Google Software and search
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Google product.
RSS Feeds for Google security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Google products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Google Sorted by Most Security Vulnerabilities since 2018
Recent Google Security Advisories
| Advisory | Title | Published |
|---|---|---|
| 2026-09-02 | Chrome Releases: September 2026 | September 2, 2026 |
| 2026-09-02 | Chrome Releases: Chrome Stable for iOS Update (version 153) | September 2, 2026 |
| 2026-09-02 | Chrome Releases: Stable Channel Update for Desktop (version 152.0.7977.75) | September 2, 2026 |
| 2026-09-02 | Chrome Releases: Chrome for Android (version 152) | September 2, 2026 |
| 2026-08-26 | Chrome Releases: Chrome for Android Update (version 152) | August 26, 2026 |
| 2026-08-26 | Chrome Releases: Stable Channel Update for Desktop (version 152) | August 26, 2026 |
| 2026-08-21 | Chrome Releases: Stable Channel Update for Desktop (version 151.0.7922.173) | August 21, 2026 |
| 2026-08-21 | Chrome Releases: Chrome for Android Update (version 151) | August 21, 2026 |
| 2026-08-19 | Chrome Releases: Chrome Stable for iOS Update (version 152) | August 19, 2026 |
| 2026-08-19 | Chrome Releases: Stable Channel Update for Desktop (version 151.0.7922.169) | August 19, 2026 |
Known Exploited Google Vulnerabilities
The following Google vulnerabilities have recently been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Google Chromium V8 Out-of-Bounds Read and Write Vulnerability |
Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2026-11645 Exploit Probability: 2.2% |
June 9, 2026 |
| Google Dawn Use-After-Free Vulnerability |
Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based products including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2026-5281 Exploit Probability: 5.5% |
April 1, 2026 |
| Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerabi |
Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2026-3910 Exploit Probability: 2.0% |
March 13, 2026 |
| Google Skia Out-of-Bounds Write Vulnerability |
Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products. CVE-2026-3909 Exploit Probability: 1.6% |
March 13, 2026 |
| Google Chromium CSS Use-After-Free Vulnerability |
Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2026-2441 Exploit Probability: 22.0% |
February 17, 2026 |
| Google Chromium Out of Bounds Memory Access Vulnerability |
Google Chromium contains an out of bounds memory access vulnerability in ANGLE that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2025-14174 Exploit Probability: 22.7% |
December 12, 2025 |
| Google Chromium V8 Type Confusion Vulnerability |
Google Chromium V8 contains a type confusion vulnerability that allows for heap corruption. CVE-2025-13223 Exploit Probability: 4.9% |
November 19, 2025 |
| Google Chromium V8 Type Confusion Vulnerability |
Google Chromium contains a type confusion vulnerability in the V8 JavaScript and WebAssembly engine. CVE-2025-10585 Exploit Probability: 5.4% |
September 23, 2025 |
| Google Chromium ANGLE and GPU Improper Input Validation Vulnerability |
Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. This vulnerability could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2025-6558 Exploit Probability: 9.0% |
July 22, 2025 |
| Google Chromium V8 Type Confusion Vulnerability |
Google Chromium V8 contains a type confusion vulnerability that could allow a remote attacker to perform arbitrary read/write via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2025-6554 Exploit Probability: 8.6% |
July 2, 2025 |
| Google Chromium V8 Out-of-Bounds Read and Write Vulnerability |
Google Chromium V8 contains an out-of-bounds read and write vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2025-5419 Exploit Probability: 6.5% |
June 5, 2025 |
| Google Chromium Loader Insufficient Policy Enforcement Vulnerability |
Google Chromium contains an insufficient policy enforcement vulnerability that allows a remote attacker to leak cross-origin data via a crafted HTML page. CVE-2025-4664 Exploit Probability: 5.4% |
May 15, 2025 |
| Google Chromium Mojo Sandbox Escape Vulnerability |
Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error, which results from an incorrect handle being provided in unspecified circumstances. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2025-2783 Exploit Probability: 8.4% |
March 27, 2025 |
| Google Chromium V8 Inappropriate Implementation Vulnerability |
Google Chromium V8 contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2024-7965 Exploit Probability: 18.4% |
August 28, 2024 |
| Google Chromium V8 Type Confusion Vulnerability |
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2024-7971 Exploit Probability: 20.5% |
August 26, 2024 |
| Google Chromium V8 Type Confusion Vulnerability |
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2024-5274 Exploit Probability: 10.0% |
May 28, 2024 |
| Google Chromium V8 Type Confusion Vulnerability |
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. CVE-2024-4947 Exploit Probability: 15.1% |
May 20, 2024 |
| Google Chromium V8 Out-of-Bounds Memory Write Vulnerability |
Google Chromium V8 Engine contains an unspecified out-of-bounds memory write vulnerability via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2024-4761 Exploit Probability: 11.0% |
May 16, 2024 |
| Google Chromium Visuals Use-After-Free Vulnerability |
Google Chromium Visuals contains a use-after-free vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2024-4671 Exploit Probability: 8.3% |
May 13, 2024 |
| Google Chromium V8 Type Confusion Vulnerability |
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. CVE-2023-4762 Exploit Probability: 38.0% |
February 6, 2024 |
8 known exploited Google vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.
