CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2026-79254

    Last Modified: 27 Aug 2026

    Incorrect reference resolution in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-79260

    Last Modified: 31 Aug 2026

    Improper input validation in Cookies in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-79253

    Last Modified: 26 Aug 2026

    Improper input validation in Network in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    7.5
    High

    CVE-2026-78915

    Last Modified: 27 Aug 2026

    Race condition in Enterprise in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Low)

    Published: 25 Aug 2026
    5.9
    Medium

    CVE-2026-79126

    Last Modified: 27 Aug 2026

    Incorrect provision of specified functionality in Proxy in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker to potentially obtain sensitive information via crafted network traffic. (Chromium security severity: Low)

    Published: 25 Aug 2026
    5.5
    Medium

    CVE-2026-78957

    Last Modified: 2 Sept 2026

    Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensitive information via a crafted file. (Chromium security severity: Low)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-78981

    Last Modified: 27 Aug 2026

    Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to potentially obtain sensitive information via a local program. (Chromium security severity: Low)

    Published: 25 Aug 2026
    9.8
    Critical

    CVE-2026-79152

    Last Modified: 27 Aug 2026

    Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to bypass web origin policy via a co-installed app. (Chromium security severity: Low)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-79179

    Last Modified: 27 Aug 2026

    Incorrect authorization in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-79133

    Last Modified: 27 Aug 2026

    Incorrect authorization in Forms in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-79021

    Last Modified: 28 Aug 2026

    Missing authorization in InterestGroups in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted PDF file. (Chromium security severity: Low)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79225

    Last Modified: 27 Aug 2026

    Incorrect authorization in Browser in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via UI Interaction. (Chromium security severity: Low)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79105

    Last Modified: 28 Aug 2026

    Improper input validation in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-79017

    Last Modified: 27 Aug 2026

    Race condition in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Low)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-79207

    Last Modified: 27 Aug 2026

    Information leak in Passwords in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensitive information via a crafted file. (Chromium security severity: Low)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-79125

    Last Modified: 27 Aug 2026

    Information leak in XR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    9.1
    Critical

    CVE-2026-79148

    Last Modified: 31 Aug 2026

    Off-by-one error in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially read memory inside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)

    Published: 25 Aug 2026
    8.8
    High

    CVE-2026-79197

    Last Modified: 26 Aug 2026

    Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    8.8
    High

    CVE-2026-79045

    Last Modified: 27 Aug 2026

    Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    8.8
    High

    CVE-2026-79223

    Last Modified: 28 Aug 2026

    Integer overflow in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory inside the sandbox via a crafted file. (Chromium security severity: Low)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-79246

    Last Modified: 28 Aug 2026

    Information leak in DataTransfer in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-79112

    Last Modified: 31 Aug 2026

    Out of bounds read in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    8.8
    High

    CVE-2026-79244

    Last Modified: 31 Aug 2026

    Use after free in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-78947

    Last Modified: 28 Aug 2026

    Incomplete cleanup in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Low)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-78980

    Last Modified: 28 Aug 2026

    Improper input validation in ReaderMode in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-79018

    Last Modified: 27 Aug 2026

    Information leak in FoldableAPIs in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    9.6
    Critical

    CVE-2026-79056

    Last Modified: 26 Aug 2026

    Use after free in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-79108

    Last Modified: 31 Aug 2026

    UI misrepresentation in Web Authentication (Passkeys & Security Keys) in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79015

    Last Modified: 28 Aug 2026

    Improper input validation in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-79239

    Last Modified: 27 Aug 2026

    Out of bounds read in Tint in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    8.8
    High

    CVE-2026-78956

    Last Modified: 26 Aug 2026

    Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-79177

    Last Modified: 28 Aug 2026

    Incorrect authorization in Media in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-79060

    Last Modified: 31 Aug 2026

    Incorrect authorization in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79009

    Last Modified: 28 Aug 2026

    UI misrepresentation in UI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    9.1
    Critical

    CVE-2026-79058

    Last Modified: 31 Aug 2026

    Missing authorization in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-78896

    Last Modified: 27 Aug 2026

    Information leak in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79284

    Last Modified: 27 Aug 2026

    UI misrepresentation in Core in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79041

    Last Modified: 27 Aug 2026

    Missing authorization in Browser in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-78968

    Last Modified: 27 Aug 2026

    Missing authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially spoof address bar via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-78946

    Last Modified: 27 Aug 2026

    Incorrect authorization in Select in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    9.8
    Critical

    CVE-2026-79090

    Last Modified: 28 Aug 2026

    Improper privilege management in Actor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-79005

    Last Modified: 27 Aug 2026

    Incorrect authorization in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-79123

    Last Modified: 27 Aug 2026

    Improper input validation in NTP Footer in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-79243

    Last Modified: 27 Aug 2026

    Improper input validation in ReadingList in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79273

    Last Modified: 28 Aug 2026

    Incorrect reference resolution in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79040

    Last Modified: 27 Aug 2026

    Uninitialized resource in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-78977

    Last Modified: 27 Aug 2026

    Uninitialized resource in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79261

    Last Modified: 31 Aug 2026

    Incorrect authorization in Controls in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79233

    Last Modified: 27 Aug 2026

    UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79022

    Last Modified: 28 Aug 2026

    UI misrepresentation in Transactions Platform in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026