CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2026-14432

    Last Modified: 1 Aug 2026

    Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 1 Jul 2026
    8.8
    High

    CVE-2026-14393

    Last Modified: 1 Aug 2026

    Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 1 Jul 2026
    8.8
    High

    CVE-2026-14403

    Last Modified: 3 Aug 2026

    Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

    Published: 1 Jul 2026
    9.6
    Critical

    CVE-2026-14419

    Last Modified: 1 Aug 2026

    Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

    Published: 1 Jul 2026
    9.6
    Critical

    CVE-2026-14417

    Last Modified: 31 Jul 2026

    Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

    Published: 1 Jul 2026
    9.6
    Critical

    CVE-2026-14424

    Last Modified: 31 Jul 2026

    Use after free in Dawn in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Jul 2026
    9.6
    Critical

    CVE-2026-14425

    Last Modified: 3 Aug 2026

    Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Jul 2026
    9.6
    Critical

    CVE-2026-14390

    Last Modified: 31 Jul 2026

    Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Jul 2026
    9.6
    Critical

    CVE-2026-14398

    Last Modified: 31 Jul 2026

    Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

    Published: 1 Jul 2026
    9.6
    Critical

    CVE-2026-14405

    Last Modified: 31 Jul 2026

    Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

    Published: 1 Jul 2026
    6.5
    Medium

    CVE-2026-14399

    Last Modified: 31 Jul 2026

    Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

    Published: 1 Jul 2026
    6.5
    Medium

    CVE-2026-14408

    Last Modified: 1 Aug 2026

    Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

    Published: 1 Jul 2026
    6.5
    Medium

    CVE-2026-14421

    Last Modified: 3 Aug 2026

    Uninitialized Use in Dawn in Google Chrome on ChromeOS prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

    Published: 1 Jul 2026
    8.3
    High

    CVE-2026-14413

    Last Modified: 1 Aug 2026

    Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Jul 2026
    4.3
    Medium

    CVE-2026-14418

    Last Modified: 1 Aug 2026

    Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Jul 2026
    6.5
    Medium

    CVE-2026-14402

    Last Modified: 1 Aug 2026

    Uninitialized Use in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Jul 2026
    8.8
    High

    CVE-2026-14431

    Last Modified: 31 Jul 2026

    Type Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Jul 2026
    9.6
    Critical

    CVE-2026-14423

    Last Modified: 31 Jul 2026

    Type Confusion in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Jul 2026
    8.8
    High

    CVE-2026-14395

    Last Modified: 1 Aug 2026

    Out of bounds write in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

    Published: 1 Jul 2026
    9.6
    Critical

    CVE-2026-14392

    Last Modified: 3 Aug 2026

    Out of bounds write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Jul 2026
    8.3
    High

    CVE-2026-14400

    Last Modified: 3 Aug 2026

    Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Jul 2026
    9.6
    Critical

    CVE-2026-14397

    Last Modified: 31 Jul 2026

    Out of bounds write in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 1 Jul 2026
    5.9
    Medium

    CVE-2026-14406

    Last Modified: 1 Aug 2026

    Out of bounds read in V8 in Google Chrome prior to 150.0.7871.46 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. (Chromium security severity: Medium)

    Published: 1 Jul 2026
    9.6
    Critical

    CVE-2026-14416

    Last Modified: 3 Aug 2026

    Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

    Published: 1 Jul 2026
    6.5
    Medium

    CVE-2026-14388

    Last Modified: 4 Aug 2026

    Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

    Published: 1 Jul 2026
    6.5
    Medium

    CVE-2026-14386

    Last Modified: 1 Aug 2026

    Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Jul 2026
    6.5
    Medium

    CVE-2026-14396

    Last Modified: 31 Jul 2026

    Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Jul 2026
    6.5
    Medium

    CVE-2026-14384

    Last Modified: 1 Aug 2026

    Out of bounds read in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 1 Jul 2026
    8.8
    High

    CVE-2026-14422

    Last Modified: 31 Jul 2026

    Out of bounds read and write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Jul 2026
    9.6
    Critical

    CVE-2026-14420

    Last Modified: 3 Aug 2026

    Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

    Published: 1 Jul 2026
    8.8
    High

    CVE-2026-14430

    Last Modified: 12 Aug 2026

    Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Jul 2026
    8.3
    High

    CVE-2026-14389

    Last Modified: 1 Aug 2026

    Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 1 Jul 2026
    9.6
    Critical

    CVE-2026-14387

    Last Modified: 1 Aug 2026

    Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 1 Jul 2026
    5.3
    Medium

    CVE-2026-14391

    Last Modified: 12 Aug 2026

    Integer overflow in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

    Published: 1 Jul 2026
    8.3
    High

    CVE-2026-14429

    Last Modified: 3 Aug 2026

    Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Jul 2026
    5.3
    Medium

    CVE-2026-14414

    Last Modified: 3 Aug 2026

    Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

    Published: 1 Jul 2026
    8.3
    High

    CVE-2026-14428

    Last Modified: 3 Aug 2026

    Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Jul 2026
    8.3
    High

    CVE-2026-14412

    Last Modified: 1 Aug 2026

    Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Jul 2026
    9.6
    Critical

    CVE-2026-14411

    Last Modified: 1 Aug 2026

    Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Jul 2026
    9.6
    Critical

    CVE-2026-14382

    Last Modified: 1 Aug 2026

    Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Jul 2026
    8.3
    High

    CVE-2026-14401

    Last Modified: 3 Aug 2026

    Insufficient validation of untrusted input in ANGLE in Google Chrome on Android prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Jul 2026
    6.5
    Medium

    CVE-2026-14381

    Last Modified: 12 Aug 2026

    Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

    Published: 1 Jul 2026
    8.8
    High

    CVE-2026-14415

    Last Modified: 1 Aug 2026

    Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)

    Published: 1 Jul 2026
    7.5
    High

    CVE-2026-14409

    Last Modified: 31 Jul 2026

    Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

    Published: 1 Jul 2026
    8.8
    High

    CVE-2026-14407

    Last Modified: 31 Jul 2026

    Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 1 Jul 2026
    8.8
    High

    CVE-2026-14383

    Last Modified: 31 Jul 2026

    Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 1 Jul 2026
    4.3
    Medium

    CVE-2026-14410

    Last Modified: 31 Jul 2026

    Inappropriate implementation in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

    Published: 1 Jul 2026
    6.5
    Medium

    CVE-2026-14404

    Last Modified: 31 Jul 2026

    Inappropriate implementation in PDFium in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI spoofing via a crafted PDF file. (Chromium security severity: Medium)

    Published: 1 Jul 2026
    8.3
    High

    CVE-2026-14427

    Last Modified: 3 Aug 2026

    Heap buffer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

    Published: 1 Jul 2026
    8.8
    High

    CVE-2026-14385

    Last Modified: 12 Aug 2026

    Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Jul 2026