By weakness (CWE)

CWE-416: related vulnerabilities

CVEs classified under CWE-416. Understanding the weakness class helps prioritize systemic fixes over one-off patches.

286 published vulnerabilities · page 2 of 3

  • CVE-2026-9884HIGH 8.8

    A use-after-free vulnerability in Google Chrome on macOS allows an attacker to run malicious code on a victim's computer by tricking them into visiting a specially crafted website. The vulnerability affects Chrome versions before 148.0.7778.216 on Mac and requires user interaction (clicking a link or viewing a page) but no special privileges to exploit. Google has classified this as a critical security issue in the Chromium project.

  • CVE-2026-9887HIGH 8.8

    A memory safety bug in Google Chrome's proxy handling system allows an attacker to craft a malicious Proxy Auto-Config (PAC) script that, when processed by the browser, causes the application to reference memory that has already been freed. This use-after-free condition can be leveraged to execute arbitrary code on a user's system. The vulnerability requires user interaction—specifically, the victim must visit a website or be directed to load a PAC script—but no special privileges are needed from the attacker's perspective. Chrome versions prior to 148.0.7778.216 are affected.

  • CVE-2026-9897HIGH 8.8

    Google Chrome versions prior to 148.0.7778.216 contain a use-after-free vulnerability in the DOM (Document Object Model) that allows attackers to execute arbitrary code within the browser sandbox by tricking users into visiting a crafted webpage. This vulnerability requires user interaction but poses a high risk because successful exploitation grants code execution capabilities inside the sandboxed browser process.

  • CVE-2026-9923HIGH 8.8

    A use-after-free vulnerability exists in Skia, the graphics library used by Google Chrome. An attacker can exploit this flaw by hosting a specially crafted HTML page. If a user visits that page while running a vulnerable version of Chrome, the attacker may corrupt memory on the user's system, potentially leading to data theft, system compromise, or browser crashes. The vulnerability requires user interaction (visiting a malicious page) but no special privileges.

  • CVE-2026-9927HIGH 8.8

    A use-after-free vulnerability in ANGLE (the graphics translation layer used by Chrome) allows attackers to run malicious code within Chrome's sandbox by tricking users into visiting a specially crafted webpage. The vulnerability exists in Google Chrome versions prior to 148.0.7778.216 and affects Windows, macOS, and Linux systems. While sandboxed, successful exploitation could grant an attacker local execution capabilities on the victim's machine.

  • CVE-2026-9941HIGH 8.8

    A use-after-free flaw in Chrome's ANGLE graphics library allows attackers to run arbitrary code within Chrome's sandbox by serving a malicious HTML page. An attacker would need to trick a user into visiting a crafted website; no special privileges or system access are required. Chrome versions before 148.0.7778.216 are vulnerable.

  • CVE-2026-9945HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's media handling code on Windows systems. An attacker can craft a malicious HTML page that, when visited by a user, triggers the vulnerability to execute arbitrary code within Chrome's sandboxed environment. This requires user interaction (visiting a link or webpage) but no special privileges, making it a practical attack vector for compromised websites or phishing campaigns.

  • CVE-2026-9947HIGH 8.8

    A use-after-free memory vulnerability exists in Google Chrome's XML processing engine that allows an attacker to execute arbitrary code within Chrome's sandbox. An attacker can trigger this vulnerability by crafting a malicious HTML page and convincing a user to visit it. While the sandbox limits damage, successful exploitation could allow the attacker to steal sensitive data or escalate privileges. The vulnerability affects Chrome versions prior to 148.0.7778.216 on Windows, macOS, and Linux systems.

  • CVE-2026-9952HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's WebAudio component that allows attackers to execute arbitrary code within the Chrome sandbox by tricking users into visiting a malicious website. The vulnerability affects Chrome versions prior to 148.0.7778.216 and requires user interaction (clicking a link or visiting a page). While sandboxed, successful exploitation could allow an attacker to run code with the privileges of the Chrome process, potentially leading to data theft or system compromise.

