Google Software and search
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Google product.
RSS Feeds for Google security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Google products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Google Sorted by Most Security Vulnerabilities since 2018
Recent Google Security Advisories
| Advisory | Title | Published |
|---|---|---|
| 2026-09-16 | Chrome Releases: Chrome for Android Update (version 153) | September 16, 2026 |
| 2026-09-15 | Chrome Releases: Chrome Stable for iOS Update (version 154) | September 15, 2026 |
| 2026-09-15 | Chrome Releases: Stable Channel Update for Desktop (version 153.0.8010.47) | September 15, 2026 |
| 2026-09-08 | Chrome Releases: Stable Channel Update for ChromeOS / ChromeOS Flex | September 8, 2026 |
| 2026-09-08 | Chrome Releases: Stable Channel Update for Desktop (version 153) | September 8, 2026 |
| 2026-09-08 | Chrome Releases: Chrome for Android Update (version 153) | September 8, 2026 |
| 2026-09-04 | Chrome Releases: Chrome for Android Update (version 152) | September 4, 2026 |
| 2026-09-03 | Chrome Releases: Stable Channel Update for Desktop (version 152.0.7977.82) | September 3, 2026 |
| 2026-09-02 | Chrome Releases: September 2026 | September 2, 2026 |
| 2026-09-02 | Chrome Releases: Chrome Stable for iOS Update (version 153) | September 2, 2026 |
Known Exploited Google Vulnerabilities
The following Google vulnerabilities have recently been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Google Chromium V8 Out of Bounds Write Vulnerability |
Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2026-87491 |
September 9, 2026 |
| Google Chromium V8 Type Confusion Vulnerability |
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2026-85046 |
September 4, 2026 |
| Google Chromium V8 Out-of-Bounds Read and Write Vulnerability |
Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2026-11645 Exploit Probability: 2.2% |
June 9, 2026 |
| Google Dawn Use-After-Free Vulnerability |
Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based products including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2026-5281 Exploit Probability: 5.5% |
April 1, 2026 |
| Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerabi |
Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2026-3910 Exploit Probability: 2.0% |
March 13, 2026 |
| Google Skia Out-of-Bounds Write Vulnerability |
Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products. CVE-2026-3909 Exploit Probability: 1.6% |
March 13, 2026 |
| Google Chromium CSS Use-After-Free Vulnerability |
Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2026-2441 Exploit Probability: 22.0% |
February 17, 2026 |
| Google Chromium Out of Bounds Memory Access Vulnerability |
Google Chromium contains an out of bounds memory access vulnerability in ANGLE that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2025-14174 Exploit Probability: 22.7% |
December 12, 2025 |
| Google Chromium V8 Type Confusion Vulnerability |
Google Chromium V8 contains a type confusion vulnerability that allows for heap corruption. CVE-2025-13223 Exploit Probability: 4.9% |
November 19, 2025 |
| Google Chromium V8 Type Confusion Vulnerability |
Google Chromium contains a type confusion vulnerability in the V8 JavaScript and WebAssembly engine. CVE-2025-10585 Exploit Probability: 5.4% |
September 23, 2025 |
| Google Chromium ANGLE and GPU Improper Input Validation Vulnerability |
Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. This vulnerability could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2025-6558 Exploit Probability: 9.0% |
July 22, 2025 |
| Google Chromium V8 Type Confusion Vulnerability |
Google Chromium V8 contains a type confusion vulnerability that could allow a remote attacker to perform arbitrary read/write via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2025-6554 Exploit Probability: 8.6% |
July 2, 2025 |
| Google Chromium V8 Out-of-Bounds Read and Write Vulnerability |
Google Chromium V8 contains an out-of-bounds read and write vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2025-5419 Exploit Probability: 6.5% |
June 5, 2025 |
| Google Chromium Loader Insufficient Policy Enforcement Vulnerability |
Google Chromium contains an insufficient policy enforcement vulnerability that allows a remote attacker to leak cross-origin data via a crafted HTML page. CVE-2025-4664 Exploit Probability: 5.4% |
May 15, 2025 |
| Google Chromium Mojo Sandbox Escape Vulnerability |
Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error, which results from an incorrect handle being provided in unspecified circumstances. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2025-2783 Exploit Probability: 8.4% |
March 27, 2025 |
| Google Chromium V8 Inappropriate Implementation Vulnerability |
Google Chromium V8 contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2024-7965 Exploit Probability: 18.4% |
August 28, 2024 |
| Google Chromium V8 Type Confusion Vulnerability |
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2024-7971 Exploit Probability: 20.5% |
August 26, 2024 |
| Google Chromium V8 Type Confusion Vulnerability |
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2024-5274 Exploit Probability: 10.0% |
May 28, 2024 |
| Google Chromium V8 Type Confusion Vulnerability |
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. CVE-2024-4947 Exploit Probability: 15.1% |
May 20, 2024 |
| Google Chromium V8 Out-of-Bounds Memory Write Vulnerability |
Google Chromium V8 Engine contains an unspecified out-of-bounds memory write vulnerability via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2024-4761 Exploit Probability: 11.0% |
May 16, 2024 |
7 known exploited Google vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.
