VulnSea

Chrome vulnerabilities

CVEs whose affected-version data names the Chrome package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

506 CVEsRSS

CVE-2026-84330Medium· 5.4
3w ago

UI misrepresentation in FullScreen in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page

UI misrepresentation in FullScreen in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.26%via NVD
CVE-2026-84327Medium· 6.5⚖ disputed
3w ago

Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page

Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

▾ Sunlitgoogle · chromeEPSS 0.31%via NVD
CVE-2026-84353Critical· 9.6
3w ago

Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page

Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security s…

▾ Midnightgoogle · chromeEPSS 0.46%via NVD
CVE-2026-84352Critical· 9.6
3w ago

Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page

Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

▾ Midnightgoogle · chromeEPSS 0.46%via NVD
CVE-2026-84333Critical· 9.6
3w ago

Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page

Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.46%via NVD
CVE-2026-84356Medium· 4.3
3w ago

UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page

UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)

▾ SunlitGoogle · ChromeEPSS 0.24%via CVEORG
CVE-2026-84325Critical· 9.8
3w ago

Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app

Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High)

▾ MidnightGoogle · ChromeEPSS 0.40%via CVEORG
CVE-2026-84332Medium· 5.4
3w ago

chromium-browser: Google Chrome: System access restriction bypass via crafted HTML page (CVE-2026-84332)

A flaw was found in Google Chrome. This incorrect authorization vulnerability in SiteSettings allows a remote attacker to bypass system access restrictions by enticing a user to visit a specially crafted HTML page. This could lead to unaut…

▾ SunlitRed Hat · ChromeEPSS 0.29%via CSAF
CVE-2026-84357Medium· 6.5
3w ago

Improper input validation in Omnibox in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic

Improper input validation in Omnibox in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: High)

▾ SunlitGoogle · ChromeEPSS 0.27%via CVEORG
CVE-2026-82072High· 8.8
1mo ago

Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

▾ Twilightgoogle · chromeEPSS 0.41%via NVD
CVE-2026-79000Medium· 4.3
1mo ago

Improper input validation in DeviceBoundSessionCredentials in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic

Improper input validation in DeviceBoundSessionCredentials in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severi…

▾ SunlitGoogle · ChromeEPSS 0.25%via CVEORG
CVE-2026-78942Medium· 4.3
1mo ago

Incorrect reference resolution in Loader in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via crafted network traffic

Incorrect reference resolution in Loader in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via crafted network traffic. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.28%via CVEORG
CVE-2026-78979Medium· 4.3
1mo ago

Race condition in Core in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page

Race condition in Core in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

▾ SunlitGoogle · ChromeEPSS 0.21%via CVEORG
CVE-2026-78976Medium· 4.3
1mo ago

Improper input validation in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page

Improper input validation in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Me…

▾ SunlitGoogle · ChromeEPSS 0.27%via CVEORG
CVE-2026-79084Medium· 4.3
1mo ago

Inadequate encryption strength in Notifications in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page

Inadequate encryption strength in Notifications in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severit…

▾ SunlitGoogle · ChromeEPSS 0.13%via CVEORG
CVE-2026-79049High· 7.1⚖ disputed
1mo ago

chromium-browser: chromium-browser: Incorrect reference resolution in Passwords (CVE-2026-79049)

An incorrect reference resolution flaw was found in the Passwords component of the Chromium browser. Upstream bug(s): https://code.google.com/p/chromium/issues/detail?id=513786555

▾ TwilightRed Hat · ChromeEPSS 0.26%via CSAF
CVE-2026-79003Medium· 4.3
1mo ago

Incorrect authorization in Device in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page

Incorrect authorization in Device in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.24%via CVEORG
CVE-2026-79067Medium· 4.3
1mo ago

Missing authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page

Missing authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.24%via CVEORG
CVE-2026-79050Medium· 5.4
1mo ago

chromium-browser: Google Chrome: System access restriction bypass via crafted HTML page (CVE-2026-79050)

A flaw was found in Google Chrome's Network component. This incorrect authorization vulnerability allows a remote attacker to bypass system access restrictions. The attacker can achieve this by enticing a user to open a specially crafted H…

▾ SunlitRed Hat · ChromeEPSS 0.24%via CSAF
CVE-2026-79006Medium· 4.3
1mo ago

chromium-browser: Google Chrome: Web origin policy bypass via crafted network traffic (CVE-2026-79006)

A flaw was found in Google Chrome. This vulnerability, located in the HttpsUpgrades component, allows a remote attacker to bypass the web origin policy. By sending specially crafted network traffic, an attacker could circumvent security re…

▾ SunlitRed Hat · ChromeEPSS 0.25%via CSAF
CVE-2026-79136Medium· 5.4
1mo ago

chromium-browser: Chromium: Web origin policy bypass via incorrect ServiceWorker authorization (CVE-2026-79136)

A flaw was found in Chromium. This incorrect authorization vulnerability in the ServiceWorker component allows a remote attacker to bypass the web origin policy. By crafting a malicious HTML page, an attacker can circumvent security restri…

▾ SunlitRed Hat · ChromeEPSS 0.27%via CSAF
CVE-2026-79116Medium· 4.3
1mo ago

Missing authorization in Viz in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page

Missing authorization in Viz in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.27%via CVEORG
CVE-2026-79070Medium· 4.3
1mo ago

Incorrect reference resolution in Cache in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page

Incorrect reference resolution in Cache in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.33%via CVEORG
CVE-2026-79143Medium· 4.3
1mo ago

chromium-browser: Google Chrome FileSystem: System access bypass through crafted HTML and social engineering (CVE-2026-79143)

A flaw was found in Google Chrome's FileSystem component. This incorrect authorization vulnerability allows a remote attacker to bypass system access restrictions. By leveraging social engineering techniques with a specially crafted HTML p…

▾ SunlitRed Hat · ChromeEPSS 0.24%via CSAF
CVE-2026-79137Medium· 4.3
1mo ago

Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension

Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.22%via CVEORG
CVE-2026-79087Medium· 4.3
1mo ago

Injection in Chrome Tabs in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass system access restrictions via a crafted HTML page

Injection in Chrome Tabs in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.25%via CVEORG
CVE-2026-79199Medium· 4.3
1mo ago

chromium-browser: Chromium-browser: System access restriction bypass via crafted HTML page (CVE-2026-79199)

A flaw was found in chromium-browser. This incorrect authorization vulnerability allows a remote attacker to bypass system access restrictions. By crafting a malicious HTML page, an attacker can gain unauthorized access within the network …

▾ SunlitRed Hat · ChromeEPSS 0.24%via CSAF
CVE-2026-79192Medium· 4.3
1mo ago

Improper input validation in Variations in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via crafted network traffic

Improper input validation in Variations in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via crafted network traffic. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.25%via CVEORG
CVE-2026-79151Medium· 6.5⚖ disputed
1mo ago

chromium-browser: Chromium-browser Safebrowsing: Bypass system access restrictions via improper input validation. (CVE-2026-79151)

A flaw was found in Chromium-browser's Safebrowsing component. A remote attacker could exploit this vulnerability by providing a specially crafted file. This could allow the attacker to bypass system access restrictions.

▾ SunlitRed Hat · ChromeEPSS 0.23%via CSAF
CVE-2026-79205Medium· 4.3
1mo ago

Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page

Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.27%via CVEORG
Chrome vulnerabilities (CVEs) — page 11 · VulnSea