Google Software and search
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Google product.
RSS Feeds for Google security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Google products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Google Sorted by Most Security Vulnerabilities since 2018
Recent Google Security Advisories
| Advisory | Title | Published |
|---|---|---|
| 2026-09-29 | Chrome Releases: Chrome for Android Update (version 154) | September 29, 2026 |
| 2026-09-29 | Chrome Releases: Stable Channel Update for Desktop (version 154.0.8037.92) | September 29, 2026 |
| 2026-09-25 | Chrome Releases: Stable Channel Update for ChromeOS / ChromeOS Flex | September 25, 2026 |
| 2026-09-22 | Chrome Releases: Chrome Stable for iOS Update (version 154) | September 22, 2026 |
| 2026-09-22 | Chrome Releases: Stable Channel Update for Desktop (version 154) | September 22, 2026 |
| 2026-09-22 | Chrome Releases: Chrome for Android Update (version 154) | September 22, 2026 |
| 2026-09-18 | Chrome Releases: Stable Channel Update for Desktop (version 153.0.8010.52) | September 18, 2026 |
| 2026-09-18 | Chrome Releases: Chrome for Android Update (version 153) | September 18, 2026 |
| 2026-09-17 | Chrome Releases: Stable Channel Update for ChromeOS / ChromeOS Flex | September 17, 2026 |
| 2026-09-16 | Chrome Releases: Chrome for Android Update (version 153) | September 16, 2026 |
Known Exploited Google Vulnerabilities
The following Google vulnerabilities have recently been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Google Pixel Improper Authorization Vulnerability |
Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges. CVE-2026-58704 |
September 16, 2026 |
| Google Chromium V8 Out of Bounds Write Vulnerability |
Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2026-87491 |
September 9, 2026 |
| Google Chromium V8 Type Confusion Vulnerability |
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2026-85046 |
September 4, 2026 |
| Google Chromium V8 Out-of-Bounds Read and Write Vulnerability |
Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2026-11645 Exploit Probability: 2.2% |
June 9, 2026 |
| Google Dawn Use-After-Free Vulnerability |
Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based products including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2026-5281 Exploit Probability: 5.5% |
April 1, 2026 |
| Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerabi |
Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2026-3910 Exploit Probability: 2.0% |
March 13, 2026 |
| Google Skia Out-of-Bounds Write Vulnerability |
Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products. CVE-2026-3909 Exploit Probability: 1.6% |
March 13, 2026 |
| Google Chromium CSS Use-After-Free Vulnerability |
Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2026-2441 Exploit Probability: 22.0% |
February 17, 2026 |
| Google Chromium Out of Bounds Memory Access Vulnerability |
Google Chromium contains an out of bounds memory access vulnerability in ANGLE that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2025-14174 Exploit Probability: 22.3% |
December 12, 2025 |
| Google Chromium V8 Type Confusion Vulnerability |
Google Chromium V8 contains a type confusion vulnerability that allows for heap corruption. CVE-2025-13223 Exploit Probability: 5.0% |
November 19, 2025 |
| Google Chromium V8 Type Confusion Vulnerability |
Google Chromium contains a type confusion vulnerability in the V8 JavaScript and WebAssembly engine. CVE-2025-10585 Exploit Probability: 5.4% |
September 23, 2025 |
| Google Chromium ANGLE and GPU Improper Input Validation Vulnerability |
Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. This vulnerability could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2025-6558 Exploit Probability: 9.6% |
July 22, 2025 |
| Google Chromium V8 Type Confusion Vulnerability |
Google Chromium V8 contains a type confusion vulnerability that could allow a remote attacker to perform arbitrary read/write via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2025-6554 Exploit Probability: 12.6% |
July 2, 2025 |
| Google Chromium V8 Out-of-Bounds Read and Write Vulnerability |
Google Chromium V8 contains an out-of-bounds read and write vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2025-5419 Exploit Probability: 7.8% |
June 5, 2025 |
| Google Chromium Loader Insufficient Policy Enforcement Vulnerability |
Google Chromium contains an insufficient policy enforcement vulnerability that allows a remote attacker to leak cross-origin data via a crafted HTML page. CVE-2025-4664 Exploit Probability: 5.6% |
May 15, 2025 |
| Google Chromium Mojo Sandbox Escape Vulnerability |
Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error, which results from an incorrect handle being provided in unspecified circumstances. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2025-2783 Exploit Probability: 9.2% |
March 27, 2025 |
| Google Chromium V8 Inappropriate Implementation Vulnerability |
Google Chromium V8 contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2024-7965 Exploit Probability: 18.5% |
August 28, 2024 |
| Google Chromium V8 Type Confusion Vulnerability |
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2024-7971 Exploit Probability: 21.1% |
August 26, 2024 |
| Google Chromium V8 Type Confusion Vulnerability |
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2024-5274 Exploit Probability: 7.5% |
May 28, 2024 |
| Google Chromium V8 Type Confusion Vulnerability |
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. CVE-2024-4947 Exploit Probability: 15.2% |
May 20, 2024 |
8 known exploited Google vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.
