VYPR

Chromium

by Chromium

Source repositories

CVEs (1,466)

  • CVE-2021-30612HigSep 3, 2021
    risk 0.57cvss 8.8epss 0.03

    Chromium: CVE-2021-30612 Use after free in WebRTC

  • CVE-2021-30611HigSep 3, 2021
    risk 0.57cvss 8.8epss 0.03

    Chromium: CVE-2021-30611 Use after free in WebRTC

  • CVE-2017-7000HigApr 3, 2018
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application…

  • CVE-2026-102317HigSep 29, 2026
    risk 0.56cvss 8.6epss 0.00

    Improper privilege management in Mojo in Google Chrome on on Windows prior to 154.0.8037.92 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)

  • CVE-2026-87633HigSep 9, 2026
    risk 0.56cvss 8.6epss 0.00

    Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)

  • CVE-2026-17699HigJul 30, 2026
    risk 0.56cvss 8.6epss 0.00

    Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

  • CVE-2026-13849HigJun 30, 2026
    risk 0.56cvss 8.6epss 0.00

    Insufficient validation of untrusted input in Chromoting in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

  • CVE-2026-95278HigSep 29, 2026
    risk 0.55cvss 8.4epss 0.00

    Missing authorization in WakeLock in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-76037HigAug 18, 2026
    risk 0.55cvss 8.4epss 0.00

    Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)

  • CVE-2026-17877HigJul 30, 2026
    risk 0.55cvss 8.4epss 0.00

    Inappropriate implementation in Chromoting in Google Chrome on Linux prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via malicious network traffic. (Chromium security severity: Medium)

  • CVE-2026-95381HigSep 29, 2026
    risk 0.54cvss 8.3epss 0.00

    Improper input validation in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-95351HigSep 29, 2026
    risk 0.54cvss 8.3epss 0.00

    Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-95348HigSep 29, 2026
    risk 0.54cvss 8.3epss 0.00

    Use after free in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-95341HigSep 29, 2026
    risk 0.54cvss 8.3epss 0.00

    Improper input validation in Desktop in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)

  • CVE-2026-95335HigSep 29, 2026
    risk 0.54cvss 8.3epss 0.00

    Use after free in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-95334HigSep 29, 2026
    risk 0.54cvss 8.3epss 0.00

    Incorrect reference resolution in WebProtect in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-95319HigSep 29, 2026
    risk 0.54cvss 8.3epss 0.00

    Use after free in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-95274HigSep 29, 2026
    risk 0.54cvss 8.3epss 0.00

    Improper output encoding in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-91743HigSep 15, 2026
    risk 0.54cvss 8.3epss 0.00

    Race condition in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-91735HigSep 15, 2026
    risk 0.54cvss 8.3epss 0.00

    Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Page 27 of 74