CVE Feed

    Dashboard / CVE

    3.1
    Low

    CVE-2026-79031

    Last Modified: 28 Aug 2026

    Improper resource exposure in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    8.8
    High

    CVE-2026-78891

    Last Modified: 26 Aug 2026

    Buffer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79248

    Last Modified: 28 Aug 2026

    Incorrect authorization in Input in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    5.3
    Medium

    CVE-2026-78991

    Last Modified: 27 Aug 2026

    Race condition in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79084

    Last Modified: 28 Aug 2026

    Inadequate encryption strength in Notifications in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79095

    Last Modified: 28 Aug 2026

    Information leak in Payments in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79006

    Last Modified: 28 Aug 2026

    Protection mechanism failure in HttpsUpgrades in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via crafted network traffic. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79116

    Last Modified: 31 Aug 2026

    Missing authorization in Viz in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-78942

    Last Modified: 28 Aug 2026

    Incorrect reference resolution in Loader in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via crafted network traffic. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    9.6
    Critical

    CVE-2026-79128

    Last Modified: 27 Aug 2026

    Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    9.6
    Critical

    CVE-2026-79140

    Last Modified: 27 Aug 2026

    Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79192

    Last Modified: 28 Aug 2026

    Improper input validation in Variations in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via crafted network traffic. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79065

    Last Modified: 31 Aug 2026

    Improper input validation in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79144

    Last Modified: 31 Aug 2026

    Information leak in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-79271

    Last Modified: 31 Aug 2026

    Information leak in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    9.6
    Critical

    CVE-2026-78909

    Last Modified: 26 Aug 2026

    Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    8.8
    High

    CVE-2026-78990

    Last Modified: 26 Aug 2026

    Use after free in Compositing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-78987

    Last Modified: 28 Aug 2026

    Information leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    9.6
    Critical

    CVE-2026-78937

    Last Modified: 26 Aug 2026

    Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    9.6
    Critical

    CVE-2026-79129

    Last Modified: 27 Aug 2026

    Use after free in Sessions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79046

    Last Modified: 28 Aug 2026

    Race condition in Permissions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    8.3
    High

    CVE-2026-79210

    Last Modified: 31 Aug 2026

    Use after free in Audio in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    5.3
    Medium

    CVE-2026-79028

    Last Modified: 27 Aug 2026

    Observable discrepancy in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    9.6
    Critical

    CVE-2026-78985

    Last Modified: 27 Aug 2026

    Incorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    5.4
    Medium

    CVE-2026-78898

    Last Modified: 31 Aug 2026

    Incorrect authorization in Downloads in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79237

    Last Modified: 28 Aug 2026

    Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    8.3
    High

    CVE-2026-79256

    Last Modified: 28 Aug 2026

    Externally controlled reference in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    8.3
    High

    CVE-2026-79109

    Last Modified: 27 Aug 2026

    Improper input validation in Printing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    6.8
    Medium

    CVE-2026-79032

    Last Modified: 31 Aug 2026

    Improper input validation in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    3.1
    Low

    CVE-2026-78941

    Last Modified: 31 Aug 2026

    Information leak in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    8.3
    High

    CVE-2026-78999

    Last Modified: 27 Aug 2026

    Improper privilege management in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    9.6
    Critical

    CVE-2026-78945

    Last Modified: 26 Aug 2026

    Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    7.4
    High

    CVE-2026-79286

    Last Modified: 27 Aug 2026

    Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a co-installed app. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79010

    Last Modified: 28 Aug 2026

    Operation on a resource after expiration or release in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79016

    Last Modified: 31 Aug 2026

    Observable discrepancy in SVG in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79267

    Last Modified: 31 Aug 2026

    Race condition in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    3.1
    Low

    CVE-2026-79186

    Last Modified: 31 Aug 2026

    Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-78966

    Last Modified: 28 Aug 2026

    Externally controlled reference in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-79176

    Last Modified: 27 Aug 2026

    UI misrepresentation in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79106

    Last Modified: 31 Aug 2026

    Improper input validation in Input in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79262

    Last Modified: 31 Aug 2026

    Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-78961

    Last Modified: 28 Aug 2026

    Incorrect authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    3.1
    Low

    CVE-2026-78958

    Last Modified: 31 Aug 2026

    Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    5.3
    Medium

    CVE-2026-79044

    Last Modified: 27 Aug 2026

    Missing authorization in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    5.3
    Medium

    CVE-2026-79104

    Last Modified: 28 Aug 2026

    Missing authorization in Sensor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-79088

    Last Modified: 31 Aug 2026

    Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-79076

    Last Modified: 31 Aug 2026

    Improper input validation in Sync in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    8.3
    High

    CVE-2026-79071

    Last Modified: 27 Aug 2026

    Race condition in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-79222

    Last Modified: 28 Aug 2026

    Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to bypass web origin policy via a co-installed app. (Chromium security severity: Medium)

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-78893

    Last Modified: 27 Aug 2026

    Information leak in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)

    Published: 25 Aug 2026