  • CVE-2026-9957HIGH 8.8

    Google Chrome's PDF renderer contains a use-after-free vulnerability that allows attackers to run malicious code within Chrome's sandboxed PDF handling process. An attacker can exploit this by sending a specially crafted PDF file to a victim. If the victim opens the PDF in Chrome, the vulnerability triggers, potentially allowing the attacker to escape the sandbox and execute arbitrary code on the system. The vulnerability affects Chrome versions prior to 148.0.7778.216 and impacts users on Windows, macOS, and Linux.

  • CVE-2026-9958HIGH 8.8

    A use-after-free vulnerability in PDFium, the PDF rendering engine embedded in Google Chrome, allows attackers to corrupt heap memory when a victim opens a maliciously crafted PDF file. An attacker can trigger this flaw remotely simply by getting someone to view a rigged PDF—no special browser settings or plugins required. This can lead to information disclosure, data corruption, or arbitrary code execution depending on how an attacker chains the memory corruption with other techniques.

  • CVE-2026-9961HIGH 8.8

    A use-after-free memory vulnerability exists in Google Chrome's SurfaceCapture component that allows attackers to corrupt heap memory. An attacker can craft a malicious HTML page that, when visited by a user, triggers the flaw to potentially execute arbitrary code with the privileges of the Chrome process. The vulnerability requires user interaction (visiting a malicious site) but has high impact once triggered.

  • CVE-2026-9962HIGH 8.8

    A use-after-free memory vulnerability in Google Chrome's WebRTC component allows an attacker to execute arbitrary code within the browser's sandbox by tricking a user into visiting a specially crafted webpage. The attacker gains the ability to read sensitive data, modify information, or crash the browser without needing special privileges or authentication.

  • CVE-2026-9978HIGH 8.8

    A use-after-free flaw in Google Chrome's Glic component allows attackers to run arbitrary code within the browser's sandbox by tricking users into visiting a malicious webpage. The vulnerability affects Chrome versions prior to 148.0.7778.216 across Windows, macOS, and Linux. While the code execution is confined to the sandbox, successful exploitation could lead to data theft, credential compromise, or lateral movement depending on the attacker's objectives and the system's security posture.

  • CVE-2026-9984HIGH 8.8

    Google Chrome on Windows contains a use-after-free memory vulnerability in its UI layer that allows attackers to execute arbitrary code on affected systems. The flaw can be triggered by tricking a user into visiting a specially crafted webpage; no special privileges or system access is required from the attacker. This is a remote code execution risk that affects Chrome versions prior to 148.0.7778.216.

  • CVE-2026-9992HIGH 8.8

    Google Chrome versions prior to 148.0.7778.216 contain a use-after-free vulnerability in its Network component that allows attackers to execute arbitrary code within the browser's sandbox by tricking users into visiting a malicious website. The vulnerability requires user interaction (clicking a link or visiting a page) but no special privileges, making it a practical attack vector for widespread exploitation.

  • CVE-2026-9995HIGH 8.8

    Google Chrome contains a use-after-free memory vulnerability in its WebXR implementation that allows attackers to execute arbitrary code within the browser's sandbox. An attacker can craft a malicious HTML page that, when visited by a user, triggers this flaw to break out of memory protections and run code. This affects Chrome versions prior to 148.0.7778.216 on Windows, macOS, and Linux systems.

  • CVE-2026-45458HIGH 8.4

    A use-after-free memory vulnerability in Microsoft Office allows an unauthorized attacker to execute arbitrary code on a local system. The vulnerability affects multiple Office products and versions, including Office 2019, 2021, 2024, Microsoft 365 Apps, Word, and SharePoint Server. Exploitation requires local access but does not require user interaction or elevated privileges, making it a significant local privilege escalation and code execution risk.

  • CVE-2026-45461HIGH 8.4

    A use-after-free memory flaw in Microsoft Office could allow an attacker with local access to run malicious code on your system with the same privileges as the logged-in user. The vulnerability requires no special permissions or user interaction beyond having access to the machine, making it a serious risk in environments where multiple users or untrusted software might run on the same device.

