-28 23:16:50 | MEDIUM (7) | Uninitialized Use in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9916 | 2026-05-28 23:16:50 | HIGH (8) | Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9915 | 2026-05-28 23:16:50 | HIGH (8) | Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9914 | 2026-05-28 23:16:49 | HIGH (8) | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9913 | 2026-05-28 23:16:49 | MEDIUM (4) | Inappropriate implementation in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9912 | 2026-05-28 23:16:49 | MEDIUM (7) | Inappropriate implementation in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9911 | 2026-05-28 23:16:49 | MEDIUM (4) | Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9910 | 2026-05-28 23:16:49 | HIGH (9) | Out of bounds memory access in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9909 | 2026-05-28 23:16:49 | HIGH (8) | Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9908 | 2026-05-28 23:16:49 | MEDIUM (7) | Out of bounds read in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9907 | 2026-05-28 23:16:49 | MEDIUM (4) | Out of bounds read in Dawn in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9906 | 2026-05-28 23:16:49 | HIGH (8) | Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9905 | 2026-05-28 23:16:49 | HIGH (8) | Use after free in Accessibility in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9904 | 2026-05-28 23:16:48 | HIGH (8) | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9903 | 2026-05-28 23:16:48 | MEDIUM (5) | Insufficient validation of untrusted input in Site Isolation in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted MHTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9902 | 2026-05-28 23:16:48 | HIGH (8) | Use after free in Accessibility in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9901 | 2026-05-28 23:16:48 | HIGH (8) | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9900 | 2026-05-28 23:16:48 | HIGH (8) | Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9899 | 2026-05-28 23:16:48 | HIGH (8) | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9898 | 2026-05-28 23:16:48 | HIGH (8) | Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9897 | 2026-05-28 23:16:48 | HIGH (9) | Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9896 | 2026-05-28 23:16:48 | HIGH (9) | Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9895 | 2026-05-28 23:16:47 | HIGH (8) | Out of bounds read in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9894 | 2026-05-28 23:16:47 | HIGH (8) | Use after free in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9893 | 2026-05-28 23:16:47 | HIGH (8) | Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-9892 | 2026-05-28 23:16:47 | HIGH (8) | Inappropriate implementation in Skia in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-9891 | 2026-05-28 23:16:47 | CRITICAL (9) | Use after free in Extensions in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-9890 | 2026-05-28 23:16:47 | HIGH (8) | Use after free in XR in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-9889 | 2026-05-28 23:16:47 | HIGH (8) | Out of bounds read and write in Dawn in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-9888 | 2026-05-28 23:16:47 | HIGH (8) | Use after free in WebView in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-9887 | 2026-05-28 23:16:47 | HIGH (9) | Use after free in Proxy in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted PAC script. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-9886 | 2026-05-28 23:16:47 | CRITICAL (10) | Use after free in Base in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-9885 | 2026-05-28 23:16:46 | HIGH (8) | Insufficient validation of untrusted input in UI in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-9884 | 2026-05-28 23:16:46 | HIGH (9) | Use after free in Browser in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-9883 | 2026-05-28 23:16:46 | HIGH (9) | Use after free in Base in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-9882 | 2026-05-28 23:16:46 | MEDIUM (7) | Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-9881 | 2026-05-28 23:16:46 | CRITICAL (9) | Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-9880 | 2026-05-28 23:16:46 | HIGH (8) | Insufficient validation of untrusted input in WebGL in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-9879 | 2026-05-28 23:16:46 | HIGH (9) | Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-9878 | 2026-05-28 23:16:46 | HIGH (9) | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-9877 | 2026-05-28 23:16:46 | HIGH (8) | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-9876 | 2026-05-28 23:16:46 | CRITICAL (10) | Use after free in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-9875 | 2026-05-28 23:16:45 | CRITICAL (10) | Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-9874 | 2026-05-28 23:16:45 | CRITICAL (10) | Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-9873 | 2026-05-28 23:16:45 | HIGH (9) | Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-9872 | 2026-05-28 23:16:45 | CRITICAL (10) | Out of bounds write in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-9126 | 2026-05-20 20:16:46 | HIGH (9) | Use after free in DOM in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-9124 | 2026-05-20 20:16:45 | MEDIUM (5) | Insufficient validation of untrusted input in Input in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-9123 | 2026-05-20 20:16:45 | HIGH (8) | Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148.0.7778.179 allowed a local attacker to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: Medium) | ADJACENT_NETWORK |
| CVE-2026-9122 | 2026-05-20 20:16:45 | MEDIUM (7) | Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-9121 | 2026-05-20 20:16:45 | HIGH (9) | Out of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-9120 | 2026-05-20 20:16:44 | HIGH (9) | Use after free in WebRTC in Google Chrome prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9119 | 2026-05-20 20:16:43 | HIGH (9) | Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9118 | 2026-05-20 20:16:43 | HIGH (9) | Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9117 | 2026-05-20 20:16:43 | HIGH (8) | Type Confusion in GFX in Google Chrome on Linux, ChromeOS prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: High) | NETWORK |
| CVE-2026-9116 | 2026-05-20 20:16:43 | MEDIUM (4) | Insufficient policy enforcement in ServiceWorker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9115 | 2026-05-20 20:16:43 | MEDIUM (4) | Insufficient policy enforcement in Service Worker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9114 | 2026-05-20 20:16:42 | HIGH (9) | Use after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: High) | NETWORK |