Top 10 Riskiest Google Vulnerabilities
Based on the current exploit probability, these Google vulnerabilities are on CISA's Known Exploited vulnerabilities list (KEV) and are ranked by the current EPSS exploit probability.
| Rank | CVE | EPSS | Vulnerability |
|---|---|---|---|
| 1 | CVE-2023-4863 | 100.0% | Google Chromium Heap-Based Buffer Overflow Vulnerability |
| 2 | CVE-2018-17463 | 84.6% | Google Chromium V8 Remote Code Execution Vulnerability |
| 3 | CVE-2021-21224 | 84.2% | Chromium V8 JavaScript Engine Remote Code Execution Vulnerability |
| 4 | CVE-2020-6418 | 78.8% | Chromium V8 Type Confusion Vulnerability |
| 5 | CVE-2021-21220 | 70.4% | Chromium V8 Input Validation Vulnerability |
| 6 | CVE-2021-30551 | 64.7% | Chromium V8 Type Confusion Vulnerability |
| 7 | CVE-2021-30632 | 63.2% | Google Chrome Out-of-bounds write |
| 8 | CVE-2019-5786 | 61.1% | Google Chrome Use-After-Free Vulnerability |
| 9 | CVE-2018-6065 | 60.3% | Google Chromium V8 Integer Overflow Vulnerability |
| 10 | CVE-2019-5825 | 55.9% | Google Chromium V8 Out-of-Bounds Write Vulnerability |
By the Year
In 2026 there have been 3540 vulnerabilities in Google with an average score of 7.0 out of ten. Last year, in 2025 Google had 720 security vulnerabilities published. That is, 2820 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.13
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 3540 | 7.04 |
| 2025 | 720 | 7.17 |
| 2024 | 1125 | 7.29 |
| 2023 | 1564 | 6.66 |
| 2022 | 1592 | 6.85 |
| 2021 | 1166 | 7.11 |
| 2020 | 1033 | 6.87 |
| 2019 | 858 | 7.33 |
| 2018 | 570 | 7.43 |
It may take a day or so for new Google vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Google Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-95305 | Sep 29, 2026 |
Google Chrome Chromoting UI Spoofing before 154.0.8037.57UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic. (Chromium security severity: Low) |
|
| CVE-2026-95316 | Sep 29, 2026 |
Local Mem Read via Unchecked Return Value in Chrome <154.0.8037.57Unchecked return value in Performance in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially read memory via a local program. (Chromium security severity: Low) |
|
| CVE-2026-95340 | Sep 29, 2026 |
Chrome <154.0.8037.57: PIP Auth Bypass Web Origin Policy (CVE-2026-95340)Incorrect authorization in PictureInPicture in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-95364 | Sep 29, 2026 |
Google Chrome <154.0.8037.57 Passwords Input Validation SpoofImproper input validation in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-95328 | Sep 29, 2026 |
Google Chrome Android <154.0.8037.57: Confused Deputy via Coinstalled AppConfused deputy in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker leveraging social engineering to obtain sensitive information via a co-installed app. (Chromium security severity: Low) |
|
| CVE-2026-95380 | Sep 29, 2026 |
Type Confusion in V8 of Chrome v<154.0.8037.57: RCE via HTMLType confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-95296 | Sep 29, 2026 |
Chrome Core Mac auth flaw before 154.0.8037.57 cross-origin data leakMissing authorization in Core in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-95288 | Sep 29, 2026 |
UI Spoof via Crafted HTML in Chrome iOS <154.0.8037.57UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-95342 | Sep 29, 2026 |
Missing Auth in Chrome V8 <154.0.8037.57 Allowing Remote Web Origin BypassMissing authorization in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-95309 | Sep 29, 2026 |
Google Chrome Mobile iOS <154.0.8037.57 UI Spoofing via Crafted HTMLUI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-95319 | Sep 29, 2026 |