  • CVE-2026-45472HIGH 8.4

    Microsoft Office contains a use-after-free memory vulnerability that allows an attacker with local access to execute arbitrary code without requiring special user privileges or interaction. This is a serious flaw because it affects multiple versions of Office across both subscription (Microsoft 365) and perpetual licensing models. The vulnerability stems from improper memory management when handling certain Office objects, creating a window where freed memory is accessed, potentially leading to full system compromise.

  • CVE-2026-45474HIGH 8.4

    A use-after-free vulnerability in Microsoft Office allows an attacker to execute arbitrary code on a local system without requiring user interaction or special privileges. This is a memory safety issue where the application references memory that has already been freed, potentially enabling complete system compromise through malicious Office documents or crafted input.

  • CVE-2026-46270HIGH 8.4

    A use-after-free vulnerability exists in the Linux kernel's RT9455 power supply driver. The bug stems from improper resource cleanup ordering during driver removal: an interrupt handler can fire after the power supply device has been deallocated but before the interrupt itself is disabled, causing the handler to reference freed memory. This can crash the system or corrupt kernel memory. The vulnerability can also manifest during driver initialization if an interrupt fires before the power supply is fully registered.

  • CVE-2026-46288HIGH 8.4

    CVE-2026-46288 is a use-after-free memory safety bug in the Linux kernel's device tree unit testing code. The vulnerability occurs because the code releases memory for a data structure but then continues to access that same memory through another variable pointing to the same location. This can lead to crashes, information disclosure, or potentially arbitrary code execution with local access. The issue is confined to kernel test infrastructure rather than production device tree handling, limiting its practical exposure, but it demonstrates a common class of memory management errors that merit fixing.

  • CVE-2026-10000HIGH 8.3

    A use-after-free memory vulnerability exists in Google Chrome's password management system on Windows. An attacker who has already compromised Chrome's renderer process (the sandboxed component that displays web pages) could exploit this flaw through a malicious HTML page to escape the sandbox and gain system-level access. This is a multi-stage attack: the attacker must first achieve renderer compromise, then leverage this vulnerability to break out of Chrome's security boundary.

  • CVE-2026-10001HIGH 8.3

    A use-after-free flaw in Chrome's PerformanceManager could let an attacker escape the browser sandbox if they've already compromised the rendering engine. The attack requires a specially crafted web page and user interaction, but success could grant full system access. This affects Chrome versions before 148.0.7778.216.

  • CVE-2026-10012HIGH 8.3

    A use-after-free flaw in Chrome's Skia graphics library allows an attacker who controls the browser's renderer process to escape the sandbox and execute arbitrary code on the underlying system. The attack requires a malicious HTML page and user interaction, but once the renderer is compromised, the vulnerability enables full system compromise. This is particularly dangerous because renderer exploits are common entry points; this flaw raises the stakes by providing a bridge from that compromised renderer to the host OS.

  • CVE-2026-10014HIGH 8.3

    A use-after-free memory flaw in Chrome's WebMIDI implementation on Android allows an attacker who has already compromised Chrome's renderer process to escape the sandbox through a specially crafted web page. This is a privilege escalation attack: the attacker must first breach the renderer sandbox, then exploit this vulnerability to break out and gain full device access.

  • CVE-2026-10884HIGH 8.3

    A use-after-free memory vulnerability exists in Google Chrome's Chromecast component that could allow an attacker to escape the browser's sandbox if the attacker has already compromised the renderer process. The vulnerability requires user interaction and specific browser conditions, but successful exploitation could grant an attacker unauthorized access to the host system. Google has assigned this a Critical severity rating within Chromium's threat model.

  • CVE-2026-10894HIGH 8.3

    A use-after-free flaw in Chrome's printing subsystem on Linux could allow an attacker who already controls the browser's renderer process to break out of Chrome's sandbox protections and gain full system access. The vulnerability is triggered by a specially crafted web page and affects Chrome versions before 149.0.7827.53. While this requires initial compromise of the renderer process, it represents a critical escalation path from web content to system privileges.

