CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2026-50263

    Last Modified: 4 Aug 2026

    A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure.

    Published: 2 Jun 2026
    7.8
    High

    CVE-2026-50264

    Last Modified: 27 Jul 2026

    An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may be used to crash the server, or for privilege escalation if the X server runs as root.

    Published: 2 Jun 2026
    7.8
    High

    CVE-2026-50260

    Last Modified: 4 Aug 2026

    A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters via a second client connection. This may be used to crash the server, or for privilege escalation if the X server runs as root.

    Published: 2 Jun 2026
    7.8
    High

    CVE-2026-50257

    Last Modified: 4 Aug 2026

    A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to set up a fence and await that fence, then a second X connection destroys the fence, causing the use-after-free. This may be used to crash the server, or for privilege escalation if the X server runs as root.

    Published: 2 Jun 2026
    5.5
    Medium

    CVE-2026-50262

    Last Modified: 4 Aug 2026

    An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to information disclosure. A write path also exists but requires byte-swapped clients which is disabled by default.

    Published: 2 Jun 2026
    7.8
    High

    CVE-2026-50259

    Last Modified: 4 Aug 2026

    A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type index. The helper function CheckKeyTypes() writes to this buffer at a client-controlled offset, allowing a stack buffer overflow. This may be used to crash the server, or for privilege escalation if the X server runs as root.

    Published: 2 Jun 2026
    7.8
    High

    CVE-2026-50258

    Last Modified: 4 Aug 2026

    A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify or clamp non-canonical key types to XkbMaxShiftLevel. A client can change key types to excessive shift levels and trigger stack overflows. This is caused by an incomplete fix of CVE-2025-26597. This may be used to crash the server, or for privilege escalation if the X server runs as root.

    Published: 2 Jun 2026
    7.8
    High

    CVE-2026-50256

    Last Modified: 4 Aug 2026

    A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias resolution. The server allocates a 256 byte stack buffer but libXfont2's alias target name length is 1024 bytes. A font alias name between 257 and 1023 bytes causes the X server to copy that name into the undersized stack buffer without further checks. This may be used to crash the server, or for privilege escalation if the X server runs as root.

    Published: 2 Jun 2026
    7.8
    High

    CVE-2026-50261

    Last Modified: 4 Aug 2026

    A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while changing those counters. This may be used to crash the server, or for privilege escalation if the X server runs as root.

    Published: 2 Jun 2026
    7.5
    High

    CVE-2026-10946

    Last Modified: 9 Jun 2026

    Heap buffer overflow in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 2 Jun 2026
    8.3
    High

    CVE-2026-10949

    Last Modified: 9 Jun 2026

    Heap buffer overflow in Video in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 2 Jun 2026
    4.7
    Medium

    CVE-2026-11233

    Last Modified: 9 Jun 2026

    Insufficient policy enforcement in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11272

    Last Modified: 9 Jun 2026

    Insufficient validation of untrusted input in Reading List in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    4.3
    Medium

    CVE-2026-11277

    Last Modified: 9 Jun 2026

    Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    4.3
    Medium

    CVE-2026-11294

    Last Modified: 9 Jun 2026

    Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    5.3
    Medium

    CVE-2026-11005

    Last Modified: 10 Jun 2026

    Out of bounds read in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11195

    Last Modified: 10 Jun 2026

    Inappropriate implementation in MHTML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11196

    Last Modified: 10 Jun 2026

    Type Confusion in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted XML file. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.1
    Medium

    CVE-2026-11229

    Last Modified: 10 Jun 2026

    Inappropriate implementation in Enterprise in Google Chrome prior to 149.0.7827.53 allowed a local attacker to perform privilege escalation via physical access to the device. (Chromium security severity: Low)

    Published: 2 Jun 2026
    4.3
    Medium

    CVE-2026-11280

    Last Modified: 15 Jun 2026

    Inappropriate implementation in Signin in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    4.3
    Medium

    CVE-2026-11126

    Last Modified: 9 Jun 2026

    Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11129

    Last Modified: 8 Jun 2026

    Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11128

    Last Modified: 9 Jun 2026

    Inappropriate implementation in Web Share in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11141

    Last Modified: 8 Jun 2026

    Uninitialized Use in Audio in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11143

    Last Modified: 8 Jun 2026

    Out of bounds read in Extensions in Google Chrome on Linux prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11147

    Last Modified: 6 Jun 2026

    Use after free in WebML in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11144

    Last Modified: 8 Jun 2026

    Use after free in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    4.3
    Medium

    CVE-2026-11161

    Last Modified: 8 Jun 2026

    Inappropriate implementation in DataTransfer in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    4.3
    Medium

    CVE-2026-11159

    Last Modified: 8 Jun 2026

    Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    9.6
    Critical

    CVE-2026-11163

    Last Modified: 8 Jun 2026

    Use after free in Messages in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.1
    High

    CVE-2026-11170

    Last Modified: 8 Jun 2026

    Inappropriate implementation in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to perform OS-level privilege escalation via malicious network traffic. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.3
    Medium

    CVE-2026-11181

    Last Modified: 9 Jun 2026

    Inappropriate implementation in Media Session in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11191

    Last Modified: 9 Jun 2026

    Out of bounds memory access in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11194

    Last Modified: 10 Jun 2026

    Inappropriate implementation in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11230

    Last Modified: 10 Jun 2026

    Use after free in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11235

    Last Modified: 9 Jun 2026

    Insufficient policy enforcement in Compositing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11262

    Last Modified: 6 Jun 2026

    Use after free in TabStrip in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    7.5
    High

    CVE-2026-11265

    Last Modified: 8 Jun 2026

    Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11270

    Last Modified: 8 Jun 2026

    Inappropriate implementation in UI in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11288

    Last Modified: 9 Jun 2026

    Insufficient policy enforcement in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    6.1
    Medium

    CVE-2026-11273

    Last Modified: 8 Jun 2026

    Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11279

    Last Modified: 10 Jun 2026

    Out of bounds read in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11287

    Last Modified: 8 Jun 2026

    Insufficient policy enforcement in Navigation in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    4.3
    Medium

    CVE-2026-11292

    Last Modified: 9 Jun 2026

    Insufficient policy enforcement in Blink in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    5
    Medium

    CVE-2026-11290

    Last Modified: 15 Jun 2026

    Integer overflow in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to cause a denial of service via a malicious file. (Chromium security severity: Low)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11295

    Last Modified: 8 Jun 2026

    Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    4.3
    Medium

    CVE-2026-11298

    Last Modified: 9 Jun 2026

    Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11299

    Last Modified: 9 Jun 2026

    Integer overflow in Fonts in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11304

    Last Modified: 8 Jun 2026

    Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Low)

    Published: 2 Jun 2026
    6.3
    Medium

    CVE-2026-11308

    Last Modified: 8 Jun 2026

    Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Low)

    Published: 2 Jun 2026