Top 10 Riskiest Google Vulnerabilities
Based on the current exploit probability, these Google vulnerabilities are on CISA's Known Exploited vulnerabilities list (KEV) and are ranked by the current EPSS exploit probability.
| Rank | CVE | EPSS | Vulnerability |
|---|---|---|---|
| 1 | CVE-2023-4863 | 99.7% | Google Chromium Heap-Based Buffer Overflow Vulnerability |
| 2 | CVE-2018-17463 | 84.6% | Google Chromium V8 Remote Code Execution Vulnerability |
| 3 | CVE-2021-21224 | 84.2% | Chromium V8 JavaScript Engine Remote Code Execution Vulnerability |
| 4 | CVE-2020-6418 | 78.8% | Chromium V8 Type Confusion Vulnerability |
| 5 | CVE-2019-13720 | 73.0% | Google Chrome Use-After-Free Vulnerability |
| 6 | CVE-2021-21220 | 70.4% | Chromium V8 Input Validation Vulnerability |
| 7 | CVE-2021-30551 | 64.7% | Chromium V8 Type Confusion Vulnerability |
| 8 | CVE-2021-30632 | 64.5% | Google Chrome Out-of-bounds write |
| 9 | CVE-2019-5786 | 61.5% | Google Chrome Use-After-Free Vulnerability |
| 10 | CVE-2018-6065 | 60.3% | Google Chromium V8 Integer Overflow Vulnerability |
By the Year
In 2026 there have been 2847 vulnerabilities in Google with an average score of 7.1 out of ten. Last year, in 2025 Google had 720 security vulnerabilities published. That is, 2127 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.11
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 2847 | 7.06 |
| 2025 | 720 | 7.17 |
| 2024 | 1125 | 7.29 |
| 2023 | 1564 | 6.66 |
| 2022 | 1592 | 6.85 |
| 2021 | 1166 | 7.11 |
| 2020 | 1033 | 6.87 |
| 2019 | 858 | 7.33 |
| 2018 | 570 | 7.43 |
It may take a day or so for new Google vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Google Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-84356 | Sep 01, 2026 |
Chrome UI Misrep Spoof FullScreen before 152.0.7977.75UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-84350 | Sep 01, 2026 |
Chrome TabStrip UAF before 152.0.7977.75Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Low) |
|
| CVE-2026-84331 | Sep 01, 2026 |
Chrome <152: Actor Incorrect Auth Enables Web Origin Policy BypassIncorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-84329 | Sep 01, 2026 |
CredentialProvider Confused Deputy Leak Google Chrome <152.0.7977.75 on WindowsConfused deputy in CredentialProvider in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak sensitive information via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-84327 | Sep 01, 2026 |
Incorrect Authorization in Autofill (Google Chrome Android <152.0.7977.75)Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-84348 | Sep 01, 2026 |
Chrome MediaCapture Info Leak <152.0.7977.75Information leak in MediaCapture in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-84335 | Sep 01, 2026 |
Chrome TabStrip Auth Bypass <152.0.7977.75Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-84334 | Sep 01, 2026 |
Chromoting Auth Bypass: Local Exec in Chrome <152.0.7977.75 WindowsIncorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium) |
|
| CVE-2026-84332 | Sep 01, 2026 |
Google Chrome <=152.0.7977.75: SiteSettings auth bypass via crafted HTMLIncorrect authorization in SiteSettings in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-84330 | Sep 01, 2026 |
Chrome Android FullScreen UI Spoofing <152.0.7977.75UI misrepresentation in FullScreen in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-84358 | Sep 01, 2026 |
Chrome <=152.0.7977.75: Improper Priv Mgmt in Downloads Spoofs URL BarImproper privilege management in Downloads in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-84355 | Sep 01, 2026 |
Chrome <=152 Navigation Auth Bypass via RendererIncorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-84347 | Sep 01, 2026 |
Use-after-free Chrome WebRTC <152.0.7977.75Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-84328 | Sep 01, 2026 |
Chrome FileSystem Auth Bypass via Crafted HTML (pre-152.0.7977.75)Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-84325 | Sep 01, 2026 |