  • CVE-2026-10905HIGH 8.3

    A memory safety flaw in Google Chrome's network code allows an attacker who has already compromised the browser's renderer process to escape the sandbox and gain full system access. The vulnerability requires user interaction (opening a malicious HTML page) but poses significant risk because successful exploitation bypasses Chrome's core security boundary—the sandbox that isolates the browser from the operating system.

  • CVE-2026-10908HIGH 8.3

    A use-after-free vulnerability exists in Google Chrome's full-screen functionality on Windows systems. An attacker who has already compromised Chrome's rendering engine could exploit a specially crafted web page to escape the browser sandbox and execute arbitrary code with higher privileges. This requires the attacker to have initial renderer process access, but once achieved, the flaw could allow them to run code outside the sandbox protection layer.

  • CVE-2026-10909HIGH 8.3

    A use-after-free vulnerability in Google Chrome's Dawn graphics engine allows an attacker who has already compromised the browser's renderer process to escape the sandbox through a malicious webpage. This is a high-severity issue because it bridges two separate security boundaries—first gaining control within Chrome's renderer, then breaking out to execute arbitrary code on the underlying operating system.

  • CVE-2026-10915HIGH 8.3

    A use-after-free memory vulnerability exists in Google Chrome on iOS that allows an attacker who has already compromised the browser's renderer process to break out of the sandbox and gain deeper system access. The vulnerability requires the attacker to serve a specially crafted HTML page and involves a complex attack chain but poses severe risk because successful exploitation can lead to full compromise of the device. Chrome versions prior to 149.0.7827.53 on iOS are affected.

  • CVE-2026-10918HIGH 8.3

    A use-after-free vulnerability in Google Chrome's Viz component allows an attacker who has already compromised the browser's renderer process to potentially escape the sandbox and gain deeper system access. The attacker would need to trick a user into visiting a malicious webpage, but the actual exploitation requires prior renderer compromise, making this a multi-stage attack. While not currently known to be exploited in the wild, the vulnerability represents a meaningful privilege escalation path for sophisticated threat actors who have achieved initial browser process compromise.

  • CVE-2026-10919HIGH 8.3

    A use-after-free bug in Chrome's ANGLE graphics library before version 149.0.7827.53 allows an attacker who already controls the browser's rendering process to break out of the sandbox and gain full system access. The attacker must trick a user into visiting a malicious webpage, but once the renderer is compromised, this flaw provides a path to escape Chrome's isolation boundaries.

  • CVE-2026-10933HIGH 8.3

    A use-after-free vulnerability exists in Google Chrome's audio processing component on Windows systems. An attacker who has already compromised Chrome's renderer process could exploit this flaw through a specially crafted web page to escape the browser sandbox and gain higher privileges on the system. This requires an initial renderer compromise, but if successful, could lead to full system takeover.

  • CVE-2026-10934HIGH 8.3

    Google Chrome on Android contains a use-after-free vulnerability in its Autofill feature that could allow an attacker to escape the browser sandbox. The flaw requires an attacker to first compromise Chrome's renderer process—the component responsible for parsing and displaying web content—and then trick a user into visiting a malicious webpage. If successful, the attacker could break out of Chrome's security sandbox and gain broader access to the device. This vulnerability affects Chrome versions prior to 149.0.7827.53 on Android.

  • CVE-2026-10953HIGH 8.3

    A use-after-free vulnerability exists in Google Chrome for Android versions prior to 149.0.7827.53. An attacker who has already compromised Chrome's renderer process can exploit this flaw by crafting a malicious HTML page to break out of the browser sandbox and gain system-level access to the Android device. This is a post-compromise escalation risk rather than a direct entry point, but it significantly amplifies the impact of any renderer exploit.

  • CVE-2026-10961HIGH 8.3

    Chrome for iOS users running versions prior to 149.0.7827.53 face a critical sandbox escape vulnerability. A malicious website can exploit a use-after-free memory flaw to break out of Chrome's security sandbox if the attacker first compromises the renderer process—the component that handles webpage content. Once the sandbox is escaped, an attacker gains direct access to the device, potentially leading to theft of credentials, personal data, or malware installation. The vulnerability requires user interaction (visiting a crafted page) but is otherwise remotely exploitable.

