VYPR

Chrome on Android

by Google

CVEs (12)

  • CVE-2020-16010CriKEVNov 3, 2020
    risk 0.75cvss 9.6epss 0.06

    Heap buffer overflow in UI in Google Chrome on Android prior to 86.0.4240.185 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2026-17681CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Insufficient validation of untrusted input in Web Authentication in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity:…

  • CVE-2026-10959HigJun 4, 2026
    risk 0.57cvss 8.8epss 0.00

    Use after free in Input in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2019-5816HigJun 27, 2019
    risk 0.57cvss 8.8epss 0.02

    Process lifetime issue in Chrome in Google Chrome on Android prior to 74.0.3729.108 allowed a remote attacker to potentially persist an exploited process via a crafted HTML page.

  • CVE-2026-14096MedJun 30, 2026
    risk 0.42cvss 6.5epss 0.00

    Inappropriate implementation in Input in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-13866MedJun 30, 2026
    risk 0.42cvss 6.5epss 0.00

    Inappropriate implementation in Input in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-13816MedJun 30, 2026
    risk 0.42cvss 6.5epss 0.00

    Insufficient validation of untrusted input in File Input in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

  • CVE-2016-5187MedDec 18, 2016
    risk 0.42cvss 6.5epss 0.01

    Google Chrome prior to 54.0.2840.85 for Android incorrectly handled rapid transition into and out of full screen mode, which allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via crafted HTML pages.

  • CVE-2017-5082MedOct 27, 2017
    risk 0.36cvss 5.5epss 0.00

    Failure to take advantage of available mitigations in credit card autofill in Google Chrome prior to 59.0.3071.92 for Android allowed a local attacker to take screen shots of credit card information via a crafted HTML page.

  • CVE-2026-14140MedJun 30, 2026
    risk 0.28cvss 4.3epss 0.00

    Insufficient validation of untrusted input in Input in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-14126MedJun 30, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect security UI in UI in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2022-2479MedJul 28, 2022
    risk 0.28cvss 4.3epss 0.01

    Insufficient validation of untrusted input in File in Google Chrome on Android prior to 103.0.5060.134 allowed an attacker who convinced a user to install a malicious app to obtain potentially sensitive information from internal file directories via a crafted HTML page.