| CVE-2026-9113 | 2026-05-20 20:16:42 | MEDIUM (4) | Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9112 | 2026-05-20 20:16:42 | HIGH (9) | Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-9111 | 2026-05-20 20:16:42 | HIGH (9) | Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-9110 | 2026-05-20 20:16:42 | MEDIUM (4) | Inappropriate implementation in UI in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-8587 | 2026-05-14 20:17:21 | HIGH (9) | Use after free in Extensions in Google Chrome on Mac prior to 148.0.7778.168 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-8586 | 2026-05-14 20:17:21 | MEDIUM (6) | Inappropriate implementation in Chromoting in Google Chrome prior to 148.0.7778.168 allowed a local attacker to bypass discretionary access control via a malicious file. (Chromium security severity: Medium) | ADJACENT_NETWORK |
| CVE-2026-8585 | 2026-05-14 20:17:21 | HIGH (8) | Inappropriate implementation in Media in Google Chrome on iOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-8584 | 2026-05-14 20:17:21 | MEDIUM (4) | Inappropriate implementation in Views in Google Chrome on iOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-8583 | 2026-05-14 20:17:21 | MEDIUM (5) | Insufficient policy enforcement in WebXR in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-8582 | 2026-05-14 20:17:21 | MEDIUM (5) | Object lifecycle issue in Dawn in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-8581 | 2026-05-14 20:17:20 | HIGH (9) | Use after free in GPU in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-8580 | 2026-05-14 20:17:20 | CRITICAL (10) | Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-8579 | 2026-05-14 20:17:20 | LOW (3) | Insufficient validation of untrusted input in Skia in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted print file. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-8578 | 2026-05-14 20:17:20 | LOW (3) | Out of bounds read in GPU in Google Chrome on Linux prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-8577 | 2026-05-14 20:17:20 | HIGH (9) | Integer overflow in Fonts in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-8576 | 2026-05-14 20:17:20 | MEDIUM (4) | Inappropriate implementation in CORS in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-8575 | 2026-05-14 20:17:20 | HIGH (8) | Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-8574 | 2026-05-14 20:17:20 | HIGH (8) | Use after free in Core in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-8573 | 2026-05-14 20:17:20 | HIGH (8) | Integer overflow in Codecs in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-8572 | 2026-05-14 20:17:19 | LOW (3) | Insufficient policy enforcement in Network in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-8571 | 2026-05-14 20:17:19 | HIGH (8) | Insufficient policy enforcement in GPU in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-8570 | 2026-05-14 20:17:19 | MEDIUM (7) | Type Confusion in V8 in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-8569 | 2026-05-14 20:17:19 | HIGH (8) | Out of bounds write in Codecs in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-8568 | 2026-05-14 20:17:19 | LOW (3) | Insufficient policy enforcement in AI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to bypass Site Isolation via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-8567 | 2026-05-14 20:17:19 | MEDIUM (4) | Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-8566 | 2026-05-14 20:17:19 | MEDIUM (4) | Insufficient policy enforcement in Payments in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-8565 | 2026-05-14 20:17:19 | MEDIUM (5) | Inappropriate implementation in Downloads in Google Chrome on Mac prior to 148.0.7778.168 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-8564 | 2026-05-14 20:17:19 | MEDIUM (4) | Incorrect security UI in Downloads in Google Chrome on Android and Mac prior to 148.0.7778.168 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-8563 | 2026-05-14 20:17:18 | MEDIUM (4) | Insufficient policy enforcement in IFrame Sandbox in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-8562 | 2026-05-14 20:17:18 | MEDIUM (4) | Side-channel information leakage in Navigation in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-8561 | 2026-05-14 20:17:18 | MEDIUM (5) | Incorrect security UI in Fullscreen in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-8560 | 2026-05-14 20:17:18 | MEDIUM (4) | Heap buffer overflow in SwiftShader in Google Chrome on Mac and iOS prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-8559 | 2026-05-14 20:17:18 | MEDIUM (4) | Integer overflow in Internationalization in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8558 | 2026-05-14 20:17:18 | HIGH (9) | Out of bounds write in Fonts in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8557 | 2026-05-14 20:17:17 | HIGH (8) | Use after free in Accessibility in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8556 | 2026-05-14 20:17:17 | LOW (3) | Inappropriate implementation in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8555 | 2026-05-14 20:17:17 | HIGH (9) | Use after free in GTK in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8554 | 2026-05-14 20:17:17 | LOW (3) | Type Confusion in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8553 | 2026-05-14 20:17:17 | LOW (3) | Use after free in GPU in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8552 | 2026-05-14 20:17:16 | MEDIUM (4) | Heap buffer overflow in GPU in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8551 | 2026-05-14 20:17:16 | HIGH (9) | Use after free in Downloads in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8550 | 2026-05-14 20:17:16 | MEDIUM (7) | Use after free in Google Lens in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8549 | 2026-05-14 20:17:16 | HIGH (9) | Use after free in Media in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8548 | 2026-05-14 20:17:16 | HIGH (8) | Out of bounds write in Media in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8547 | 2026-05-14 20:17:16 | HIGH (8) | Insufficient policy enforcement in Passwords in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8546 | 2026-05-14 20:17:16 | MEDIUM (5) | Out of bounds read in GPU in Google Chrome on Mac and Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8545 | 2026-05-14 20:17:15 | LOW (3) | Object corruption in Compositing in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8544 | 2026-05-14 20:17:15 | HIGH (9) | Use after free in Media in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8543 | 2026-05-14 20:17:15 | MEDIUM (5) | Out of bounds read in FileSystem in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8542 | 2026-05-14 20:17:15 | HIGH (8) | Use after free in Core in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8541 | 2026-05-14 20:17:15 | MEDIUM (5) | Out of bounds read in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8540 | 2026-05-14 20:17:15 | HIGH (9) | Type Confusion in V8 in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8539 | 2026-05-14 20:17:15 | MEDIUM (5) | Script injection in SanitizerAPI in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8538 | 2026-05-14 20:17:15 | MEDIUM (5) | Insufficient validation of untrusted input in GPU in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform a denial of service via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8537 | 2026-05-14 20:17:15 | MEDIUM (4) | Insufficient policy enforcement in ViewTransitions in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8536 | 2026-05-14 20:17:14 | LOW (3) | Insufficient validation of untrusted input in ReadingMode in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to bypass site Isolation via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8535 | 2026-05-14 20:17:14 | MEDIUM (5) | Out of bounds read in Media in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted JPEG file. (Chromium security severity: High) | NETWORK |
