CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2026-10941

    Last Modified: 9 Jun 2026

    Out of bounds memory access in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-10963

    Last Modified: 6 Jun 2026

    Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-10948

    Last Modified: 9 Jun 2026

    Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-10982

    Last Modified: 6 Jun 2026

    Use after free in WebXR in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-10986

    Last Modified: 6 Jun 2026

    Integer overflow in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a malicious file. (Chromium security severity: High)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-10997

    Last Modified: 8 Jun 2026

    Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted Chrome Extension. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-10999

    Last Modified: 8 Jun 2026

    Integer overflow in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11083

    Last Modified: 8 Jun 2026

    Inappropriate implementation in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11087

    Last Modified: 8 Jun 2026

    Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11096

    Last Modified: 9 Jun 2026

    Out of bounds read in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    7.8
    High

    CVE-2026-11103

    Last Modified: 8 Jun 2026

    Inappropriate implementation in Installer in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11097

    Last Modified: 9 Jun 2026

    Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    9.6
    Critical

    CVE-2026-11120

    Last Modified: 8 Jun 2026

    Insufficient validation of untrusted input in Enterprise Reporting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.1
    Medium

    CVE-2026-11122

    Last Modified: 9 Jun 2026

    Inappropriate implementation in Keyboard in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11123

    Last Modified: 9 Jun 2026

    Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    4.3
    Medium

    CVE-2026-11257

    Last Modified: 8 Jun 2026

    Inappropriate implementation in Browser in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11268

    Last Modified: 9 Jun 2026

    Uninitialized Use in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11271

    Last Modified: 8 Jun 2026

    Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    4.3
    Medium

    CVE-2026-11274

    Last Modified: 9 Jun 2026

    Inappropriate implementation in DOM Distiller in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11283

    Last Modified: 8 Jun 2026

    Insufficient validation of untrusted input in Shortcuts in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Low)

    Published: 2 Jun 2026
    4.3
    Medium

    CVE-2026-11291

    Last Modified: 8 Jun 2026

    Inappropriate implementation in Android Autofill in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11284

    Last Modified: 9 Jun 2026

    Side-channel information leakage in PerformanceAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    7.7
    High

    CVE-2026-11297

    Last Modified: 8 Jun 2026

    Insufficient validation of untrusted input in Reader Mode in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Low)

    Published: 2 Jun 2026
    4.3
    Medium

    CVE-2026-11300

    Last Modified: 8 Jun 2026

    Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    9.6
    Critical

    CVE-2026-11293

    Last Modified: 9 Jun 2026

    Use after free in Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11306

    Last Modified: 8 Jun 2026

    Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-10964

    Last Modified: 6 Jun 2026

    Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-10987

    Last Modified: 6 Jun 2026

    Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11046

    Last Modified: 6 Jun 2026

    Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    5.3
    Medium

    CVE-2026-11004

    Last Modified: 8 Jun 2026

    Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11006

    Last Modified: 8 Jun 2026

    Out of bounds read in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11014

    Last Modified: 8 Jun 2026

    Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass site isolation via a crafted Chrome Extension. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11018

    Last Modified: 8 Jun 2026

    Insufficient policy enforcement in Actor in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11019

    Last Modified: 8 Jun 2026

    Inappropriate implementation in Payments in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11023

    Last Modified: 9 Jun 2026

    Inappropriate implementation in WebAppInstalls in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11025

    Last Modified: 9 Jun 2026

    Insufficient policy enforcement in Navigation in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.1
    Medium

    CVE-2026-11034

    Last Modified: 8 Jun 2026

    Insufficient validation of untrusted input in Tab Group Sync in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via malicious network traffic. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    9.6
    Critical

    CVE-2026-11029

    Last Modified: 10 Jun 2026

    Insufficient validation of untrusted input in Drag and Drop in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11039

    Last Modified: 8 Jun 2026

    Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11055

    Last Modified: 6 Jun 2026

    Use after free in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11059

    Last Modified: 6 Jun 2026

    Use after free in Blink in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11069

    Last Modified: 8 Jun 2026

    Insufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11080

    Last Modified: 8 Jun 2026

    Use after free in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11084

    Last Modified: 8 Jun 2026

    Inappropriate implementation in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    7.8
    High

    CVE-2026-11072

    Last Modified: 8 Jun 2026

    Use after free in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to execute arbitrary code via a malicious file. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11105

    Last Modified: 8 Jun 2026

    Insufficient validation of untrusted input in WebUI in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    5.3
    Medium

    CVE-2026-11098

    Last Modified: 9 Jun 2026

    Insufficient validation of untrusted input in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11109

    Last Modified: 8 Jun 2026

    Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11106

    Last Modified: 8 Jun 2026

    Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.1
    High

    CVE-2026-11111

    Last Modified: 8 Jun 2026

    Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026