VYPR

Chromium

by Chromium

Source repositories

CVEs (1,466)

  • CVE-2017-5124MedFeb 7, 2018
    risk 0.43cvss 6.1epss 0.05

    Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted MHTML page.

  • CVE-2026-102330MedSep 29, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in SiteIsolation in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-102320MedSep 29, 2026
    risk 0.42cvss 6.5epss 0.00

    Missing authorization in CORS in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-102310MedSep 29, 2026
    risk 0.42cvss 6.5epss 0.00

    Missing authorization in Payments in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-95382MedSep 29, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper input validation in Auth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-95374MedSep 29, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in Network in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-95366MedSep 29, 2026
    risk 0.42cvss 6.5epss 0.00

    Use of released resource in Core in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-95330MedSep 29, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper state validation in Downloads in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-95327MedSep 29, 2026
    risk 0.42cvss 6.5epss 0.00

    Information leak in Networking in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-95297MedSep 29, 2026
    risk 0.42cvss 6.5epss 0.00

    Missing authorization in Contextual Tasks in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-95275MedSep 29, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect reference resolution in MediaStream in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87629MedSep 9, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in Sources in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-87626MedSep 9, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in DeviceBoundSessionCredentials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via crafted network traffic. (Chromium security severity: Medium)

  • CVE-2026-87623MedSep 9, 2026
    risk 0.42cvss 6.5epss 0.00

    Observable discrepancy in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87610MedSep 9, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in Omnibox in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87603MedSep 9, 2026
    risk 0.42cvss 6.5epss 0.00

    Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87591MedSep 9, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)

  • CVE-2026-87584MedSep 9, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87580MedSep 9, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in WebAppInstalls in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87549MedSep 9, 2026
    risk 0.42cvss 6.5epss 0.00

    Incomplete cleanup in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

Page 40 of 74