| CVE-2026-8534 | 2026-05-14 20:17:14 | HIGH (8) | Integer overflow in GPU in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8533 | 2026-05-14 20:17:14 | HIGH (8) | Use after free in Accessibility in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8532 | 2026-05-14 20:17:14 | HIGH (9) | Integer overflow in XML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8531 | 2026-05-14 20:17:14 | HIGH (9) | Heap buffer overflow in WebML in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8530 | 2026-05-14 20:17:14 | HIGH (8) | Use after free in Network in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8529 | 2026-05-14 20:17:14 | HIGH (9) | Heap buffer overflow in Codecs in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: High) | NETWORK |
| CVE-2026-8528 | 2026-05-14 20:17:14 | MEDIUM (4) | Insufficient validation of untrusted input in SiteIsolation in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to bypass Site Isolation via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8527 | 2026-05-14 20:17:14 | HIGH (9) | Insufficient validation of untrusted input in Downloads in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8526 | 2026-05-14 20:17:13 | HIGH (9) | Out of bounds write in WebRTC in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8525 | 2026-05-14 20:17:13 | HIGH (8) | Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8524 | 2026-05-14 20:17:13 | HIGH (9) | Out of bounds write in WebAudio in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8523 | 2026-05-14 20:17:13 | HIGH (8) | Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-8522 | 2026-05-14 20:17:13 | HIGH (9) | Use after free in Downloads in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-8521 | 2026-05-14 20:17:13 | HIGH (8) | Use after free in Tab Groups in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical) | ADJACENT_NETWORK |
| CVE-2026-8520 | 2026-05-14 20:17:13 | HIGH (8) | Race in Payments in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-8519 | 2026-05-14 20:17:13 | HIGH (9) | Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-8518 | 2026-05-14 20:17:13 | HIGH (9) | Use after free in Blink in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-8517 | 2026-05-14 20:17:12 | HIGH (9) | Object lifecycle issue in WebShare in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-8516 | 2026-05-14 20:17:12 | MEDIUM (5) | Insufficient validation of untrusted input in DataTransfer in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-8515 | 2026-05-14 20:17:12 | HIGH (8) | Use after free in HID in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-8514 | 2026-05-14 20:17:12 | HIGH (8) | Use after free in Aura in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-8513 | 2026-05-14 20:17:12 | HIGH (8) | Use after free in Input in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-8512 | 2026-05-14 20:17:12 | HIGH (8) | Use after free in FileSystem in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-8511 | 2026-05-14 20:17:12 | CRITICAL (10) | Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-8510 | 2026-05-14 20:17:12 | HIGH (8) | Integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-8509 | 2026-05-14 20:17:11 | HIGH (9) | Heap buffer overflow in WebML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-82072 | 2026-08-28 00:18:23 | HIGH (9) | Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-8022 | 2026-05-06 19:16:53 | LOW (3) | Inappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted MHTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-8021 | 2026-05-06 19:16:53 | MEDIUM (4) | Script injection in UI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-8020 | 2026-05-06 19:16:53 | MEDIUM (5) | Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-8019 | 2026-05-06 19:16:53 | MEDIUM (5) | Insufficient policy enforcement in WebApp in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-8018 | 2026-05-06 19:16:53 | HIGH (8) | Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: Low) | NETWORK |
| CVE-2026-8017 | 2026-05-06 19:16:53 | LOW (3) | Side-channel information leakage in Media in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-8016 | 2026-05-06 19:16:53 | HIGH (9) | Use after free in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-8015 | 2026-05-06 19:16:52 | MEDIUM (5) | Inappropriate implementation in Media in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-8014 | 2026-05-06 19:16:52 | MEDIUM (4) | Inappropriate implementation in Preload in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-8013 | 2026-05-06 19:16:52 | MEDIUM (4) | Insufficient validation of untrusted input in FedCM in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-8012 | 2026-05-06 19:16:52 | MEDIUM (5) | Inappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-8011 | 2026-05-06 19:16:52 | MEDIUM (4) | Insufficient policy enforcement in Search in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-8010 | 2026-05-06 19:16:52 | MEDIUM (6) | Insufficient validation of untrusted input in SiteIsolation in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-8009 | 2026-05-06 19:16:52 | MEDIUM (5) | Inappropriate implementation in Cast in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-8008 | 2026-05-06 19:16:52 | MEDIUM (5) | Inappropriate implementation in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low) | NETWORK |
| CVE-2026-8007 | 2026-05-06 19:16:52 | HIGH (8) | Insufficient validation of untrusted input in Cast in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-8006 | 2026-05-06 19:16:52 | MEDIUM (5) | Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low) | NETWORK |
| CVE-2026-8005 | 2026-05-06 19:16:51 | MEDIUM (4) | Insufficient validation of untrusted input in Cast in Google Chrome prior to 148.0.7778.96 allowed an attacker on the local network segment to bypass same origin policy via malicious network traffic. (Chromium security severity: Low) | ADJACENT_NETWORK |
| CVE-2026-8004 | 2026-05-06 19:16:51 | MEDIUM (4) | Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Low) | NETWORK |
| CVE-2026-8003 | 2026-05-06 19:16:51 | MEDIUM (5) | Insufficient validation of untrusted input in TabGroups in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low) | NETWORK |
| CVE-2026-8002 | 2026-05-06 19:16:51 | HIGH (9) | Use after free in Audio in Google Chrome on Mac prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-8001 | 2026-05-06 19:16:51 | HIGH (8) | Use After Free in Printing in Google Chrome on Linux, Mac, ChromeOS prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-8000 | 2026-05-06 19:16:51 | HIGH (9) | Insufficient validation of untrusted input in ChromeDriver in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-7999 | 2026-05-06 19:16:51 | MEDIUM (4) | Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-7998 | 2026-05-06 19:16:51 | MEDIUM (5) | Insufficient validation of untrusted input in Dialog in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-7997 | 2026-05-06 19:16:51 | HIGH (8) | Insufficient validation of untrusted input in Updater in Google Chrome on Mac prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Low) | LOCAL |
