apk package
wolfi/chromium
pkg:apk/wolfi/chromium
Vulnerabilities (2,588)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-79223 | Hig | 8.8 | < 152.0.7977.75-r0 | 152.0.7977.75-r0 | Aug 25, 2026 | Integer overflow in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory inside the sandbox via a crafted file. (Chromium security severity: Low) | |
| CVE-2026-79222 | Med | 4.3 | < 152.0.7977.75-r0 | 152.0.7977.75-r0 | Aug 25, 2026 | Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to bypass web origin policy via a co-installed app. (Chromium security severity: Medium) | |
| CVE-2026-79221 | Med | 6.5 | < 152.0.7977.75-r0 | 152.0.7977.75-r0 | Aug 25, 2026 | Uninitialized resource in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2026-79220 | Med | 5.3 | < 152.0.7977.75-r0 | 152.0.7977.75-r0 | Aug 25, 2026 | Information leak in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2026-79219 | Hig | 8.8 | < 152.0.7977.75-r0 | 152.0.7977.75-r0 | Aug 25, 2026 | Use after free in Bluetooth in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: High) | |
| CVE-2026-79218 | Hig | 8.3 | < 152.0.7977.75-r0 | 152.0.7977.75-r0 | Aug 25, 2026 | Incorrect authorization in Sandbox in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2026-79217 | Med | 4.3 | < 152.0.7977.75-r0 | 152.0.7977.75-r0 | Aug 25, 2026 | Incorrect authorization in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2026-79216 | Hig | 7.5 | < 152.0.7977.75-r0 | 152.0.7977.75-r0 | Aug 25, 2026 | Buffer overflow in Blink in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2026-79215 | Hig | 8.8 | < 152.0.7977.75-r0 | 152.0.7977.75-r0 | Aug 25, 2026 | Integer overflow in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2026-79214 | Med | 4.3 | < 152.0.7977.75-r0 | 152.0.7977.75-r0 | Aug 25, 2026 | Improper input validation in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2026-79213 | Med | 4.3 | < 152.0.7977.75-r0 | 152.0.7977.75-r0 | Aug 25, 2026 | Incorrect authorization in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2026-79212 | Med | 4.3 | < 152.0.7977.75-r0 | 152.0.7977.75-r0 | Aug 25, 2026 | Missing authorization in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2026-79211 | Med | 4.3 | < 152.0.7977.75-r0 | 152.0.7977.75-r0 | Aug 25, 2026 | Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2026-79210 | Hig | 8.3 | < 152.0.7977.75-r0 | 152.0.7977.75-r0 | Aug 25, 2026 | Use after free in Audio in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2026-79209 | Hig | 8.8 | < 152.0.7977.75-r0 | 152.0.7977.75-r0 | Aug 25, 2026 | Type confusion in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2026-79208 | Med | 5.9 | < 152.0.7977.75-r0 | 152.0.7977.75-r0 | Aug 25, 2026 | Missing authorization in HTTP2 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via crafted network traffic. (Chromium security severity: Medium) | |
| CVE-2026-79207 | Med | 6.5 | < 152.0.7977.75-r0 | 152.0.7977.75-r0 | Aug 25, 2026 | Information leak in Passwords in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensitive information via a crafted file. (Chromium security severity: Low) | |
| CVE-2026-79206 | Med | 6.5 | < 152.0.7977.75-r0 | 152.0.7977.75-r0 | Aug 25, 2026 | Out of bounds read in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low) | |
| CVE-2026-79205 | Med | 4.3 | < 152.0.7977.75-r0 | 152.0.7977.75-r0 | Aug 25, 2026 | Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2026-79204 | Med | 5.4 | < 152.0.7977.75-r0 | 152.0.7977.75-r0 | Aug 25, 2026 | UI misrepresentation in Input in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) |
- affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0
Integer overflow in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory inside the sandbox via a crafted file. (Chromium security severity: Low)
- affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0
Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to bypass web origin policy via a co-installed app. (Chromium security severity: Medium)
- affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0
Uninitialized resource in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0
Information leak in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
- affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0
Use after free in Bluetooth in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: High)
- affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0
Incorrect authorization in Sandbox in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0
Incorrect authorization in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
- affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0
Buffer overflow in Blink in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0
Integer overflow in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0
Improper input validation in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
- affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0
Incorrect authorization in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
- affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0
Missing authorization in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
- affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0
Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
- affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0
Use after free in Audio in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0
Type confusion in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0
Missing authorization in HTTP2 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via crafted network traffic. (Chromium security severity: Medium)
- affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0
Information leak in Passwords in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensitive information via a crafted file. (Chromium security severity: Low)
- affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0
Out of bounds read in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
- affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0
Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
- affected < 152.0.7977.75-r0fixed 152.0.7977.75-r0
UI misrepresentation in Input in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Page 4 of 130