VYPR

Chromium

by Chromium

Source repositories

CVEs (1,466)

  • CVE-2026-95290MedSep 29, 2026
    risk 0.35cvss 5.4epss 0.00

    Missing authorization in NFC in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-95287MedSep 29, 2026
    risk 0.35cvss 5.4epss 0.00

    Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87655MedSep 9, 2026
    risk 0.35cvss 5.4epss 0.00

    Clickjacking in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87635MedSep 9, 2026
    risk 0.35cvss 5.4epss 0.00

    UI misrepresentation in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87615MedSep 9, 2026
    risk 0.35cvss 5.4epss 0.00

    Race condition in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87583MedSep 9, 2026
    risk 0.35cvss 5.4epss 0.00

    UI misrepresentation in Passwords in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-87540MedSep 9, 2026
    risk 0.35cvss 5.4epss 0.00

    Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87507MedSep 9, 2026
    risk 0.35cvss 5.4epss 0.00

    UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87501MedSep 9, 2026
    risk 0.35cvss 5.4epss 0.00

    UI misrepresentation in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87484MedSep 9, 2026
    risk 0.35cvss 5.4epss 0.00

    UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87445MedSep 9, 2026
    risk 0.35cvss 5.4epss 0.00

    UI misrepresentation in Session in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79283MedAug 25, 2026
    risk 0.35cvss 5.4epss 0.00

    UI misrepresentation in Geometry in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79250MedAug 25, 2026
    risk 0.35cvss 5.4epss 0.00

    UI misrepresentation in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79173MedAug 25, 2026
    risk 0.35cvss 5.4epss 0.00

    UI misrepresentation in WebAppInstalls in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78974MedAug 25, 2026
    risk 0.35cvss 5.4epss 0.00

    UI misrepresentation in Linux Toolkit Theming in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-78898MedAug 25, 2026
    risk 0.35cvss 5.4epss 0.00

    Incorrect authorization in Downloads in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-17812MedJul 30, 2026
    risk 0.35cvss 5.4epss 0.00

    Inappropriate implementation in DigitalCredentials in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-17728MedJul 30, 2026
    risk 0.35cvss 5.4epss 0.00

    Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-16415MedJul 21, 2026
    risk 0.35cvss 5.4epss 0.00

    Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-14142MedJun 30, 2026
    risk 0.35cvss 5.4epss 0.00

    Inappropriate implementation in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

Page 52 of 74