| CVE-2026-7996 | 2026-05-06 19:16:50 | MEDIUM (4) | Insufficient validation of untrusted input in SSL in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-7995 | 2026-05-06 19:16:50 | HIGH (9) | Out of bounds read in AdFilter in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7994 | 2026-05-06 19:16:50 | HIGH (8) | Inappropriate implementation in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium) | LOCAL |
| CVE-2026-7993 | 2026-05-06 19:16:50 | MEDIUM (4) | Insufficient validation of untrusted input in Payments in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7992 | 2026-05-06 19:16:50 | HIGH (9) | Insufficient validation of untrusted input in UI in Google Chrome on Linux, ChromeOS prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7991 | 2026-05-06 19:16:50 | HIGH (9) | Use after free in UI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7990 | 2026-05-06 19:16:50 | HIGH (8) | Insufficient validation of untrusted input in Updater in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium) | LOCAL |
| CVE-2026-7989 | 2026-05-06 19:16:50 | MEDIUM (4) | Insufficient data validation in DataTransfer in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7988 | 2026-05-06 19:16:50 | HIGH (9) | Type Confusion in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7987 | 2026-05-06 19:16:50 | HIGH (9) | Use after free in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7986 | 2026-05-06 19:16:49 | MEDIUM (4) | Insufficient policy enforcement in Autofill in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7985 | 2026-05-06 19:16:49 | HIGH (8) | Use after free in GPU in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7984 | 2026-05-06 19:16:49 | HIGH (9) | Use after free in ReadingMode in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7983 | 2026-05-06 19:16:49 | MEDIUM (4) | Out of bounds read in Dawn in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7982 | 2026-05-06 19:16:49 | MEDIUM (7) | Uninitialized Use in WebCodecs in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7981 | 2026-05-06 19:16:49 | HIGH (8) | Out of bounds read in Codecs in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a malicious file. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7980 | 2026-05-06 19:16:49 | HIGH (9) | Use after free in WebAudio in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7979 | 2026-05-06 19:16:49 | MEDIUM (4) | Inappropriate implementation in Media in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7978 | 2026-05-06 19:16:49 | HIGH (8) | Inappropriate implementation in Companion in Google Chrome on Mac prior to 148.0.7778.96 allowed a remote attacker to perform OS-level privilege escalation via malicious network traffic. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7977 | 2026-05-06 19:16:49 | MEDIUM (6) | Inappropriate implementation in Canvas in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7976 | 2026-05-06 19:16:48 | HIGH (8) | Use after free in Views in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7975 | 2026-05-06 19:16:48 | HIGH (8) | Use after free in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7974 | 2026-05-06 19:16:48 | HIGH (9) | Use after free in Blink in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7973 | 2026-05-06 19:16:48 | HIGH (9) | Integer overflow in Dawn in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7972 | 2026-05-06 19:16:48 | MEDIUM (4) | Uninitialized Use in GPU in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7971 | 2026-05-06 19:16:48 | MEDIUM (6) | Inappropriate implementation in ORB in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7970 | 2026-05-06 19:16:48 | HIGH (8) | Use after free in TopChrome in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7969 | 2026-05-06 19:16:48 | MEDIUM (4) | Integer overflow in Network in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7968 | 2026-05-06 19:16:48 | LOW (3) | Insufficient validation of untrusted input in CORS in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7967 | 2026-05-06 19:16:47 | HIGH (8) | Insufficient validation of untrusted input in Navigation in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7966 | 2026-05-06 19:16:47 | LOW (3) | Insufficient validation of untrusted input in SiteIsolation in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7965 | 2026-05-06 19:16:47 | LOW (3) | Insufficient validation of untrusted input in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7964 | 2026-05-06 19:16:47 | MEDIUM (4) | Insufficient validation of untrusted input in FileSystem in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7963 | 2026-05-06 19:16:46 | HIGH (8) | Inappropriate implementation in ServiceWorker in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7962 | 2026-05-06 19:16:46 | MEDIUM (5) | Insufficient policy enforcement in DirectSockets in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform arbitrary read/write via a crafted Chrome Extension. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7961 | 2026-05-06 19:16:46 | MEDIUM (4) | Insufficient validation of untrusted input in Permissions in Google Chrome prior to 148.0.7778.96 allowed an attacker on the local network segment to leak cross-origin data via malicious network traffic. (Chromium security severity: Medium) | ADJACENT_NETWORK |
| CVE-2026-7960 | 2026-05-06 19:16:46 | MEDIUM (5) | Race in Speech in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7959 | 2026-05-06 19:16:46 | LOW (3) | Inappropriate implementation in Navigation in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7958 | 2026-05-06 19:16:46 | MEDIUM (5) | Inappropriate implementation in ServiceWorker in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts or HTML (UXSS) via a crafted Chrome Extension. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7957 | 2026-05-06 19:16:44 | HIGH (9) | Out of bounds write in Media in Google Chrome on Mac, iOS prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7956 | 2026-05-06 19:16:44 | HIGH (8) | Use after free in Navigation in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7955 | 2026-05-06 19:16:44 | MEDIUM (5) | Uninitialized Use in GPU in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7954 | 2026-05-06 19:16:44 | LOW (3) | Race in Shared Storage in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7953 | 2026-05-06 19:16:44 | MEDIUM (6) | Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via malicious network traffic. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7952 | 2026-05-06 19:16:44 | MEDIUM (4) | Insufficient policy enforcement in Extensions in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7951 | 2026-05-06 19:16:43 | HIGH (9) | Out of bounds write in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7950 | 2026-05-06 19:16:43 | MEDIUM (5) | Out of bounds read and write in GFX in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform arbitrary read/write via malicious network traffic. