Google Google Software and search

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Google product.

RSS Feeds for Google security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Google products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Google Sorted by Most Security Vulnerabilities since 2018

Google Chrome6627 vulnerabilities
Web browser

Google Android6556 vulnerabilities
Mobile operating system

Google Tensorflow432 vulnerabilities
Open source machine learning / AI library

Google ChromeOS51 vulnerabilities

Google Asylo16 vulnerabilities

Google Protobuf9 vulnerabilities

Google Gvisor8 vulnerabilities

Google Gerrit7 vulnerabilities

Google Fuchsia5 vulnerabilities

Google Protobuf Java5 vulnerabilities

Google Protobuf Javalite4 vulnerabilities

Google Web Toolkit3 vulnerabilities

Google Protobuf Kotlin3 vulnerabilities

Google Web Stories3 vulnerabilities

Google Web Designer3 vulnerabilities

Google Chromecast Firmware2 vulnerabilities

Google Firebase Php Jwt2 vulnerabilities

Google Nearby2 vulnerabilities

Google Protobuf Kotlin Lite2 vulnerabilities

Google Protobuf Python2 vulnerabilities

Google Updater2 vulnerabilities

Google Androidx Car App1 vulnerability

Google Bazel For Clion1 vulnerability

Google Bazel For Intellij1 vulnerability

Google Car1 vulnerability

Google Cloud Looker1 vulnerability

Google Drive1 vulnerability

Google Secops Soar1 vulnerability

Google Site Kit1 vulnerability

Google Looker1 vulnerability

Google Nftables1 vulnerability

Google Pixel1 vulnerability

Google Quick Share1 vulnerability

Google Reverb1 vulnerability

Google Safearchive1 vulnerability

Google Tensorflow Serving1 vulnerability

Google Tink C1 vulnerability

Google Vertex Ai1 vulnerability

Recent Google Security Advisories

Advisory Title Published
2026-09-29 Chrome Releases: Chrome for Android Update (version 154) September 29, 2026
2026-09-29 Chrome Releases: Stable Channel Update for Desktop (version 154.0.8037.92) September 29, 2026
2026-09-25 Chrome Releases: Stable Channel Update for ChromeOS / ChromeOS Flex September 25, 2026
2026-09-22 Chrome Releases: Chrome Stable for iOS Update (version 154) September 22, 2026
2026-09-22 Chrome Releases: Stable Channel Update for Desktop (version 154) September 22, 2026
2026-09-22 Chrome Releases: Chrome for Android Update (version 154) September 22, 2026
2026-09-18 Chrome Releases: Stable Channel Update for Desktop (version 153.0.8010.52) September 18, 2026
2026-09-18 Chrome Releases: Chrome for Android Update (version 153) September 18, 2026
2026-09-17 Chrome Releases: Stable Channel Update for ChromeOS / ChromeOS Flex September 17, 2026
2026-09-16 Chrome Releases: Chrome for Android Update (version 153) September 16, 2026

