VYPR

Chromium

by Chromium

Source repositories

CVEs (1,132)

  • CVE-2026-12457MedJun 17, 2026
    risk 0.27cvss 4.2epss 0.00

    Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-12453MedJun 17, 2026
    risk 0.27cvss 4.2epss 0.00

    Insufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-9986MedMay 28, 2026
    risk 0.27cvss 4.2epss 0.00

    Insufficient validation of untrusted input in OptimizationGuide in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-9110MedMay 20, 2026
    risk 0.27cvss 4.2epss 0.00

    Inappropriate implementation in UI in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-8021MedMay 6, 2026
    risk 0.27cvss 4.2epss 0.00

    Script injection in UI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-7996MedMay 6, 2026
    risk 0.27cvss 4.2epss 0.00

    Insufficient validation of untrusted input in SSL in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-7993MedMay 6, 2026
    risk 0.27cvss 4.2epss 0.00

    Insufficient validation of untrusted input in Payments in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity:…

  • CVE-2026-7989MedMay 6, 2026
    risk 0.27cvss 4.2epss 0.00

    Insufficient data validation in DataTransfer in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-7964MedMay 6, 2026
    risk 0.27cvss 4.2epss 0.00

    Insufficient validation of untrusted input in FileSystem in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-7952MedMay 6, 2026
    risk 0.27cvss 4.2epss 0.00

    Insufficient policy enforcement in Extensions in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-7947MedMay 6, 2026
    risk 0.27cvss 4.2epss 0.00

    Insufficient validation of untrusted input in Network in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-7934MedMay 6, 2026
    risk 0.27cvss 4.2epss 0.00

    Insufficient validation of untrusted input in Popup Blocker in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-7912MedMay 6, 2026
    risk 0.27cvss 4.2epss 0.00

    Integer overflow in GPU in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-17902LowJul 30, 2026
    risk 0.23cvss 3.5epss 0.00

    Inappropriate implementation in Editing in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2025-13640LowDec 2, 2025
    risk 0.23cvss 3.5epss 0.00

    Inappropriate implementation in Passwords in Google Chrome prior to 143.0.7499.41 allowed a local attacker to bypass authentication via physical access to the device. (Chromium security severity: Low)

  • CVE-2026-19161LowAug 6, 2026
    risk 0.20cvss 3.1epss 0.00

    Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-19160LowAug 6, 2026
    risk 0.20cvss 3.1epss 0.00

    Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-18000LowJul 30, 2026
    risk 0.20cvss 3.1epss 0.00

    Insufficient policy enforcement in USB in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-17997LowJul 30, 2026
    risk 0.20cvss 3.1epss 0.00

    Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-17957LowJul 30, 2026
    risk 0.20cvss 3.1epss 0.00

    Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

Page 53 of 57