VYPR

apk package

wolfi/chromium-lang

pkg:apk/wolfi/chromium-lang

Vulnerabilities (1,178)

  • CVE-2026-79140CriAug 25, 2026
    affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0

    Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79137MedAug 25, 2026
    affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0

    Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)

  • CVE-2026-79136MedAug 25, 2026
    affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0

    Incorrect authorization in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79134MedAug 25, 2026
    affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0

    Incorrect authorization in GetUserMedia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79133MedAug 25, 2026
    affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0

    Incorrect authorization in Forms in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-79132HigAug 25, 2026
    affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0

    Improper input validation in Input in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79131CriAug 25, 2026
    affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0

    Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-79130CriAug 25, 2026
    affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0

    Buffer overflow in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-79129CriAug 25, 2026
    affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0

    Use after free in Sessions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Medium)

  • CVE-2026-79128CriAug 25, 2026
    affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0

    Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79127HigAug 25, 2026
    affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0

    Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79125MedAug 25, 2026
    affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0

    Information leak in XR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-79124MedAug 25, 2026
    affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0

    Information leak in Intents in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-79122MedAug 25, 2026
    affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0

    Information leak in SignIn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium)

  • CVE-2026-79121HigAug 25, 2026
    affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0

    Improper input validation in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-79120MedAug 25, 2026
    affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0

    Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79119HigAug 25, 2026
    affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0

    Use after free in PDF in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: Low)

  • CVE-2026-79118MedAug 25, 2026
    affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0

    Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-79117MedAug 25, 2026
    affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0

    Race condition in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a co-installed app. (Chromium security severity: High)

  • CVE-2026-79116MedAug 25, 2026
    affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0

    Missing authorization in Viz in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

Page 7 of 59