Google Chrome <152 Improper Input Validation in DataTransfer (CVE-2026-84325)Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High) |
|
| CVE-2026-84323 | Sep 01, 2026 |
Missing auth in Chrome FileSystem pre-152.0.7977.75 allows remote info leakMissing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-84349 | Sep 01, 2026 |
Use-after-free in Chrome <152.0.7977.75 Renderer: Remote Code ExecUse after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-84333 | Sep 01, 2026 |
Use After Free in Chrome's Dawn (Android pre-152.0.7977.75)Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-84326 | Sep 01, 2026 |
Uninitialized V8 Resource Enables Remote Code Exec in Chrome <152.0.7977.75Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-84324 | Sep 01, 2026 |
Chrome UA in Proxy before 152.0.7977.75 allows remote code execUse after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High) |
|
| CVE-2026-84351 | Sep 01, 2026 |
Buffer overflow in GPU in Google Chrome <152.0.7977.75 on WindowsBuffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-84352 | Sep 01, 2026 |
Google Chrome Android WebGL UAF RCE before 152.0.7977.75Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) |
|
| CVE-2026-84354 | Sep 01, 2026 |
Chrome FS Auth Bypass Pre-152.0.7977.75 Remote ExecIncorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-84357 | Sep 01, 2026 |
Chrome Omnibox Improper Input Validation (<=152.0.7977.75)Improper input validation in Omnibox in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: High) |
|
| CVE-2026-84359 | Sep 01, 2026 |
Google Chrome Skia Info Leak <152.0.7977.75Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-84353 | Sep 01, 2026 |
UEF in Shared Tab Groups: Chrome Android <152.0.7977.75 Remote Code ExecUse after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) |
|
| CVE-2026-19410 | Aug 31, 2026 |
CVE-2026-19410: Incorrect Auth in GCP Cloud Build GitHub Trigger Comment ControlAn Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-06-24 on Google Cloud Platform allows a remote attacker to execute unreviewed code in the build environment using webhook suppression. This vulnerability was patched on 24 June 2026, and no customer action is needed. |
|
| CVE-2026-82072 | Aug 27, 2026 |
Out of bounds read in V8 (Chrome <151.0.7922.72) allows RCEOut of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-19485 | Aug 26, 2026 |
Predictable Resource Name vulnerability in Google Cloud Vertex AI Search for CommerceA Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versions prior to 2026-04-27 on Google Cloud Platform allows an attacker knowing the victim's project number to obtain read/write access to staged data and error logs using predictable bucket names. This vulnerability was patched and no customer action is needed. |
|
| CVE-2026-75062 | Aug 26, 2026 |
Google Langfun Eval Injection via lf.query before 0.1.2Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in the default lf.query Python protocol in Google langfun versions prior to 0.1.2 allows remote unauthenticated attackers to execute arbitrary Python code in the context of the host application via crafted prompt inputs that cause the model to generate executable Python expressions evaluated without a sandbox. |
|
| CVE-2026-12717 | Aug 26, 2026 |
GCP BigQueryDTS RCE via Improper JDBC Connection String ValidationAn Improper Input Validation vulnerability in CData JDBC driver integration in Google Cloud BigQuery Data Transfer Service versions prior to 2026-05-01 on Google Cloud Platform allows an authenticated attacker to achieve remote code execution in the connector container and escalate privileges in the tenant project using crafted JDBC connection string parameters. This vulnerability was patched on 1 May 2026, and no customer action is needed. |
|
| CVE-2026-78964 | Aug 25, 2026 |