Chrome <154.0.8037.57: UAF in Printing, remote code exec riskUse after free in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-95326 | Sep 29, 2026 |
Google Chrome 154.0.8037.57 Bluetooth cleanup flaw bypasses restrictionsIncomplete cleanup in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-95361 | Sep 29, 2026 |
Confused Deputy in DevTools (Chrome <154.0.8037.57)Confused deputy in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-95385 | Sep 29, 2026 |
Chrome Windows <154.0.8037.57 PlatformIntegration Bypass via Crafted HTMLInappropriate implementation in PlatformIntegration in Google Chrome on on Windows prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-95352 | Sep 29, 2026 |
DevTools Auth Bypass in Chrome <154.0.8037.57 via ExtensionIncorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Low) |
|
| CVE-2026-95368 | Sep 29, 2026 |
Chrome DevTools Authorisation Bypass <154.0.8037.57Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-95367 | Sep 29, 2026 |
Info Leak via DataTransfer in Chrome <154.0.8037.57Information leak in DataTransfer in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-95279 | Sep 29, 2026 |
Chrome Android UI Misrepresentation Omnibox Spoof <154.0.8037.57UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-95308 | Sep 29, 2026 |
Google Chrome <154.0.8037.57 Integer Overflow in Metrics (Renderer)Integer overflow in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-95292 | Sep 29, 2026 |
Chrome SafeBrowsing Auth Bypass (<154.0.8037.57)Incorrect authorization in Safebrowsing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: Low) |
|
| CVE-2026-95334 | Sep 29, 2026 |
Google Chrome <154.0.8037.57 WebProtect RCE via Reference ResolutionIncorrect reference resolution in WebProtect in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-95307 | Sep 29, 2026 |
UI Spoofing via ExtensionsMenu in Chrome <154.0.8037.57UI misrepresentation in ExtensionsMenu in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-95285 | Sep 29, 2026 |
Chrome Android WebView Auth Bypass 154.0.8037.57Missing authorization in WebView in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-95327 | Sep 29, 2026 |
Info Leak in Chrome Networking before 154.0.8037.57Information leak in Networking in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-95333 | Sep 29, 2026 |
Chrome UA Free in Metrics before 154.0.8037.57 exec outside sandboxUse after free in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium) |
|
| CVE-2026-95278 | Sep 29, 2026 |
Google Chrome <154.0.8037.57 WakeLock Auth Bypass via Crafted HTMLMissing authorization in WakeLock in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) |
|
| CVE-2026-95358 | Sep 29, 2026 |
Google Chrome Mobile Auth Bypass prior to 154.0.8037.57Incorrect authorization in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to bypass system access restrictions into a privileged page via a co-installed app. (Chromium security severity: Medium) |
|
| CVE-2026-95311 | Sep 29, 2026 |
Chrome Fonts non-heap memory free RCE (pre-154.0.8037.57)Free of non-heap memory in Fonts in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-95347 | Sep 29, 2026 |
Chrome Updater UAF (Mac) <154.0.8037.57 Allows RCA ExecUse after free in Updater in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium) |
|
| CVE-2026-95332 | Sep 29, 2026 |
Uninitialized Var in Tint (Chrome Android <154.0.8037.57)Use of uninitialized variable in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-95312 | Sep 29, 2026 |
Info Leak in Chrome Passwords <154.0.8037.57 via RendererInformation leak in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-95289 | Sep 29, 2026 |