Known Exploited Google Vulnerabilities

The following Google vulnerabilities have recently been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
Google Pixel Improper Authorization Vulnerability Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges.
CVE-2026-58704
September 16, 2026
Google Chromium V8 Out of Bounds Write Vulnerability Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2026-87491
September 9, 2026
Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2026-85046
September 4, 2026
Google Chromium V8 Out-of-Bounds Read and Write Vulnerability Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2026-11645 Exploit Probability: 2.2%
June 9, 2026
Google Dawn Use-After-Free Vulnerability Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based products including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2026-5281 Exploit Probability: 5.5%
April 1, 2026
Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerabi Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2026-3910 Exploit Probability: 2.0%
March 13, 2026
Google Skia Out-of-Bounds Write Vulnerability Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products.
CVE-2026-3909 Exploit Probability: 1.6%
March 13, 2026
Google Chromium CSS Use-After-Free Vulnerability Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2026-2441 Exploit Probability: 22.0%
February 17, 2026
Google Chromium Out of Bounds Memory Access Vulnerability Google Chromium contains an out of bounds memory access vulnerability in ANGLE that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2025-14174 Exploit Probability: 22.3%
December 12, 2025
Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 contains a type confusion vulnerability that allows for heap corruption.
CVE-2025-13223 Exploit Probability: 5.0%
November 19, 2025
Google Chromium V8 Type Confusion Vulnerability Google Chromium contains a type confusion vulnerability in the V8 JavaScript and WebAssembly engine.
CVE-2025-10585 Exploit Probability: 5.4%
September 23, 2025
Google Chromium ANGLE and GPU Improper Input Validation Vulnerability Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. This vulnerability could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2025-6558 Exploit Probability: 9.6%
July 22, 2025
Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 contains a type confusion vulnerability that could allow a remote attacker to perform arbitrary read/write via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2025-6554 Exploit Probability: 12.6%
July 2, 2025
Google Chromium V8 Out-of-Bounds Read and Write Vulnerability Google Chromium V8 contains an out-of-bounds read and write vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2025-5419 Exploit Probability: 7.8%
June 5, 2025
Google Chromium Loader Insufficient Policy Enforcement Vulnerability Google Chromium contains an insufficient policy enforcement vulnerability that allows a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2025-4664 Exploit Probability: 5.6%
May 15, 2025
Google Chromium Mojo Sandbox Escape Vulnerability Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error, which results from an incorrect handle being provided in unspecified circumstances. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2025-2783 Exploit Probability: 9.2%
March 27, 2025
Google Chromium V8 Inappropriate Implementation Vulnerability Google Chromium V8 contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2024-7965 Exploit Probability: 18.5%
August 28, 2024
Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2024-7971 Exploit Probability: 21.1%
August 26, 2024
Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2024-5274 Exploit Probability: 7.5%
May 28, 2024
Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page.
CVE-2024-4947 Exploit Probability: 15.2%
May 20, 2024

8 known exploited Google vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.

Top 10 Riskiest Google Vulnerabilities

Based on the current exploit probability, these Google vulnerabilities are on CISA's Known Exploited vulnerabilities list (KEV) and are ranked by the current EPSS exploit probability.

Rank CVE EPSS Vulnerability
1 CVE-2023-4863 100.0% Google Chromium Heap-Based Buffer Overflow Vulnerability
2 CVE-2018-17463 84.6% Google Chromium V8 Remote Code Execution Vulnerability
3 CVE-2021-21224 84.2% Chromium V8 JavaScript Engine Remote Code Execution Vulnerability
4 CVE-2020-6418 78.8% Chromium V8 Type Confusion Vulnerability
5 CVE-2021-21220 70.4% Chromium V8 Input Validation Vulnerability
6 CVE-2021-30551 64.7% Chromium V8 Type Confusion Vulnerability
7 CVE-2021-30632 63.2% Google Chrome Out-of-bounds write
8 CVE-2019-5786 61.1% Google Chrome Use-After-Free Vulnerability
9 CVE-2018-6065 60.3% Google Chromium V8 Integer Overflow Vulnerability
10 CVE-2019-5825 55.9% Google Chromium V8 Out-of-Bounds Write Vulnerability

By the Year

In 2026 there have been 3540 vulnerabilities in Google with an average score of 7.0 out of ten. Last year, in 2025 Google had 720 security vulnerabilities published. That is, 2820 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.13




Year Vulnerabilities Average Score
2026 3540 7.04
2025 720 7.17
2024 1125 7.29
2023 1564 6.66
2022 1592 6.85
2021 1166 7.11
2020 1033 6.87
2019 858 7.33
2018 570 7.43

