Total
508 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-9123 | 2 Google, Linux | 4 Android, Chrome, Chrome Os and 1 more | 2026-07-23 | N/A | 7.5 HIGH |
| Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148.0.7778.179 allowed a local attacker to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: Medium) | |||||
| CVE-2026-9117 | 2 Google, Linux | 3 Chrome, Chrome Os, Linux Kernel | 2026-07-23 | N/A | 7.5 HIGH |
| Type Confusion in GFX in Google Chrome on Linux, ChromeOS prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: High) | |||||
| CVE-2026-11676 | 2 Google, Linux | 3 Chrome, Chrome Os, Linux Kernel | 2026-07-23 | N/A | 8.3 HIGH |
| Insufficient validation of untrusted input in Dawn in Google Chrome on Linux and ChromeOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-11668 | 2 Google, Linux | 3 Chrome, Chrome Os, Linux Kernel | 2026-07-23 | N/A | 4.3 MEDIUM |
| Uninitialized Use in Codecs in Google Chrome on Linux, ChromeOS prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted video file. (Chromium security severity: High) | |||||
| CVE-2026-11669 | 1 Google | 2 Chrome, Chrome Os | 2026-07-23 | N/A | 5.3 MEDIUM |
| Out of bounds read in Media in Google Chrome on ChromeOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-11028 | 2 Google, Linux | 3 Chrome, Chrome Os, Linux Kernel | 2026-07-23 | N/A | 8.8 HIGH |
| Use after free in Media in Google Chrome on Linux and ChromeOS prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-9985 | 1 Google | 2 Chrome, Chrome Os | 2026-07-21 | N/A | 5.3 MEDIUM |
| Insufficient validation of untrusted input in Media in Google Chrome on ChromeOS prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-0248 | 2 Google, Paloaltonetworks | 3 Android, Chrome Os, Prisma Access Agent | 2026-07-14 | N/A | 5.9 MEDIUM |
| An improper certificate validation vulnerability in the Prisma Access AgentĀ® for Android and Chrome OS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. By presenting a certificate for any domain issued by a trusted Certificate Authority, the attacker can capture sensitive device information. The Prisma Access Agent on macOS, Windows, Linux and iOS are not affected. | |||||
| CVE-2026-14103 | 1 Google | 2 Chrome, Chrome Os | 2026-07-02 | N/A | 6.5 MEDIUM |
| Use after free in SSL in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-14062 | 1 Google | 2 Chrome, Chrome Os | 2026-07-02 | N/A | 5.9 MEDIUM |
| Inappropriate implementation in Views in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. (Chromium security severity: Low) | |||||
| CVE-2026-13986 | 1 Google | 2 Chrome, Chrome Os | 2026-07-02 | N/A | 4.2 MEDIUM |
| Inappropriate implementation in Media UI in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-13942 | 1 Google | 2 Chrome, Chrome Os | 2026-07-02 | N/A | 3.3 LOW |
| Inappropriate implementation in Video Capture in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a local attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-14421 | 1 Google | 2 Chrome, Chrome Os | 2026-07-02 | N/A | 6.5 MEDIUM |
| Uninitialized Use in Dawn in Google Chrome on ChromeOS prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-14090 | 1 Google | 2 Chrome, Chrome Os | 2026-07-02 | N/A | 8.1 HIGH |
| Insufficient validation of untrusted input in CameraCapture in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-13779 | 1 Google | 2 Chrome, Chrome Os | 2026-07-02 | N/A | 8.1 HIGH |
| Use after free in Chromoting in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical) | |||||
| CVE-2026-12026 | 1 Google | 2 Chrome, Chrome Os | 2026-07-01 | N/A | 6.5 MEDIUM |
| Out of bounds read in Video in Google Chrome on ChromeOS prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-8576 | 2 Google, Linux | 3 Chrome, Chrome Os, Linux Kernel | 2026-06-17 | N/A | 4.3 MEDIUM |
| Inappropriate implementation in CORS in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-8535 | 2 Google, Linux | 3 Chrome, Chrome Os, Linux Kernel | 2026-06-17 | N/A | 5.3 MEDIUM |
| Out of bounds read in Media in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted JPEG file. (Chromium security severity: High) | |||||
| CVE-2026-8534 | 2 Google, Linux | 3 Chrome, Chrome Os, Linux Kernel | 2026-06-17 | N/A | 8.3 HIGH |
| Integer overflow in GPU in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-8001 | 3 Apple, Google, Linux | 4 Macos, Chrome, Chrome Os and 1 more | 2026-06-17 | N/A | 8.3 HIGH |
| Use After Free in Printing in Google Chrome on Linux, Mac, ChromeOS prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) | |||||