Use-after-free in Chrome Sync on iOS <152.0.7977.65Use after free in Sync in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-78914 | Aug 25, 2026 |
Uninitialized Skia Res Chrome <152.0.7977.65: Sandbox ReadUninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-79254 | Aug 25, 2026 |
Chrome CustomTabs Ref Res Bypass <152.0.7977.65Incorrect reference resolution in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-79260 | Aug 25, 2026 |
Google Chrome <152.0.7977.65 Cookie Input Validation BypassImproper input validation in Cookies in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-79126 | Aug 25, 2026 |
Chrome Proxy Info Leak Windows <152.0.7977.65Incorrect provision of specified functionality in Proxy in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker to potentially obtain sensitive information via crafted network traffic. (Chromium security severity: Low) |
|
| CVE-2026-78981 | Aug 25, 2026 |
Info Leak in Chrome Mobile iOS <152.0.7977.65 via Local ProgramInformation leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to potentially obtain sensitive information via a local program. (Chromium security severity: Low) |
|
| CVE-2026-78957 | Aug 25, 2026 |
Mobile Chrome iOS <152.0.7977.65 Info Leak via Crafted FileInformation leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensitive information via a crafted file. (Chromium security severity: Low) |
|
| CVE-2026-78915 | Aug 25, 2026 |
Race Condition in Chrome Enterprise on Windows <152.0.7977.65Race condition in Enterprise in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Low) |
|
| CVE-2026-79253 | Aug 25, 2026 |
Google Chrome Network: Improper Input Validation (v <152.0.7977.65)Improper input validation in Network in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-79021 | Aug 25, 2026 |
Google Chrome <152 Auth Bypass in InterestGroups via Crafted PDFMissing authorization in InterestGroups in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted PDF file. (Chromium security severity: Low) |
|
| CVE-2026-79133 | Aug 25, 2026 |
Chrome Forms IAM flaw <152.0.7977.65 sensitive data exfil via crafted pageIncorrect authorization in Forms in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-79152 | Aug 25, 2026 |
Chrome Android CustomTabs Auth Bypass < 152.0.7977.65Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to bypass web origin policy via a co-installed app. (Chromium security severity: Low) |
|
| CVE-2026-79179 | Aug 25, 2026 |
Google Chrome <152.0.7977.65: DOM Auth Bypass leaking dataIncorrect authorization in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-79225 | Aug 25, 2026 |
Browser Auth Bypass in Chrome Android 152.0.7977.65 (UI Interaction)Incorrect authorization in Browser in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via UI Interaction. (Chromium security severity: Low) |
|
| CVE-2026-79017 | Aug 25, 2026 |
Race Condition in Chrome Extensions 152.0.7977.65 - Remote System Access BypassRace condition in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Low) |
|
| CVE-2026-79105 | Aug 25, 2026 |
Google Chrome Mobile iOS Improper Input Validation (Pre-152.0.7977.65)Improper input validation in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-79125 | Aug 25, 2026 |
Information Leak in XR component of Google Chrome before 152.0.7977.65Information leak in XR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-79148 | Aug 25, 2026 |
Chrome DevTools OOB memory read via crafted extension (152.0.7977.65)Off-by-one error in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially read memory inside the sandbox via a crafted Chrome extension. (Chromium security severity: Low) |
|
| CVE-2026-79207 | Aug 25, 2026 |
Info leak in Chrome iOS passwords prior to 152.0.7977.65Information leak in Passwords in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensitive information via a crafted file. (Chromium security severity: Low) |
|