CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2026-79098

    Last Modified: 28 Aug 2026

    UI misrepresentation in PermissionElement in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    5.3
    Medium

    CVE-2026-79147

    Last Modified: 31 Aug 2026

    Information leak in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    5.3
    Medium

    CVE-2026-79089

    Last Modified: 31 Aug 2026

    Race condition in Transactions Platform in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    8.8
    High

    CVE-2026-79119

    Last Modified: 27 Aug 2026

    Use after free in PDF in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: Low)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-78897

    Last Modified: 27 Aug 2026

    Missing authorization in BrowserTag in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Low)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-79206

    Last Modified: 31 Aug 2026

    Out of bounds read in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79190

    Last Modified: 28 Aug 2026

    Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    5.3
    Medium

    CVE-2026-79181

    Last Modified: 27 Aug 2026

    Observable discrepancy in Glic in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-78979

    Last Modified: 28 Aug 2026

    Race condition in Core in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79000

    Last Modified: 28 Aug 2026

    Improper input validation in DeviceBoundSessionCredentials in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)

    Published: 25 Aug 2026
    5.3
    Medium

    CVE-2026-79196

    Last Modified: 26 Aug 2026

    Race condition in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    8.8
    High

    CVE-2026-78950

    Last Modified: 26 Aug 2026

    Integer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79077

    Last Modified: 31 Aug 2026

    Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    5.3
    Medium

    CVE-2026-79001

    Last Modified: 26 Aug 2026

    Information leak in Bluetooth in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    3.1
    Low

    CVE-2026-79289

    Last Modified: 31 Aug 2026

    Improper control of a resource through its lifetime in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79184

    Last Modified: 28 Aug 2026

    Missing authorization in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-79124

    Last Modified: 27 Aug 2026

    Information leak in Intents in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    8.1
    High

    CVE-2026-79263

    Last Modified: 31 Aug 2026

    Race condition in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via crafted network traffic. (Chromium security severity: Low)

    Published: 25 Aug 2026
    5.1
    Medium

    CVE-2026-79055

    Last Modified: 26 Aug 2026

    Information leak in Sharing in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker leveraging social engineering to obtain sensitive information via a co-installed app. (Chromium security severity: Low)

    Published: 25 Aug 2026
    5.4
    Medium

    CVE-2026-78974

    Last Modified: 31 Aug 2026

    UI misrepresentation in Linux Toolkit Theming in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79141

    Last Modified: 31 Aug 2026

    Incorrect authorization in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    4.2
    Medium

    CVE-2026-79025

    Last Modified: 31 Aug 2026

    Improper input validation in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    8.8
    High

    CVE-2026-79266

    Last Modified: 31 Aug 2026

    Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    8.8
    High

    CVE-2026-79073

    Last Modified: 26 Aug 2026

    Improper state validation in Parser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79185

    Last Modified: 28 Aug 2026

    Information leak in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    8.8
    High

    CVE-2026-79182

    Last Modified: 27 Aug 2026

    Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    3.4
    Low

    CVE-2026-79004

    Last Modified: 31 Aug 2026

    Out of bounds read in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    8.8
    High

    CVE-2026-78963

    Last Modified: 26 Aug 2026

    Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    3.4
    Low

    CVE-2026-78984

    Last Modified: 31 Aug 2026

    Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-78960

    Last Modified: 31 Aug 2026

    Information leak in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-79075

    Last Modified: 31 Aug 2026

    Information leak in Geolocation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    3.1
    Low

    CVE-2026-79034

    Last Modified: 27 Aug 2026

    Information leak in CORS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-79221

    Last Modified: 31 Aug 2026

    Uninitialized resource in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    7.5
    High

    CVE-2026-79139

    Last Modified: 27 Aug 2026

    Improper input validation in Media in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    8.8
    High

    CVE-2026-79033

    Last Modified: 26 Aug 2026

    Insufficient control flow management in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    3.1
    Low

    CVE-2026-79203

    Last Modified: 28 Aug 2026

    Improper input validation in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    8.8
    High

    CVE-2026-79227

    Last Modified: 31 Aug 2026

    Type confusion in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    8.8
    High

    CVE-2026-79097

    Last Modified: 26 Aug 2026

    Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    7.5
    High

    CVE-2026-78901

    Last Modified: 26 Aug 2026

    Race condition in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-78962

    Last Modified: 27 Aug 2026

    Uninitialized resource in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79252

    Last Modified: 28 Aug 2026

    Information leak in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79211

    Last Modified: 31 Aug 2026

    Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    8.1
    High

    CVE-2026-78913

    Last Modified: 26 Aug 2026

    Use after free in Chromoting in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-79258

    Last Modified: 31 Aug 2026

    Incorrect authorization in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    5.3
    Medium

    CVE-2026-79265

    Last Modified: 31 Aug 2026

    Incomplete cleanup in GetUserMedia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    9.6
    Critical

    CVE-2026-79091

    Last Modified: 26 Aug 2026

    Use after free in Bluetooth in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-79249

    Last Modified: 28 Aug 2026

    Code injection in Bisection in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted file. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    9.6
    Critical

    CVE-2026-78951

    Last Modified: 26 Aug 2026

    Use after free in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    5.3
    Medium

    CVE-2026-79220

    Last Modified: 28 Aug 2026

    Information leak in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79003

    Last Modified: 31 Aug 2026

    Incorrect authorization in Device in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026