Top 10 Riskiest Google Vulnerabilities
Based on the current exploit probability, these Google vulnerabilities are on CISA's Known Exploited vulnerabilities list (KEV) and are ranked by the current EPSS exploit probability.
| Rank | CVE | EPSS | Vulnerability |
|---|---|---|---|
| 1 | CVE-2023-4863 | 100.0% | Google Chromium Heap-Based Buffer Overflow Vulnerability |
| 2 | CVE-2018-17463 | 84.6% | Google Chromium V8 Remote Code Execution Vulnerability |
| 3 | CVE-2021-21224 | 84.2% | Chromium V8 JavaScript Engine Remote Code Execution Vulnerability |
| 4 | CVE-2020-6418 | 78.8% | Chromium V8 Type Confusion Vulnerability |
| 5 | CVE-2019-13720 | 73.0% | Google Chrome Use-After-Free Vulnerability |
| 6 | CVE-2021-21220 | 70.4% | Chromium V8 Input Validation Vulnerability |
| 7 | CVE-2021-30551 | 64.7% | Chromium V8 Type Confusion Vulnerability |
| 8 | CVE-2021-30632 | 63.2% | Google Chrome Out-of-bounds write |
| 9 | CVE-2019-5786 | 61.5% | Google Chrome Use-After-Free Vulnerability |
| 10 | CVE-2018-6065 | 60.3% | Google Chromium V8 Integer Overflow Vulnerability |
By the Year
In 2026 there have been 3403 vulnerabilities in Google with an average score of 7.0 out of ten. Last year, in 2025 Google had 720 security vulnerabilities published. That is, 2683 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.13
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 3403 | 7.04 |
| 2025 | 720 | 7.17 |
| 2024 | 1125 | 7.29 |
| 2023 | 1564 | 6.66 |
| 2022 | 1592 | 6.85 |
| 2021 | 1166 | 7.11 |
| 2020 | 1033 | 6.87 |
| 2019 | 858 | 7.33 |
| 2018 | 570 | 7.43 |
It may take a day or so for new Google vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Google Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-91738 | Sep 15, 2026 |
Google Chrome ANGLE Improper Input Validation (pre-153.0.8010.47)Improper input validation in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-91730 | Sep 15, 2026 |
Chrome GetUserMedia Cleanup Flaw (v<153.0.8010.47) Enables Cross-Origin LeakIncomplete cleanup in GetUserMedia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-91722 | Sep 15, 2026 |
Use-after-free in Chrome <153.0.8010.47 Input componentUse after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-91719 | Sep 15, 2026 |
Chrome XML Injection <=153.0.8010.46 Bypass Origin PolicyCode injection in XML in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-91713 | Sep 15, 2026 |
Missing Auth in Chrome <153.0.8010.47: UI Spoof via RendererMissing authorization in Browser in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-91742 | Sep 15, 2026 |
Confused Deputy in Chrome PriceTracking iOS <153.0.8010.47Confused deputy in PriceTracking in Google Chrome on on iOS prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to bypass system access restrictions into a privileged page via crafted network traffic. (Chromium security severity: Medium) |
|
| CVE-2026-91739 | Sep 15, 2026 |
Chrome <153.0.8010.47: Auth Gap in Transactions Platform Allows Renderer SpoofMissing authorization in Transactions Platform in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-91725 | Sep 15, 2026 |
Chrome CSS Disclosure Before 153.0.8010.47Observable discrepancy in CSS in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-91714 | Sep 15, 2026 |
Format Data Leak via Font Mismatch in Chrome (<153.0.8010.47)Observable discrepancy in Fonts in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-91745 | Sep 15, 2026 |
Use-After-Free in V8 (Chrome <153.0.8010.47) Allows RCEUse after free in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-91732 | Sep 15, 2026 |
Missing Auth in Chrome AppManifest (<=153.0.8010.47)Missing authorization in AppManifest in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-91723 | Sep 15, 2026 |
Chrome <153.0.8010.47 WebAppInstalls Race Condition UI SpoofingRace condition in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-91715 | Sep 15, 2026 |
Google Chrome ServiceWorker Type Confusion < 153.0.8010.47 RCEType confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-91711 | Sep 15, 2026 |
Out-of-bounds write in Chrome ServiceWorker (pre-153.0.8010.47)Out of bounds write in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-91746 | Sep 15, 2026 |
Google Chrome <153.0.8010.47 Int Overflow in Compositing Allows X-OR Data LeakInteger overflow in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-91737 | Sep 15, 2026 |
Use-after-free in Chrome PDF before 153.0.8010.47 allows sandbox escapeUse after free in PDF in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-91729 | Sep 15, 2026 |
Use-after-free in Chrome DigitalCredentials (pre-153.0.8010.47)Use after free in DigitalCredentials in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-91716 | Sep 15, 2026 |
UAF in Auth prior to 153.0.8010.47 in Google ChromeUse after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-91740 | Sep 15, 2026 |
Uninitialized Skia res. in Chrome <153.0.8010.47 allows remote XOR leakUninitialized resource in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-91736 | Sep 15, 2026 |
Chrome UAF in DOM before 153.0.8010.47 (remote code exec)Use after free in DOM in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-91718 | Sep 15, 2026 |