  • CVE-2026-10967HIGH 8.3

    A use-after-free flaw exists in Chrome's SurfaceCapture feature on Android that allows an attacker to escape the browser sandbox. The vulnerability requires the attacker to first compromise Chrome's renderer process and then trick a user into visiting a malicious webpage. If successful, the attacker could break out of Chrome's security sandbox and gain elevated privileges on the device. This affects Chrome versions before 149.0.7827.53 on Android.

  • CVE-2026-11010HIGH 8.3

    A use-after-free memory safety bug in Chrome's WebShare feature on Android allows an attacker who has already compromised the browser's renderer process to escape the sandbox and gain elevated system privileges by tricking a user into visiting a malicious webpage. While the initial compromise requires the renderer to already be under attacker control, the sandbox escape represents a critical escalation path.

  • CVE-2026-11012HIGH 8.3

    A use-after-free vulnerability exists in Google Chrome's Serial API on Android devices running versions before 149.0.7827.53. An attacker who has already compromised Chrome's renderer process can exploit this flaw by serving a specially crafted HTML page to achieve a sandbox escape—breaking out of Chrome's security isolation layer. While the underlying Chromium issue is rated Medium severity by Google, the CVSS 3.1 score of 8.3 reflects the HIGH impact potential when combined with renderer compromise.

  • CVE-2026-11040HIGH 8.3

    A use-after-free flaw in Chrome's ANGLE graphics library allows attackers who have already compromised your browser's renderer process to escape the sandbox and gain full system access via a specially crafted webpage. Chrome versions before 149.0.7827.53 are vulnerable. The attack requires the renderer to be compromised first, but if successful, can completely undermine Chrome's security isolation.

  • CVE-2026-11631HIGH 8.3

    Google Chrome on Windows contains a use-after-free vulnerability in its Aura rendering subsystem that could allow an attacker to break out of the browser's sandbox. The flaw requires an attacker to first compromise the renderer process—typically through a separate vulnerability or exploit—and then use a malicious webpage to trigger memory corruption that escapes the sandbox. This is a post-exploitation technique rather than a direct entry point, but the consequence is severe: attackers could gain system-level access beyond Chrome's normal security boundaries.

  • CVE-2026-11635HIGH 8.3

    A use-after-free memory vulnerability exists in the Bluetooth component of Google Chrome on macOS. An attacker who already compromises a website's renderer process can exploit this flaw through a specially crafted HTML page to escape the browser sandbox and run code at system level. This is a chained attack—the initial compromise of the renderer process is prerequisite, but once achieved, the vulnerability enables full sandbox bypass with high impact.

  • CVE-2026-11642HIGH 8.3

    Google Chrome prior to version 149.0.7827.103 contains a use-after-free vulnerability in its web application handling that could allow a remote attacker to escape the browser's sandbox. The attack requires the attacker to first compromise the renderer process—a separate security boundary within Chrome—and then trick a user into visiting a malicious website. If successful, the attacker could potentially gain system-level access, though the vulnerability itself is triggered through browser interaction rather than automatic exploitation.

  • CVE-2026-11647HIGH 8.3

    A use-after-free memory vulnerability in Chrome's printing functionality on Android allows an attacker who has already compromised a renderer process to escape the sandbox and gain higher privileges. The attacker would need to trick a user into viewing a malicious HTML page, but the actual exploitation requires pre-existing renderer compromise, making this a high-severity but technically constrained attack chain.

  • CVE-2026-11652HIGH 8.3

    Google Chrome versions before 149.0.7827.103 contain a use-after-free vulnerability in its extension handling code that could allow an attacker to escape the browser sandbox. An attacker who has already compromised the Chrome renderer process—the isolated process that runs website code—could exploit this flaw by crafting a malicious HTML page to gain code execution outside the sandbox, potentially compromising the entire system. The vulnerability requires user interaction (such as visiting a malicious site) and a prior renderer compromise, making it a secondary exploitation vector rather than a direct entry point.

