VYPR

CVEs

383,770 total · page 368 of 7,676

  • CVE-2026-79016MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Observable discrepancy in SVG in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79015MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Improper input validation in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-79014MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Race condition in Autofill in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-79013MedAug 25, 2026
    risk 0.38cvss 5.9epss 0.00

    Improper input validation in Sync in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium)

  • CVE-2026-79012CriAug 25, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in Safebrowsing in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-79011HigAug 25, 2026
    risk 0.53cvss 8.1epss 0.00

    UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-79010MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Operation on a resource after expiration or release in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79009MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    UI misrepresentation in UI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-79008HigAug 25, 2026
    risk 0.54cvss 8.3epss 0.00

    Improper input validation in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79007LowAug 25, 2026
    risk 0.20cvss 3.1epss 0.00

    Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79006MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Protection mechanism failure in HttpsUpgrades in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via crafted network traffic. (Chromium security severity: Medium)

  • CVE-2026-79005MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-79004LowAug 25, 2026
    risk 0.22cvss 3.4epss 0.00

    Out of bounds read in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79003MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Device in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79002LowAug 25, 2026
    risk 0.20cvss 3.1epss 0.00

    Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79001MedAug 25, 2026
    risk 0.34cvss 5.3epss 0.00

    Information leak in Bluetooth in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-79000MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Improper input validation in DeviceBoundSessionCredentials in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)

  • CVE-2026-78999HigAug 25, 2026
    risk 0.54cvss 8.3epss 0.00

    Improper privilege management in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium…

  • CVE-2026-78991MedAug 25, 2026
    risk 0.34cvss 5.3epss 0.00

    Race condition in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78990HigAug 25, 2026
    risk 0.57cvss 8.8epss 0.00

    Use after free in Compositing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78989CriAug 25, 2026
    risk 0.62cvss 9.6epss 0.00

    Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-78987MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Information leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78986LowAug 25, 2026
    risk 0.20cvss 3.1epss 0.00

    Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-78985CriAug 25, 2026
    risk 0.62cvss 9.6epss 0.01

    Incorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78984LowAug 25, 2026
    risk 0.22cvss 3.4epss 0.00

    Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78983HigAug 25, 2026
    risk 0.54cvss 8.3epss 0.00

    Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78981MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to potentially obtain sensitive information via a local program. (Chromium security severity: Low)

  • CVE-2026-78980MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Improper input validation in ReaderMode in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-78979MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Race condition in Core in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-78978HigAug 25, 2026
    risk 0.57cvss 8.8epss 0.00

    Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78977MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Uninitialized resource in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-78976MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Improper input validation in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78975MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78974MedAug 25, 2026
    risk 0.35cvss 5.4epss 0.00

    UI misrepresentation in Linux Toolkit Theming in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-78969MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Uninitialized resource in Video in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78968MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Missing authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially spoof address bar via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-78967MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Missing authorization in BFCache in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78966MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Externally controlled reference in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78965MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-78964CriAug 25, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in Sync in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-78963HigAug 25, 2026
    risk 0.57cvss 8.8epss 0.00

    Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78962MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Uninitialized resource in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78961MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78960MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Information leak in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)

  • CVE-2026-78959MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper handling of case sensitivity in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78958LowAug 25, 2026
    risk 0.20cvss 3.1epss 0.00

    Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78957MedAug 25, 2026
    risk 0.36cvss 5.5epss 0.00

    Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensitive information via a crafted file. (Chromium security severity: Low)

  • CVE-2026-78956HigAug 25, 2026
    risk 0.57cvss 8.8epss 0.00

    Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-78955MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Observable discrepancy in PerformanceAPIs in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78954MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)