Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
43953
Total
3568
Critical
13190
High
12986
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-78966 | UNKNOWN | — | Externally controlled reference in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. … | Aug 25, 2026 |
| CVE-2026-78965 | UNKNOWN | — | Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security … | Aug 25, 2026 |
| CVE-2026-78964 | CRITICAL | 9.6 | Use after free in Sync in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the … | Aug 25, 2026 |
| CVE-2026-78963 | HIGH | 8.8 | Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a … | Aug 25, 2026 |
| CVE-2026-78962 | UNKNOWN | — | Uninitialized resource in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially leak cross-origin data via a crafted … | Aug 25, 2026 |
| CVE-2026-78961 | UNKNOWN | — | Incorrect authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to … | Aug 25, 2026 |
| CVE-2026-78960 | UNKNOWN | — | Information leak in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted Chrome … | Aug 25, 2026 |
| CVE-2026-78959 | UNKNOWN | — | Improper handling of case sensitivity in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions … | Aug 25, 2026 |
| CVE-2026-78958 | UNKNOWN | — | Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data … | Aug 25, 2026 |
| CVE-2026-78957 | UNKNOWN | — | Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensitive information via a crafted file. … | Aug 25, 2026 |
| CVE-2026-78956 | HIGH | 8.8 | Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via … | Aug 25, 2026 |
| CVE-2026-78955 | UNKNOWN | — | Observable discrepancy in PerformanceAPIs in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium … | Aug 25, 2026 |
| CVE-2026-78954 | UNKNOWN | — | Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy … | Aug 25, 2026 |
| CVE-2026-78953 | UNKNOWN | — | Missing authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via … | Aug 25, 2026 |
| CVE-2026-78952 | UNKNOWN | — | Out of bounds write in Crashpad in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process … | Aug 25, 2026 |
| CVE-2026-78951 | CRITICAL | 9.6 | Use after free in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted … | Aug 25, 2026 |
| CVE-2026-78950 | HIGH | 8.8 | Integer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted … | Aug 25, 2026 |
| CVE-2026-78949 | UNKNOWN | — | Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data via a co-installed app. … | Aug 25, 2026 |
| CVE-2026-78948 | CRITICAL | 9.6 | Buffer overflow in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML … | Aug 25, 2026 |
| CVE-2026-78947 | UNKNOWN | — | Incomplete cleanup in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted … | Aug 25, 2026 |
| CVE-2026-78946 | UNKNOWN | — | Incorrect authorization in Select in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium … | Aug 25, 2026 |
| CVE-2026-78945 | CRITICAL | 9.6 | Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the … | Aug 25, 2026 |
| CVE-2026-78944 | HIGH | 8.8 | Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox … | Aug 25, 2026 |
| CVE-2026-78943 | UNKNOWN | — | Improper input validation in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering … | Aug 25, 2026 |
| CVE-2026-78942 | UNKNOWN | — | Incorrect reference resolution in Loader in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via crafted network traffic. (Chromium … | Aug 25, 2026 |