  • CVE-2026-11656HIGH 8.3

    A use-after-free vulnerability exists in Google Chrome's ServiceWorker component that could allow attackers to escape the browser sandbox if they can trick a user into installing a malicious Chrome extension. The vulnerability affects Chrome versions before 149.0.7827.103 and requires user interaction to install the extension, but successful exploitation would grant an attacker access to the underlying system beyond Chrome's normal security boundaries.

  • CVE-2026-11661HIGH 8.3

    A use-after-free flaw in Google Chrome's Views component on Windows allows a remote attacker to escape the browser's sandbox if the renderer process has already been compromised. The attacker would need to craft a malicious HTML page to trigger the vulnerability. This is a post-compromise escalation risk: while initial renderer compromise is required, successful exploitation grants code execution outside the sandbox, elevating the threat from contained to system-wide.

  • CVE-2026-11663HIGH 8.3

    A use-after-free memory flaw exists in Google Chrome's Skia rendering engine. If an attacker first compromises Chrome's renderer process—the sandboxed component responsible for drawing web content—they can craft a malicious HTML page to trigger the vulnerability and break out of the sandbox, gaining full system access. This is a post-compromise attack chain: the renderer must already be compromised, but once it is, the attacker bypasses Chrome's key security boundary.

  • CVE-2026-11679HIGH 8.3

    A use-after-free memory vulnerability exists in Google Chrome's codec handling on Windows systems. An attacker who has already compromised Chrome's renderer process—the sandboxed component that handles web content—could exploit this flaw via a malicious HTML page to break out of the sandbox and gain full system access. This requires the attacker to have already achieved renderer process compromise, making it a critical second-stage attack in a multi-stage exploitation chain.

  • CVE-2026-11692HIGH 8.3

    A use-after-free vulnerability in Chrome's Read Anything feature allows an attacker who has already compromised the browser's renderer process to escape the sandbox and gain elevated system privileges. The attacker needs a user to open a malicious HTML page, but once triggered, the flaw breaks Chrome's security isolation and can lead to full system compromise. Google Chrome versions prior to 149.0.7827.103 are affected across Windows, macOS, and Linux.

  • CVE-2026-11700HIGH 8.3

    A use-after-free flaw in Chrome's tracing component allows an attacker who has already compromised the renderer process to escape the browser sandbox through a specially crafted HTML page. While the attack requires the renderer to be compromised first, successful exploitation could give an attacker full system access beyond the browser's security boundaries.

  • CVE-2026-9877HIGH 8.3

    A use-after-free memory vulnerability in the ANGLE graphics library affects Google Chrome versions before 148.0.7778.216. An attacker who has already compromised Chrome's renderer process can exploit this flaw through a specially crafted HTML page to escape the browser sandbox and gain unauthorized system access. While the attack requires an existing foothold in the renderer, the critical severity designation reflects the severe consequences of a successful sandbox escape.

  • CVE-2026-9888HIGH 8.3

    A use-after-free vulnerability in Chrome's WebView component on Android allows an attacker with access to the renderer process to potentially escape the sandbox through a specially crafted web page. This is a serious flaw because the renderer is typically isolated for security; if that isolation fails, an attacker could gain deeper system access. The vulnerability affects Chrome versions prior to 148.0.7778.216.

  • CVE-2026-9890HIGH 8.3

    A use-after-free memory flaw exists in Google Chrome's Extended Reality (XR) implementation on Windows. An attacker who has already compromised Chrome's renderer process can exploit this defect through a malicious webpage to break out of the browser sandbox and gain system-level access. This is a privilege escalation attack that requires the renderer to be compromised first, making it part of a multi-stage exploitation chain.

