CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2026-14132

    Last Modified: 12 Aug 2026

    Inappropriate implementation in WebXR in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    5.4
    Medium

    CVE-2026-14131

    Last Modified: 3 Aug 2026

    Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    4.3
    Medium

    CVE-2026-14130

    Last Modified: 12 Aug 2026

    Incorrect security UI in Omnibox in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    4.2
    Medium

    CVE-2026-14129

    Last Modified: 31 Jul 2026

    Inappropriate implementation in PreviewTab in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    4.3
    Medium

    CVE-2026-14128

    Last Modified: 2 Aug 2026

    Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    4.3
    Medium

    CVE-2026-14127

    Last Modified: 12 Aug 2026

    Inappropriate implementation in Printing in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    4.3
    Medium

    CVE-2026-14126

    Last Modified: 31 Jul 2026

    Incorrect security UI in UI in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    6.5
    Medium

    CVE-2026-14125

    Last Modified: 1 Jul 2026

    Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    7.8
    High

    CVE-2026-14124

    Last Modified: 2 Aug 2026

    Inappropriate implementation in CredentialProvider in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Low)

    Published: 30 Jun 2026
    4.3
    Medium

    CVE-2026-14123

    Last Modified: 31 Jul 2026

    Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    8.1
    High

    CVE-2026-14122

    Last Modified: 3 Aug 2026

    Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    9.8
    Critical

    CVE-2026-14121

    Last Modified: 31 Jul 2026

    Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Low)

    Published: 30 Jun 2026
    9.6
    Critical

    CVE-2026-14120

    Last Modified: 12 Aug 2026

    Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    6.5
    Medium

    CVE-2026-14119

    Last Modified: 1 Jul 2026

    Type Confusion in Bluetooth in Google Chrome on Windows prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sensitive information from process memory via a malicious peripheral. (Chromium security severity: Low)

    Published: 30 Jun 2026
    6.5
    Medium

    CVE-2026-14118

    Last Modified: 12 Aug 2026

    Insufficient data validation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    5.3
    Medium

    CVE-2026-14117

    Last Modified: 1 Jul 2026

    Insufficient validation of untrusted input in DevTools in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    4.3
    Medium

    CVE-2026-14116

    Last Modified: 2 Aug 2026

    Insufficient validation of untrusted input in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    7.5
    High

    CVE-2026-14115

    Last Modified: 31 Jul 2026

    Insufficient validation of untrusted input in Cast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    7.5
    High

    CVE-2026-14114

    Last Modified: 31 Jul 2026

    Inappropriate implementation in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium security severity: Low)

    Published: 30 Jun 2026
    9.6
    Critical

    CVE-2026-14113

    Last Modified: 3 Aug 2026

    Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    5.3
    Medium

    CVE-2026-14112

    Last Modified: 1 Jul 2026

    Inappropriate implementation in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    8.1
    High

    CVE-2026-14111

    Last Modified: 2 Aug 2026

    Use after free in WebProtect in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Low)

    Published: 30 Jun 2026
    4.3
    Medium

    CVE-2026-14110

    Last Modified: 12 Aug 2026

    Inappropriate implementation in DarkMode in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    9.6
    Critical

    CVE-2026-14109

    Last Modified: 12 Aug 2026

    Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    8.8
    High

    CVE-2026-14108

    Last Modified: 3 Aug 2026

    Use after free in PDFium in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)

    Published: 30 Jun 2026
    8.8
    High

    CVE-2026-14107

    Last Modified: 2 Aug 2026

    Use after free in Scheduling in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    9.6
    Critical

    CVE-2026-14106

    Last Modified: 3 Aug 2026

    Insufficient validation of untrusted input in Text in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    4.3
    Medium

    CVE-2026-14105

    Last Modified: 2 Aug 2026

    Insufficient policy enforcement in Speech in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    9.8
    Critical

    CVE-2026-14104

    Last Modified: 2 Aug 2026

    Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    6.5
    Medium

    CVE-2026-14103

    Last Modified: 1 Jul 2026

    Use after free in SSL in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    8.8
    High

    CVE-2026-14102

    Last Modified: 31 Jul 2026

    Use after free in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    6.5
    Medium

    CVE-2026-14100

    Last Modified: 3 Aug 2026

    Insufficient data validation in NetworkCache in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    9.6
    Critical

    CVE-2026-14101

    Last Modified: 2 Jul 2026

    Insufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    8.8
    High

    CVE-2026-14099

    Last Modified: 2 Aug 2026

    Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    6.5
    Medium

    CVE-2026-14098

    Last Modified: 31 Jul 2026

    Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    9.6
    Critical

    CVE-2026-14097

    Last Modified: 31 Jul 2026

    Inappropriate implementation in WebAppInstalls in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    6.5
    Medium

    CVE-2026-14096

    Last Modified: 31 Jul 2026

    Inappropriate implementation in Input in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    9.6
    Critical

    CVE-2026-14095

    Last Modified: 31 Jul 2026

    Insufficient policy enforcement in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    7.8
    High

    CVE-2026-14094

    Last Modified: 2 Aug 2026

    Use after free in Installer in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Low)

    Published: 30 Jun 2026
    9.6
    Critical

    CVE-2026-14093

    Last Modified: 3 Aug 2026

    Use after free in Cast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    4.3
    Medium

    CVE-2026-14092

    Last Modified: 3 Aug 2026

    Insufficient policy enforcement in Privacy in Google Chrome prior to 150.0.7871.47 allowed an attacker in a privileged network position to leak cross-origin data via malicious network traffic. (Chromium security severity: Low)

    Published: 30 Jun 2026
    8.8
    High

    CVE-2026-14091

    Last Modified: 3 Aug 2026

    Use after free in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    8.1
    High

    CVE-2026-14090

    Last Modified: 2 Aug 2026

    Insufficient validation of untrusted input in CameraCapture in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    4.3
    Medium

    CVE-2026-14089

    Last Modified: 31 Jul 2026

    Insufficient validation of untrusted input in PopupBlocker in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    6.5
    Medium

    CVE-2026-14088

    Last Modified: 1 Jul 2026

    Uninitialized Use in Canvas in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    8.8
    High

    CVE-2026-14087

    Last Modified: 12 Aug 2026

    Heap buffer overflow in WebNN in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    8.8
    High

    CVE-2026-14086

    Last Modified: 31 Jul 2026

    Insufficient policy enforcement in HID in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    6.5
    Medium

    CVE-2026-14085

    Last Modified: 31 Jul 2026

    Side-channel information leakage in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026
    8.8
    High

    CVE-2026-14084

    Last Modified: 3 Aug 2026

    Insufficient validation of untrusted input in Chromoting in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: Low)

    Published: 30 Jun 2026
    6.1
    Medium

    CVE-2026-14083

    Last Modified: 31 Jul 2026

    Insufficient validation of untrusted input in HTML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)

    Published: 30 Jun 2026