VYPR

Chromium

by Chromium

Source repositories

CVEs (1,470)

  • CVE-2026-79093MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Paint in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-79085MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79084MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Inadequate encryption strength in Notifications in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79077MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-79070MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect reference resolution in Cache in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79067MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79051MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Loader in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79050MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79049MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect reference resolution in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted file. (Chromium security severity: Medium)

  • CVE-2026-79016MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Observable discrepancy in SVG in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79014MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Race condition in Autofill in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-79010MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Operation on a resource after expiration or release in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79006MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Protection mechanism failure in HttpsUpgrades in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via crafted network traffic. (Chromium security severity: Medium)

  • CVE-2026-79003MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Device in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78987MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Information leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78980MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Improper input validation in ReaderMode in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-78976MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Improper input validation in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78966MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Externally controlled reference in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78961MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78954MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)

Page 59 of 74