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7949 | 2026-05-06 19:16:43 | LOW (3) | Out of bounds read in Skia in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7948 | 2026-05-06 19:16:43 | HIGH (8) | Race in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7947 | 2026-05-06 19:16:43 | MEDIUM (4) | Insufficient validation of untrusted input in Network in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7946 | 2026-05-06 19:16:43 | MEDIUM (4) | Insufficient policy enforcement in WebUI in Google Chrome on Linux, Mac, Windows, ChromeOS prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7945 | 2026-05-06 19:16:43 | LOW (3) | Insufficient validation of untrusted input in COOP in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7944 | 2026-05-06 19:16:43 | LOW (3) | Insufficient validation of untrusted input in Persistent Cache in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7943 | 2026-05-06 19:16:43 | MEDIUM (4) | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7942 | 2026-05-06 19:16:43 | MEDIUM (4) | Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7941 | 2026-05-06 19:16:42 | MEDIUM (4) | Insufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 148.0.7778.96 allowed a local attacker to inject arbitrary scripts or HTML (UXSS) via a crafted Chrome Extension. (Chromium security severity: Medium) | LOCAL |
| CVE-2026-7940 | 2026-05-06 19:16:42 | HIGH (9) | Use after free in V8 in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7939 | 2026-05-06 19:16:42 | MEDIUM (5) | Inappropriate implementation in SanitizerAPI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7938 | 2026-05-06 19:16:42 | HIGH (9) | Use after free in CSS in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7937 | 2026-05-06 19:16:42 | LOW (3) | Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7936 | 2026-05-06 19:16:42 | MEDIUM (4) | Object lifecycle issue in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7935 | 2026-05-06 19:16:42 | MEDIUM (5) | Inappropriate implementation in Speech in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7934 | 2026-05-06 19:16:42 | MEDIUM (4) | Insufficient validation of untrusted input in Popup Blocker in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7933 | 2026-05-06 19:16:42 | MEDIUM (4) | Out of bounds read in WebCodecs in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform an out of bounds memory read via a crafted video file. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7932 | 2026-05-06 19:16:42 | MEDIUM (4) | Insufficient policy enforcement in Downloads in Google Chrome prior to 148.0.7778.96 allowed a local attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) | LOCAL |
| CVE-2026-7931 | 2026-05-06 19:16:41 | MEDIUM (5) | Insufficient validation of untrusted input in iOS in Google Chrome on iOS prior to 148.0.7778.96 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7930 | 2026-05-06 19:16:41 | HIGH (9) | Insufficient validation of untrusted input in Cookies in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79293 | 2026-08-25 21:18:24 | MEDIUM (7) | Information leak in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79292 | 2026-08-25 21:18:23 | HIGH (8) | Integer overflow in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79291 | 2026-08-25 21:18:23 | MEDIUM (7) | Information leak in CSS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7929 | 2026-05-06 19:16:41 | HIGH (8) | Use after free in MediaRecording in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79288 | 2026-08-25 21:18:23 | MEDIUM (7) | Improper input validation in Autofill in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79287 | 2026-08-25 21:18:23 | MEDIUM (5) | Observable discrepancy in Forms in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79286 | 2026-08-25 21:18:23 | HIGH (7) | Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a co-installed app. (Chromium security severity: Medium) | LOCAL |
| CVE-2026-79284 | 2026-08-25 21:18:23 | MEDIUM (4) | UI misrepresentation in Core in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79283 | 2026-08-25 21:18:22 | MEDIUM (5) | UI misrepresentation in Geometry in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7928 | 2026-05-06 19:16:41 | HIGH (9) | Use after free in WebRTC in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79274 | 2026-08-25 21:18:22 | MEDIUM (4) | Information leak in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79273 | 2026-08-25 21:18:22 | MEDIUM (4) | Incorrect reference resolution in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-7927 | 2026-05-06 19:16:41 | HIGH (9) | Type Confusion in Runtime in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-7926 | 2026-05-06 19:16:41 | HIGH (9) | Use after free in PresentationAPI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79256 | 2026-08-25 21:18:20 | HIGH (8) | Externally controlled reference in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79255 | 2026-08-25 21:18:20 | LOW (3) | Improper input validation in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79254 | 2026-08-25 21:18:20 | MEDIUM (4) | Incorrect reference resolution in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79253 | 2026-08-25 21:18:20 | MEDIUM (7) | Improper input validation in Network in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79252 | 2026-08-25 21:18:20 | MEDIUM (4) | Information leak in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79251 | 2026-08-25 21:18:20 | MEDIUM (4) | Improper input validation in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79250 | 2026-08-25 21:18:19 | MEDIUM (5) | UI misrepresentation in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7925 | 2026-05-06 19:16:41 | HIGH (8) | Use after free in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High) | LOCAL |
| CVE-2026-79249 | 2026-08-25 21:18:19 | MEDIUM (7) | Code injection in Bisection in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted file. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79248 | 2026-08-25 21:18:19 | MEDIUM (4) | Incorrect authorization in Input in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79247 | 2026-08-25 21:18:19 | HIGH (8) | Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High) | NETWORK |