Incorrect Auth in Scroll (Chrome <154.0.8037.57)Incorrect authorization in Scroll in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-95344 | Sep 29, 2026 |
DevTools Race Condition: Chrome <154.0.8037.57 Bypasses Site IsolationRace condition in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass site isolation via a crafted Chrome extension. (Chromium security severity: Medium) |
|
| CVE-2026-95323 | Sep 29, 2026 |
Chrome iOS UI Spoofing Vulnerability in Chromium (URL Bar) Fixed 154.0.8037.57UI misrepresentation in Chromium in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof address bar via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-95300 | Sep 29, 2026 |
Chrome DevTools Auth Bypass Before 154.0.8037.57 via Crafted TrafficMissing authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium) |
|
| CVE-2026-95374 | Sep 29, 2026 |
Google Chrome <154.0.8037.57 Network Auth Bypass via Crafted HTMLIncorrect authorization in Network in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-95321 | Sep 29, 2026 |
Chrome Android <154.0.8037.57 UI Spoof via Crafted HTMLUI misrepresentation in Payments in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-95290 | Sep 29, 2026 |
Google Chrome <154.0.8037.57 NFC Auth Bypass via RendererMissing authorization in NFC in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-95325 | Sep 29, 2026 |
Use-after-free in ANGLE before 154.0.8037.57 allows remote code exec in ChromeUse after free in ANGLE in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-95336 | Sep 29, 2026 |
Info Leak in Chrome Transactions Platform <154.0.8037.57 via Crafted HTMLInformation leak in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-95275 | Sep 29, 2026 |
Google Chrome <154.0.8037.57 MediaStream Ref Res. Bypass via crafted HTMLIncorrect reference resolution in MediaStream in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-95341 | Sep 29, 2026 |
Chrome Desktop <154.0.8037.57 Input Validation Execute External CodeImproper input validation in Desktop in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium) |
|
| CVE-2026-95384 | Sep 29, 2026 |
Chrome <=154.0.8037.57 Transactions Platform RACE leaking infoRace condition in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-95363 | Sep 29, 2026 |
Chrome FileSystem UI spoofing <154.0.8037.57 via crafted HTMLUI misrepresentation in FileSystem in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-95354 | Sep 29, 2026 |
Use-After-Free in Chrome Verifier before 154.0.8037.57Use after free in Verifier in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium) |
|
| CVE-2026-95371 | Sep 29, 2026 |
Missing Auth in Chrome Views (Mac) <154.0.8037.57 Spoof UIMissing authorization in Views in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-95276 | Sep 29, 2026 |
Chrome Themes Prior 154.0.8037.57 Improper Input Validation RCEImproper input validation in Themes in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code inside the sandbox via crafted network traffic. (Chromium security severity: Medium) |
|
| CVE-2026-95314 | Sep 29, 2026 |
Chrome pre-154.0.8037.57 HID Auth Bypass via HTML (CVE-2026-95314)Incorrect authorization in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-95353 | Sep 29, 2026 |
Google Chrome <154.0.8037.57 Use-After-Free in BindingsUse after free in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-95303 | Sep 29, 2026 |
Chrome 154.0.8037.57 - SmartCard Credential Bypass via HTMLIncomplete cleanup in SmartCard in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) |
|