CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2026-11701

    Last Modified: 9 Jun 2026

    Inappropriate implementation in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

    Published: 8 Jun 2026
    8.3
    High

    CVE-2026-11700

    Last Modified: 9 Jun 2026

    Use after free in Tracing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 8 Jun 2026
    8.8
    High

    CVE-2026-11699

    Last Modified: 9 Jun 2026

    Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    8.8
    High

    CVE-2026-11698

    Last Modified: 9 Jun 2026

    Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    5.3
    Medium

    CVE-2026-11696

    Last Modified: 9 Jun 2026

    Uninitialized Use in Video in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    4.3
    Medium

    CVE-2026-11695

    Last Modified: 9 Jun 2026

    Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    7.5
    High

    CVE-2026-11694

    Last Modified: 9 Jun 2026

    Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    8.1
    High

    CVE-2026-11693

    Last Modified: 9 Jun 2026

    Inappropriate implementation in Plugins in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    8.3
    High

    CVE-2026-11692

    Last Modified: 9 Jun 2026

    Use after free in Read Anything in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    3.1
    Low

    CVE-2026-11691

    Last Modified: 9 Jun 2026

    Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    7.5
    High

    CVE-2026-11690

    Last Modified: 9 Jun 2026

    Out of bounds read and write in Media in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    8.1
    High

    CVE-2026-11689

    Last Modified: 10 Jun 2026

    Insufficient policy enforcement in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    8.8
    High

    CVE-2026-11688

    Last Modified: 9 Jun 2026

    Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    8.8
    High

    CVE-2026-11687

    Last Modified: 9 Jun 2026

    Use after free in Dawn in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    3.1
    Low

    CVE-2026-11686

    Last Modified: 9 Jun 2026

    Insufficient validation of untrusted input in Dawn in Google Chrome on macOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    4.3
    Medium

    CVE-2026-11685

    Last Modified: 9 Jun 2026

    Inappropriate implementation in MediaCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    3.1
    Low

    CVE-2026-11684

    Last Modified: 9 Jun 2026

    Insufficient policy enforcement in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the utility process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    8.8
    High

    CVE-2026-11683

    Last Modified: 9 Jun 2026

    Use after free in WebCodecs in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    8.3
    High

    CVE-2026-11682

    Last Modified: 10 Jun 2026

    Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    8.8
    High

    CVE-2026-11681

    Last Modified: 10 Jun 2026

    Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    8.8
    High

    CVE-2026-11680

    Last Modified: 9 Jun 2026

    Use after free in Media in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    8.3
    High

    CVE-2026-11679

    Last Modified: 9 Jun 2026

    Use after free in Codecs in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    5.3
    Medium

    CVE-2026-11678

    Last Modified: 9 Jun 2026

    Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    8.3
    High

    CVE-2026-11676

    Last Modified: 10 Jun 2026

    Insufficient validation of untrusted input in Dawn in Google Chrome on Linux and ChromeOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    3.1
    Low

    CVE-2026-11675

    Last Modified: 9 Jun 2026

    Out of bounds read in Skia in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    8.8
    High

    CVE-2026-11674

    Last Modified: 9 Jun 2026

    Use after free in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    8.8
    High

    CVE-2026-11673

    Last Modified: 9 Jun 2026

    Use after free in InterestGroups in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    8.3
    High

    CVE-2026-11672

    Last Modified: 10 Jun 2026

    Heap buffer overflow in GPU in Google Chrome on Android prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    9.6
    Critical

    CVE-2026-11671

    Last Modified: 9 Jun 2026

    Use after free in Navigation in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    8.8
    High

    CVE-2026-11670

    Last Modified: 9 Jun 2026

    Use after free in PDF in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)

    Published: 8 Jun 2026
    5.3
    Medium

    CVE-2026-11669

    Last Modified: 10 Jun 2026

    Out of bounds read in Media in Google Chrome on ChromeOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    4.3
    Medium

    CVE-2026-11668

    Last Modified: 10 Jun 2026

    Uninitialized Use in Codecs in Google Chrome on Linux, ChromeOS prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted video file. (Chromium security severity: High)

    Published: 8 Jun 2026
    5.4
    Medium

    CVE-2026-11666

    Last Modified: 10 Jun 2026

    Insufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    4.3
    Medium

    CVE-2026-11665

    Last Modified: 9 Jun 2026

    Out of bounds read in Dawn in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    8.3
    High

    CVE-2026-11663

    Last Modified: 9 Jun 2026

    Use after free in Skia in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    8.8
    High

    CVE-2026-11662

    Last Modified: 9 Jun 2026

    Type Confusion in Bindings in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    6.5
    Medium

    CVE-2026-11658

    Last Modified: 10 Jun 2026

    Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    8.8
    High

    CVE-2026-11657

    Last Modified: 9 Jun 2026

    Use after free in Payments in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    8.3
    High

    CVE-2026-11656

    Last Modified: 9 Jun 2026

    Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: High)

    Published: 8 Jun 2026
    6.5
    Medium

    CVE-2026-11653

    Last Modified: 10 Jun 2026

    Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    8.3
    High

    CVE-2026-11652

    Last Modified: 9 Jun 2026

    Use after free in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    9.6
    Critical

    CVE-2026-11651

    Last Modified: 9 Jun 2026

    Use after free in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    8.8
    High

    CVE-2026-11650

    Last Modified: 9 Jun 2026

    Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    8.8
    High

    CVE-2026-11649

    Last Modified: 9 Jun 2026

    Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    8.3
    High

    CVE-2026-11647

    Last Modified: 9 Jun 2026

    Use after free in Printing in Google Chrome on Android prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    8.8
    High

    CVE-2026-11646

    Last Modified: 9 Jun 2026

    Use after free in ViewTransitions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    8.8
    High

    CVE-2026-11645

    Last Modified: 10 Jun 2026

    Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Jun 2026
    7.5
    High

    CVE-2026-11644

    Last Modified: 9 Jun 2026

    Use after free in Views in Google Chrome on Linux prior to 149.0.7827.103 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Critical)

    Published: 8 Jun 2026
    8.1
    High

    CVE-2026-11643

    Last Modified: 9 Jun 2026

    Use after free in Proxy in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)

    Published: 8 Jun 2026
    8.3
    High

    CVE-2026-11642

    Last Modified: 9 Jun 2026

    Use after free in Web Apps in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

    Published: 8 Jun 2026