CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2026-10979

    Last Modified: 5 Jun 2026

    Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.8
    High

    CVE-2026-10978

    Last Modified: 6 Jun 2026

    Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: High)

    Published: 4 Jun 2026
    6.5
    Medium

    CVE-2026-10977

    Last Modified: 5 Jun 2026

    Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    7.4
    High

    CVE-2026-10976

    Last Modified: 5 Jun 2026

    Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    9.6
    Critical

    CVE-2026-10974

    Last Modified: 5 Jun 2026

    Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    7.4
    High

    CVE-2026-10973

    Last Modified: 6 Jun 2026

    Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    9.6
    Critical

    CVE-2026-10971

    Last Modified: 6 Jun 2026

    Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.3
    High

    CVE-2026-10970

    Last Modified: 5 Jun 2026

    Insufficient validation of untrusted input in InterestGroups in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    7.5
    High

    CVE-2026-10969

    Last Modified: 5 Jun 2026

    Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.3
    High

    CVE-2026-10967

    Last Modified: 6 Jun 2026

    Use after free in SurfaceCapture in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.3
    High

    CVE-2026-10961

    Last Modified: 6 Jun 2026

    Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.3
    High

    CVE-2026-10960

    Last Modified: 5 Jun 2026

    Uninitialized Use in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.8
    High

    CVE-2026-10952

    Last Modified: 8 Jun 2026

    Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.8
    High

    CVE-2026-10951

    Last Modified: 8 Jun 2026

    Use after free in Autofill in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    6.5
    Medium

    CVE-2026-10950

    Last Modified: 8 Jun 2026

    Insufficient policy enforcement in Autofill in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    6.5
    Medium

    CVE-2026-10944

    Last Modified: 8 Jun 2026

    Insufficient policy enforcement in Autofill in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.8
    High

    CVE-2026-10939

    Last Modified: 6 Jun 2026

    Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    6.5
    Medium

    CVE-2026-10938

    Last Modified: 5 Jun 2026

    Inappropriate implementation in Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    6.5
    Medium

    CVE-2026-10937

    Last Modified: 5 Jun 2026

    Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.8
    High

    CVE-2026-10936

    Last Modified: 5 Jun 2026

    Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.8
    High

    CVE-2026-10935

    Last Modified: 5 Jun 2026

    Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.3
    High

    CVE-2026-10934

    Last Modified: 5 Jun 2026

    Use after free in Autofill in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.3
    High

    CVE-2026-10933

    Last Modified: 5 Jun 2026

    Use after free in Audio in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.8
    High

    CVE-2026-10932

    Last Modified: 5 Jun 2026

    Use after free in UI in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    9.6
    Critical

    CVE-2026-10931

    Last Modified: 5 Jun 2026

    Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.1
    High

    CVE-2026-10930

    Last Modified: 5 Jun 2026

    Out of bounds read in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.3
    High

    CVE-2026-10929

    Last Modified: 5 Jun 2026

    Heap buffer overflow in ANGLE in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.8
    High

    CVE-2026-10928

    Last Modified: 5 Jun 2026

    Script injection in Headless in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.3
    High

    CVE-2026-10927

    Last Modified: 5 Jun 2026

    Out of bounds read in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.8
    High

    CVE-2026-10926

    Last Modified: 5 Jun 2026

    Use after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to execute arbitrary code via malicious network traffic. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.3
    High

    CVE-2026-10925

    Last Modified: 5 Jun 2026

    Out of bounds write in Skia in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.3
    High

    CVE-2026-10924

    Last Modified: 5 Jun 2026

    Integer overflow in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.8
    High

    CVE-2026-10923

    Last Modified: 6 Jun 2026

    Use after free in WebAppInstalls in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to execute arbitrary code via a malicious file. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.8
    High

    CVE-2026-10922

    Last Modified: 5 Jun 2026

    Insufficient validation of untrusted input in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass same origin policy via malicious network traffic. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.3
    High

    CVE-2026-10921

    Last Modified: 5 Jun 2026

    Integer overflow in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.3
    High

    CVE-2026-10920

    Last Modified: 5 Jun 2026

    Insufficient validation of untrusted input in WebShare in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.3
    High

    CVE-2026-10919

    Last Modified: 5 Jun 2026

    Use after free in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.3
    High

    CVE-2026-10918

    Last Modified: 5 Jun 2026

    Use after free in Viz in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.3
    High

    CVE-2026-10917

    Last Modified: 5 Jun 2026

    Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    6.1
    Medium

    CVE-2026-10916

    Last Modified: 6 Jun 2026

    Insufficient validation of untrusted input in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.3
    High

    CVE-2026-10915

    Last Modified: 5 Jun 2026

    Use after free in Core in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.8
    High

    CVE-2026-10914

    Last Modified: 5 Jun 2026

    Use after free in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.8
    High

    CVE-2026-10913

    Last Modified: 5 Jun 2026

    Use after free in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    6.5
    Medium

    CVE-2026-10912

    Last Modified: 6 Jun 2026

    Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.3
    High

    CVE-2026-10911

    Last Modified: 5 Jun 2026

    Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.8
    High

    CVE-2026-10910

    Last Modified: 5 Jun 2026

    Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.3
    High

    CVE-2026-10909

    Last Modified: 5 Jun 2026

    Use after free in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.3
    High

    CVE-2026-10908

    Last Modified: 5 Jun 2026

    Use after free in FullScreen in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.8
    High

    CVE-2026-10907

    Last Modified: 5 Jun 2026

    Out of bounds write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    7.5
    High

    CVE-2026-10906

    Last Modified: 5 Jun 2026

    Use after free in WebAuthentication in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026