It may take a day or so for new Google vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Google Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-95305 Sep 29, 2026
Google Chrome Chromoting UI Spoofing before 154.0.8037.57 UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic. (Chromium security severity: Low)
Chrome
CVE-2026-95316 Sep 29, 2026
Local Mem Read via Unchecked Return Value in Chrome <154.0.8037.57 Unchecked return value in Performance in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially read memory via a local program. (Chromium security severity: Low)
Chrome
CVE-2026-95340 Sep 29, 2026
Chrome <154.0.8037.57: PIP Auth Bypass Web Origin Policy (CVE-2026-95340) Incorrect authorization in PictureInPicture in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
Chrome
CVE-2026-95364 Sep 29, 2026
Google Chrome <154.0.8037.57 Passwords Input Validation Spoof Improper input validation in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Chrome
CVE-2026-95328 Sep 29, 2026
Google Chrome Android <154.0.8037.57: Confused Deputy via Coinstalled App Confused deputy in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker leveraging social engineering to obtain sensitive information via a co-installed app. (Chromium security severity: Low)
Chrome
CVE-2026-95380 Sep 29, 2026
Type Confusion in V8 of Chrome v<154.0.8037.57: RCE via HTML Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Chrome
CVE-2026-95296 Sep 29, 2026
Chrome Core Mac auth flaw before 154.0.8037.57 cross-origin data leak Missing authorization in Core in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Chrome
CVE-2026-95288 Sep 29, 2026
UI Spoof via Crafted HTML in Chrome iOS <154.0.8037.57 UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Chrome
CVE-2026-95342 Sep 29, 2026
Missing Auth in Chrome V8 <154.0.8037.57 Allowing Remote Web Origin Bypass Missing authorization in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
Chrome
CVE-2026-95309 Sep 29, 2026
Google Chrome Mobile iOS <154.0.8037.57 UI Spoofing via Crafted HTML UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Chrome
CVE-2026-95319 Sep 29, 2026
Chrome <154.0.8037.57: UAF in Printing, remote code exec risk Use after free in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Chrome
CVE-2026-95326 Sep 29, 2026
Google Chrome 154.0.8037.57 Bluetooth cleanup flaw bypasses restrictions Incomplete cleanup in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Chrome
CVE-2026-95361 Sep 29, 2026
Confused Deputy in DevTools (Chrome <154.0.8037.57) Confused deputy in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
Chrome
CVE-2026-95385 Sep 29, 2026
Chrome Windows <154.0.8037.57 PlatformIntegration Bypass via Crafted HTML Inappropriate implementation in PlatformIntegration in Google Chrome on on Windows prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Chrome
CVE-2026-95352 Sep 29, 2026
DevTools Auth Bypass in Chrome <154.0.8037.57 via Extension Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Low)
Chrome
CVE-2026-95368 Sep 29, 2026
Chrome DevTools Authorisation Bypass <154.0.8037.57 Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Chrome
CVE-2026-95367 Sep 29, 2026
Info Leak via DataTransfer in Chrome <154.0.8037.57 Information leak in DataTransfer in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Chrome
CVE-2026-95279 Sep 29, 2026
Chrome Android UI Misrepresentation Omnibox Spoof <154.0.8037.57 UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)
Chrome
CVE-2026-95308 Sep 29, 2026
Google Chrome <154.0.8037.57 Integer Overflow in Metrics (Renderer) Integer overflow in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Chrome
CVE-2026-95292 Sep 29, 2026
Chrome SafeBrowsing Auth Bypass (<154.0.8037.57) Incorrect authorization in Safebrowsing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: Low)
Chrome
CVE-2026-95334 Sep 29, 2026
Google Chrome <154.0.8037.57 WebProtect RCE via Reference Resolution Incorrect reference resolution in WebProtect in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Chrome
CVE-2026-95307 Sep 29, 2026
UI Spoofing via ExtensionsMenu in Chrome <154.0.8037.57 UI misrepresentation in ExtensionsMenu in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Chrome
CVE-2026-95285 Sep 29, 2026
Chrome Android WebView Auth Bypass 154.0.8037.57 Missing authorization in WebView in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
Chrome
CVE-2026-95327 Sep 29, 2026
Info Leak in Chrome Networking before 154.0.8037.57 Information leak in Networking in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
Chrome
CVE-2026-95333 Sep 29, 2026
Chrome UA Free in Metrics before 154.0.8037.57 exec outside sandbox Use after free in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
Chrome
CVE-2026-95278 Sep 29, 2026