UAoF in Chrome Core before 153.0.8010.47 enables remote code execUse after free in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-91710 | Sep 15, 2026 |
UA-FREE Chrome WebAppInstalls <153.0.8010.47: Remote Code ExecUse after free in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-91741 | Sep 15, 2026 |
Type Confusion in CacheStorage in Chrome <153.0.8010.47 Enables Remote Code ExecutionType confusion in CacheStorage in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-91735 | Sep 15, 2026 |
Google Chrome 153.0.8010.47 WebUI Wrong Auth Arbitrary Code ExecIncorrect authorization in WebUI in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-91717 | Sep 15, 2026 |
Missing Auth in Google Chrome Android <153.0.8010.47 via Co-installed AppMissing authorization in Android in Google Chrome on on Android prior to 153.0.8010.47 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: High) |
|
| CVE-2026-91709 | Sep 15, 2026 |
ServiceWorker Type Confusion in Chrome <153.0.8010.47 (Arbitrary Code Exec)Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-91708 | Sep 15, 2026 |
Chrome <153.0.8010.47 Race Cond. in Network Allows CO Data LeakRace condition in Network in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-91747 | Sep 15, 2026 |
Use-After-Free in Skia of Chrome <153.0.8010.47 via crafted HTMLUse after free in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-91733 | Sep 15, 2026 |
Chrome Skia Remote Memory Leak via Improper State Validation (Fixed 153.0.8010.47)Improper state validation in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-91731 | Sep 15, 2026 |
Chrome 153.0.8010.47 Type Confusion in Compositing (Remote Code Exec)Type confusion in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-91720 | Sep 15, 2026 |
Uninitialized Resource in ANGLE -> Remote Memory Disclosure in Chrome<153Uninitialized resource in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-91748 | Sep 15, 2026 |
Google Chrome MAC <153.0.8010.47 Race Condition in Extensions Escalates RCERace condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High) |
|
| CVE-2026-91744 | Sep 15, 2026 |
Race Condition in Chrome (<153.0.8010.47) Enables Remote Info LeakRace condition in PlatformIntegration in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-91712 | Sep 15, 2026 |
CVE-2026-91712: Chrome Mac Race Condition RCE before 153.0.8010.47Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-91743 | Sep 15, 2026 |
Chrome <153.0.8010.47 Race Condition: Remote Code Execution via Crafted HTMLRace condition in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-91734 | Sep 15, 2026 |
Chrome Windows <153.0.8010.47 Local Auth Bypass Exec Outside SandboxIncorrect authorization in Core in Google Chrome on on Windows prior to 153.0.8010.47 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) |
|
| CVE-2026-91727 | Sep 15, 2026 |
Chrome Mac <153.0.8010.47 Extension Ref Resolved Exec Outside SandboxIncorrect reference resolution in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a local attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) |
|
| CVE-2026-91749 | Sep 15, 2026 |
Use-After-Free in Chrome Workers before 153.0.8010.47Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) |
|
| CVE-2026-91728 | Sep 15, 2026 |
Integer overflow in V8 (Chrome <153.0.8010.47) allows remote code execInteger overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-91724 | Sep 15, 2026 |
Google Chrome <153.0.8010.47: Input USEAFTERFREE in rendererUse after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-91726 | Sep 15, 2026 |
Chrome Android WebGL OOB read <153.0.8010.47Out of bounds read in WebGL in Google Chrome on on Android prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) |
|
| CVE-2026-91721 | Sep 15, 2026 |
UAF in Chrome Internals before 153.0.8010.47Use after free in Internals in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) |
|
| CVE-2026-58773 | Sep 15, 2026 |
In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds checkIn link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. |
|
| CVE-2026-58767 | Sep 15, 2026 |
In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the codeIn multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. |
|
| CVE-2026-58766 | Sep 15, 2026 |
In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the codeIn multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. |
|
| CVE-2026-58765 | Sep 15, 2026 |
In GPU, there is a possible permission bypass due to a logic error in the codeIn GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. |
|
| CVE-2026-58755 | Sep 15, 2026 |
In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the codeIn smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. |
|
| CVE-2026-58751 | Sep 15, 2026 |
In multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the codeIn multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. |
|
| CVE-2026-58747 | Sep 15, 2026 |
In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the codeIn smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. |
|
| CVE-2026-58744 | Sep 15, 2026 |
In multiple locations, there is a possible escalation of privilege due to improper input validationIn multiple locations, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. |
|