| CVE-2026-79246 | 2026-08-25 21:18:19 | MEDIUM (7) | Information leak in DataTransfer in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79243 | 2026-08-25 21:18:19 | MEDIUM (7) | Improper input validation in ReadingList in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79242 | 2026-08-25 21:18:19 | MEDIUM (5) | Observable discrepancy in HTML in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7924 | 2026-05-06 19:16:41 | MEDIUM (7) | Uninitialized Use in Dawn in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79239 | 2026-08-25 21:18:18 | MEDIUM (7) | Out of bounds read in Tint in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79238 | 2026-08-25 21:18:18 | MEDIUM (4) | Incorrect authorization in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79237 | 2026-08-25 21:18:18 | MEDIUM (4) | Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79236 | 2026-08-25 21:18:18 | HIGH (9) | Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79234 | 2026-08-25 21:18:18 | MEDIUM (7) | Injection in CSS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79233 | 2026-08-25 21:18:18 | MEDIUM (4) | UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-7923 | 2026-05-06 19:16:41 | HIGH (8) | Out of bounds write in Skia in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79228 | 2026-08-25 21:18:17 | LOW (3) | Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation into a privileged page via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79225 | 2026-08-25 21:18:17 | MEDIUM (4) | Incorrect authorization in Browser in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via UI Interaction. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79223 | 2026-08-25 21:18:16 | HIGH (9) | Integer overflow in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory inside the sandbox via a crafted file. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79222 | 2026-08-25 21:18:16 | MEDIUM (4) | Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to bypass web origin policy via a co-installed app. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79220 | 2026-08-25 21:18:16 | MEDIUM (5) | Information leak in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7922 | 2026-05-06 19:16:40 | HIGH (8) | Use after free in ServiceWorker in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79219 | 2026-08-25 21:18:16 | HIGH (9) | Use after free in Bluetooth in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: High) | NETWORK |
| CVE-2026-79218 | 2026-08-25 21:18:16 | HIGH (8) | Incorrect authorization in Sandbox in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79216 | 2026-08-25 21:18:16 | HIGH (8) | Buffer overflow in Blink in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79214 | 2026-08-25 21:18:15 | MEDIUM (4) | Improper input validation in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79212 | 2026-08-25 21:18:15 | MEDIUM (4) | Missing authorization in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-7921 | 2026-05-06 19:16:40 | HIGH (9) | Use after free in Passwords in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79209 | 2026-08-25 21:18:15 | HIGH (9) | Type confusion in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79208 | 2026-08-25 21:18:15 | MEDIUM (6) | Missing authorization in HTTP2 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via crafted network traffic. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79207 | 2026-08-25 21:18:15 | MEDIUM (7) | Information leak in Passwords in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensitive information via a crafted file. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79205 | 2026-08-25 21:18:14 | MEDIUM (4) | Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79204 | 2026-08-25 21:18:14 | MEDIUM (5) | UI misrepresentation in Input in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79203 | 2026-08-25 21:18:14 | LOW (3) | Improper input validation in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79201 | 2026-08-25 21:18:14 | MEDIUM (4) | Improper access control in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7920 | 2026-05-06 19:16:40 | HIGH (8) | Use after free in Skia in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79197 | 2026-08-25 21:18:13 | HIGH (9) | Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79196 | 2026-08-25 21:18:13 | MEDIUM (5) | Race condition in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79195 | 2026-08-25 21:18:13 | HIGH (9) | Use after free in Script in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79194 | 2026-08-25 21:18:13 | HIGH (8) | Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High) | NETWORK |
| CVE-2026-79193 | 2026-08-25 21:18:13 | MEDIUM (4) | Information leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79192 | 2026-08-25 21:18:13 | MEDIUM (4) | Improper input validation in Variations in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via crafted network traffic. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79191 | 2026-08-25 21:18:13 | LOW (3) | Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79190 | 2026-08-25 21:18:13 | MEDIUM (4) | Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-7919 | 2026-05-06 19:16:40 | HIGH (8) | Use after free in Aura in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79189 | 2026-08-25 21:18:13 | CRITICAL (10) | Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79188 | 2026-08-25 21:18:12 | CRITICAL (10) | Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79187 | 2026-08-25 21:18:12 | HIGH (9) | Use after free in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79185 | 2026-08-25 21:18:12 | MEDIUM (4) | Information leak in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79184 | 2026-08-25 21:18:12 | MEDIUM (4) | Missing authorization in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79183 | 2026-08-25 21:18:12 | HIGH (9) | Use after free in Accessibility in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High) | NETWORK |
| CVE-2026-79182 | 2026-08-25 21:18:12 | HIGH (9) | Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79181 | 2026-08-25 21:18:12 | MEDIUM (5) | Observable discrepancy in Glic in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79180 | 2026-08-25 21:18:12 | MEDIUM (5) | UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7918 | 2026-05-06 19:16:40 | HIGH (8) | Use after free in GPU in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79179 | 2026-08-25 21:18:11 | MEDIUM (7) | Incorrect authorization in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79178 | 2026-08-25 21:18:11 | MEDIUM (4) | Incorrect authorization in Web Authentication (Passkeys & Security Keys) in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79177 | 2026-08-25 21:18:11 | MEDIUM (7) | Incorrect authorization in Media in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79176 | 2026-08-25 21:18:11 | MEDIUM (7) | UI misrepresentation in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79175 | 2026-08-25 21:18:11 | HIGH (8) | Type confusion in Accessibility in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79174 | 2026-08-25 21:18:11 | MEDIUM (4) | Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79173 | 2026-08-25 21:18:11 | MEDIUM (5) | UI misrepresentation in WebAppInstalls in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7917 | 2026-05-06 19:16:40 | HIGH (8) | Use after free in Fullscreen in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-7916 | 2026-05-06 19:16:40 | HIGH (8) | Insufficient data validation in InterestGroups in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79155 | 2026-08-25 21:18:11 | HIGH (8) | Race condition in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79154 | 2026-08-25 21:18:11 | MEDIUM (7) | Missing authorization in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive information via UI Interaction. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79152 | 2026-08-25 21:18:10 | CRITICAL (10) | Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to bypass web origin policy via a co-installed app. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79150 | 2026-08-25 21:18:10 | CRITICAL (10) | Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-7915 | 2026-05-06 19:16:40 | MEDIUM (4) | Insufficient data validation in DevTools in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79149 | 2026-08-25 21:18:10 | CRITICAL (10) | Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79142 | 2026-08-25 21:18:10 | HIGH (9) | Buffer overflow in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79140 | 2026-08-25 21:18:09 | CRITICAL (10) | Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7914 | 2026-05-06 19:16:40 | HIGH (8) | Type Confusion in Accessibility in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79139 | 2026-08-25 21:18:09 | HIGH (8) | Improper input validation in Media in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79138 | 2026-08-25 21:18:09 | CRITICAL (10) | Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79133 | 2026-08-25 21:18:09 | MEDIUM (7) | Incorrect authorization in Forms in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79132 | 2026-08-25 21:18:08 | HIGH (8) | Improper input validation in Input in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79131 | 2026-08-25 21:18:08 | CRITICAL (10) | Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79130 | 2026-08-25 21:18:08 | CRITICAL (10) | Buffer overflow in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-7913 | 2026-05-06 19:16:40 | HIGH (8) | Insufficient policy enforcement in DevTools in Google Chrome on Android prior to 148.0.7778.96 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: High) | LOCAL |
| CVE-2026-79129 | 2026-08-25 21:18:08 | CRITICAL (10) | Use after free in Sessions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79128 | 2026-08-25 21:18:08 | CRITICAL (10) | Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79127 | 2026-08-25 21:18:08 | HIGH (9) | Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79126 | 2026-08-25 21:18:08 | MEDIUM (6) | Incorrect provision of specified functionality in Proxy in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker to potentially obtain sensitive information via crafted network traffic. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79125 | 2026-08-25 21:18:08 | MEDIUM (7) | Information leak in XR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79124 | 2026-08-25 21:18:08 | MEDIUM (7) | Information leak in Intents in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79123 | 2026-08-25 21:18:07 | MEDIUM (7) | Improper input validation in NTP Footer in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79122 | 2026-08-25 21:18:07 | MEDIUM (6) | Information leak in SignIn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79121 | 2026-08-25 21:18:07 | HIGH (8) | Improper input validation in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-7912 | 2026-05-06 19:16:39 | MEDIUM (4) | Integer overflow in GPU in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79119 | 2026-08-25 21:18:07 | HIGH (9) | Use after free in PDF in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79117 | 2026-08-25 21:18:07 | MEDIUM (4) | Race condition in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a co-installed app. (Chromium security severity: High) | NETWORK |
| CVE-2026-79111 | 2026-08-25 21:18:06 | CRITICAL (10) | Improper input validation in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-7911 | 2026-05-06 19:16:39 | HIGH (8) | Use after free in Aura in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79109 | 2026-08-25 21:18:06 | HIGH (8) | Improper input validation in Printing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79105 | 2026-08-25 21:18:06 | MEDIUM (4) | Improper input validation in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79104 | 2026-08-25 21:18:06 | MEDIUM (5) | Missing authorization in Sensor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79103 | 2026-08-25 21:18:06 | LOW (3) | Incorrect reference resolution in Speech in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7910 | 2026-05-06 19:16:39 | CRITICAL (10) | Use after free in Views in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79098 | 2026-08-25 21:18:05 | MEDIUM (4) | UI misrepresentation in PermissionElement in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79097 | 2026-08-25 21:18:05 | HIGH (9) | Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79095 | 2026-08-25 21:18:05 | MEDIUM (4) | Information leak in Payments in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79093 | 2026-08-25 21:18:05 | MEDIUM (4) | Incorrect authorization in Paint in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79091 | 2026-08-25 21:18:05 | CRITICAL (10) | Use after free in Bluetooth in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79090 | 2026-08-25 21:18:05 | CRITICAL (10) | Improper privilege management in Actor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-7909 | 2026-05-06 19:16:39 | LOW (3) | Inappropriate implementation in ServiceWorker in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79086 | 2026-08-25 21:18:04 | MEDIUM (5) | Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: Medium) | LOCAL |
| CVE-2026-79085 | 2026-08-25 21:18:04 | MEDIUM (4) | Missing authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79084 | 2026-08-25 21:18:04 | MEDIUM (4) | Inadequate encryption strength in Notifications in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79083 | 2026-08-25 21:18:04 | HIGH (8) | Improper enforcement of behavioral workflow in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7908 | 2026-05-06 19:16:39 | CRITICAL (10) | Use after free in Fullscreen in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79078 | 2026-08-25 21:18:04 | CRITICAL (10) | Use after free in FedCM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79074 | 2026-08-25 21:18:03 | MEDIUM (5) | Information leak in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79073 | 2026-08-25 21:18:03 | HIGH (9) | Improper state validation in Parser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79071 | 2026-08-25 21:18:03 | HIGH (8) | Race condition in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7907 | 2026-05-06 19:16:39 | HIGH (9) | Use after free in DOM in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79069 | 2026-08-25 21:18:03 | HIGH (9) | Memory corruption in Tint in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79064 | 2026-08-25 21:18:02 | CRITICAL (10) | Use after free in Network in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7906 | 2026-05-06 19:16:39 | HIGH (9) | Use after free in SVG in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79057 | 2026-08-25 21:18:02 | HIGH (8) | Race condition in Start in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a co-installed app. (Chromium security severity: Medium) | LOCAL |