Google Chrome <154.0.8037.57 WakeLock Auth Bypass via Crafted HTML Missing authorization in WakeLock in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Chrome
CVE-2026-95358 Sep 29, 2026
Google Chrome Mobile Auth Bypass prior to 154.0.8037.57 Incorrect authorization in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to bypass system access restrictions into a privileged page via a co-installed app. (Chromium security severity: Medium)
Chrome
CVE-2026-95311 Sep 29, 2026
Chrome Fonts non-heap memory free RCE (pre-154.0.8037.57) Free of non-heap memory in Fonts in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Chrome
CVE-2026-95347 Sep 29, 2026
Chrome Updater UAF (Mac) <154.0.8037.57 Allows RCA Exec Use after free in Updater in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
Chrome
CVE-2026-95332 Sep 29, 2026
Uninitialized Var in Tint (Chrome Android <154.0.8037.57) Use of uninitialized variable in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Chrome
CVE-2026-95312 Sep 29, 2026
Info Leak in Chrome Passwords <154.0.8037.57 via Renderer Information leak in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Chrome
CVE-2026-95289 Sep 29, 2026
Incorrect Auth in Scroll (Chrome <154.0.8037.57) Incorrect authorization in Scroll in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Chrome
CVE-2026-95344 Sep 29, 2026
DevTools Race Condition: Chrome <154.0.8037.57 Bypasses Site Isolation Race condition in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass site isolation via a crafted Chrome extension. (Chromium security severity: Medium)
Chrome
CVE-2026-95323 Sep 29, 2026
Chrome iOS UI Spoofing Vulnerability in Chromium (URL Bar) Fixed 154.0.8037.57 UI misrepresentation in Chromium in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)
Chrome
CVE-2026-95300 Sep 29, 2026
Chrome DevTools Auth Bypass Before 154.0.8037.57 via Crafted Traffic Missing authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)
Chrome
CVE-2026-95374 Sep 29, 2026
Google Chrome <154.0.8037.57 Network Auth Bypass via Crafted HTML Incorrect authorization in Network in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Chrome
CVE-2026-95321 Sep 29, 2026
Chrome Android <154.0.8037.57 UI Spoof via Crafted HTML UI misrepresentation in Payments in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Chrome
CVE-2026-95290 Sep 29, 2026
Google Chrome <154.0.8037.57 NFC Auth Bypass via Renderer Missing authorization in NFC in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Chrome
CVE-2026-95325 Sep 29, 2026
Use-after-free in ANGLE before 154.0.8037.57 allows remote code exec in Chrome Use after free in ANGLE in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Chrome
CVE-2026-95336 Sep 29, 2026
Info Leak in Chrome Transactions Platform <154.0.8037.57 via Crafted HTML Information leak in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Chrome
CVE-2026-95275 Sep 29, 2026
Google Chrome <154.0.8037.57 MediaStream Ref Res. Bypass via crafted HTML Incorrect reference resolution in MediaStream in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
Chrome
CVE-2026-95341 Sep 29, 2026
Chrome Desktop <154.0.8037.57 Input Validation Execute External Code Improper input validation in Desktop in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
Chrome
CVE-2026-95384 Sep 29, 2026
Chrome <=154.0.8037.57 Transactions Platform RACE leaking info Race condition in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Chrome
CVE-2026-95363 Sep 29, 2026
Chrome FileSystem UI spoofing <154.0.8037.57 via crafted HTML UI misrepresentation in FileSystem in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Chrome
CVE-2026-95354 Sep 29, 2026
Use-After-Free in Chrome Verifier before 154.0.8037.57 Use after free in Verifier in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
Chrome
CVE-2026-95371 Sep 29, 2026
Missing Auth in Chrome Views (Mac) <154.0.8037.57 Spoof UI Missing authorization in Views in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Chrome
CVE-2026-95276 Sep 29, 2026
Chrome Themes Prior 154.0.8037.57 Improper Input Validation RCE Improper input validation in Themes in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code inside the sandbox via crafted network traffic. (Chromium security severity: Medium)
Chrome
CVE-2026-95314 Sep 29, 2026
Chrome pre-154.0.8037.57 HID Auth Bypass via HTML (CVE-2026-95314) Incorrect authorization in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Chrome
CVE-2026-95353 Sep 29, 2026
Google Chrome <154.0.8037.57 Use-After-Free in Bindings Use after free in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Chrome
CVE-2026-95303 Sep 29, 2026
Chrome 154.0.8037.57 - SmartCard Credential Bypass via HTML Incomplete cleanup in SmartCard in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Chrome
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.