| CVE-2026-79056 | 2026-08-25 21:18:01 | CRITICAL (10) | Use after free in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79055 | 2026-08-25 21:18:01 | MEDIUM (5) | Information leak in Sharing in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker leveraging social engineering to obtain sensitive information via a co-installed app. (Chromium security severity: Low) | LOCAL |
| CVE-2026-79054 | 2026-08-25 21:18:01 | HIGH (8) | Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-79052 | 2026-08-25 21:18:01 | CRITICAL (10) | Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-7905 | 2026-05-06 19:16:39 | HIGH (8) | Insufficient validation of untrusted input in Media in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79048 | 2026-08-25 21:18:01 | HIGH (9) | Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79047 | 2026-08-25 21:18:00 | CRITICAL (10) | Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79046 | 2026-08-25 21:18:00 | MEDIUM (4) | Race condition in Permissions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79045 | 2026-08-25 21:18:00 | HIGH (9) | Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79044 | 2026-08-25 21:18:00 | MEDIUM (5) | Missing authorization in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79043 | 2026-08-25 21:18:00 | CRITICAL (10) | Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79041 | 2026-08-25 21:18:00 | MEDIUM (4) | Missing authorization in Browser in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79040 | 2026-08-25 21:18:00 | MEDIUM (4) | Uninitialized resource in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-7904 | 2026-05-06 19:16:39 | MEDIUM (4) | Out of bounds read in Fonts in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79039 | 2026-08-25 21:18:00 | HIGH (8) | Use after free in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High) | NETWORK |
| CVE-2026-79038 | 2026-08-25 21:17:59 | MEDIUM (7) | Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79034 | 2026-08-25 21:17:59 | LOW (3) | Information leak in CORS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79033 | 2026-08-25 21:17:59 | HIGH (9) | Insufficient control flow management in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79031 | 2026-08-25 21:17:59 | LOW (3) | Improper resource exposure in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79030 | 2026-08-25 21:17:59 | MEDIUM (5) | Observable discrepancy in Autofill in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7903 | 2026-05-06 19:16:39 | HIGH (9) | Integer overflow in ANGLE in Google Chrome on Mac,Windows prior to 148.0.7778.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79027 | 2026-08-25 21:17:59 | HIGH (8) | Use after free in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via crafted network traffic. (Chromium security severity: High) | NETWORK |
| CVE-2026-79026 | 2026-08-25 21:17:59 | CRITICAL (10) | Use after free in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: High) | NETWORK |
| CVE-2026-79024 | 2026-08-25 21:17:58 | MEDIUM (7) | Information leak in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79023 | 2026-08-25 21:17:58 | MEDIUM (7) | Incorrect authorization in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79022 | 2026-08-25 21:17:58 | MEDIUM (4) | UI misrepresentation in Transactions Platform in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79021 | 2026-08-25 21:17:58 | MEDIUM (7) | Missing authorization in InterestGroups in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted PDF file. (Chromium security severity: Low) | NETWORK |
| CVE-2026-7902 | 2026-05-06 19:16:39 | HIGH (9) | Out of bounds memory access in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79019 | 2026-08-25 21:17:58 | CRITICAL (10) | Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79018 | 2026-08-25 21:17:58 | MEDIUM (7) | Information leak in FoldableAPIs in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79017 | 2026-08-25 21:17:58 | MEDIUM (7) | Race condition in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79015 | 2026-08-25 21:17:57 | MEDIUM (4) | Improper input validation in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79014 | 2026-08-25 21:17:57 | MEDIUM (4) | Race condition in Autofill in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79013 | 2026-08-25 21:17:57 | MEDIUM (6) | Improper input validation in Sync in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79012 | 2026-08-25 21:17:57 | CRITICAL (10) | Use after free in Safebrowsing in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2026-79010 | 2026-08-25 21:17:57 | MEDIUM (4) | Operation on a resource after expiration or release in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-7901 | 2026-05-06 19:16:38 | HIGH (9) | Use after free in ANGLE in Google Chrome on Mac prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2026-79009 | 2026-08-25 21:17:57 | MEDIUM (4) | UI misrepresentation in UI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79008 | 2026-08-25 21:17:57 | HIGH (8) | Improper input validation in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79006 | 2026-08-25 21:17:56 | MEDIUM (4) | Protection mechanism failure in HttpsUpgrades in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via crafted network traffic. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79005 | 2026-08-25 21:17:56 | MEDIUM (7) | Incorrect authorization in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
| CVE-2026-79002 | 2026-08-25 21:17:56 | LOW (3) | Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | NETWORK |
| CVE-2026-79001 | 2026-08-25 21:17:56 | MEDIUM (5) | Information leak in Bluetooth in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) | NETWORK |
Showing the 500 most recent of 6075 tracked CVEs.
Why keeping Google Chrome patched matters
Unpatched third-party applications are one of the most common ways attackers get in: 57% of breached MSP clients and 32% of ransomware cases trace back to a missing patch. Every Google Chrome release that fixes a security bug is public, so attackers see it too, and an out-of-date install becomes a documented way in. Tracking the installed version on every machine and closing the gap quickly is what turns a disclosed CVE into a non-event.
How Lavawall® patches Google Chrome
Lavawall® watches Google Chrome releases and CVEs continuously, ranks each update by risk, and deploys it across your whole fleet, Windows, macOS, and Linux, from a single agent, independently of your RMM. You get one place to see which machines are behind on Google Chrome, one policy to bring them current, and timestamped evidence for audits.
Frequently asked questions
Lavawall tracks Google Chrome at version 148.0.7778.217 (last checked 2024-08-27). New releases are monitored continuously and can be deployed automatically across your fleet.
Lavawall tracks 6075 CVEs for Google Chrome and remediates them automatically as part of patching.
Deploy the Lavawall® agent and Google Chrome updates are applied automatically across Windows, macOS, and Linux, risk-ranked and reported, independently of your RMM.
Lavawall® monitors releases and CVEs for Google Chrome through public information and proprietary statistical analysis, and can patch it automatically across your fleet.