  • CVE-2026-9893HIGH 8.3

    A use-after-free vulnerability exists in Google Chrome's Skia graphics library (versions before 148.0.7778.216). An attacker who has already compromised Chrome's renderer process can exploit this flaw through a specially crafted HTML page to escape the browser sandbox—potentially gaining full system access. While the attack requires an initial compromise of the renderer, the sandbox escape risk elevates this to a critical concern for organizations where Chrome is prevalent.

  • CVE-2026-9894HIGH 8.3

    Google Chrome versions before 148.0.7778.216 contain a use-after-free vulnerability in the GPU rendering process. An attacker who has already compromised Chrome's renderer process can exploit this flaw via a malicious HTML page to escape the browser's sandbox and gain broader system access. This is a post-compromise escalation risk, not a direct infection vector.

  • CVE-2026-9899HIGH 8.3

    A use-after-free memory defect in ANGLE (the graphics abstraction layer used by Chrome) can allow an attacker to escape Chrome's sandbox if they've already compromised the renderer process. The attack requires a specially crafted web page and user interaction, but successful exploitation could give an attacker full system access beyond Chrome's security boundaries.

  • CVE-2026-9902HIGH 8.3

    A use-after-free memory bug in Google Chrome's accessibility features could allow an attacker to escape the browser's sandbox if they first compromise the renderer process. The vulnerability affects Chrome versions before 148.0.7778.216 and requires the attacker to trick a user into visiting a crafted webpage. While the initial compromise of the renderer process is a significant prerequisite, successfully exploiting this flaw could grant an attacker system-level access beyond the browser's normal restrictions.

  • CVE-2026-9904HIGH 8.3

    A use-after-free memory vulnerability exists in ANGLE, the graphics abstraction layer used by Google Chrome. By delivering a specially crafted HTML page, a remote attacker could exploit this flaw to break out of Chrome's sandbox—the critical security boundary that isolates the browser process from the rest of your system. Successful exploitation allows the attacker to run arbitrary code with the privileges of your user account, potentially compromising your entire machine.

  • CVE-2026-9905HIGH 8.3

    A use-after-free vulnerability exists in Google Chrome's accessibility features on Windows. An attacker who has already compromised Chrome's renderer process can exploit this flaw through a specially crafted HTML page to break out of Chrome's sandbox and gain system-level access. This is a post-compromise risk: the attacker must first have control of the renderer, but if they do, this vulnerability provides a direct path to escape Chrome's security isolation and potentially take full control of your computer.

  • CVE-2026-9925HIGH 8.3

    A use-after-free flaw in ANGLE (the graphics abstraction layer used by Google Chrome) can allow an attacker to escape the browser sandbox if they first compromise the renderer process. The attacker would craft a malicious HTML page to trigger memory corruption that leads to code execution outside the sandbox boundary. This requires two conditions: initial renderer compromise and user interaction with the hostile page.

  • CVE-2026-9931HIGH 8.3

    A use-after-free memory flaw in Chrome's GPU component allows an attacker who has already compromised the browser's renderer process to break out of Chrome's sandbox and gain system-level access. The attacker would need to trick a user into visiting a malicious webpage while the renderer is already under attack. This is a post-compromise privilege escalation path rather than a direct remote attack vector.

  • CVE-2026-9932HIGH 8.3

    A use-after-free vulnerability exists in the ANGLE graphics library within Google Chrome on Windows. An attacker who has already compromised Chrome's renderer process can exploit this flaw via a specially crafted HTML page to break out of Chrome's sandbox and gain full system access. This is a chained attack: the initial compromise must occur first, but once inside the renderer, the attacker gains significant additional capabilities.

  • CVE-2026-9936HIGH 8.3

    A use-after-free vulnerability in Google Chrome's graphics rendering engine (GFX) affects Mac systems running versions prior to 148.0.7778.216. The flaw allows an attacker who has already compromised Chrome's renderer process to escape the browser sandbox through a malicious HTML page, potentially gaining access to the underlying operating system. This is a post-compromise attack requiring the renderer to already be under attacker control.

  • CVE-2026-9937HIGH 8.3

    A use-after-free flaw in Google Chrome's user interface on Windows allows an attacker who has already compromised Chrome's renderer process to escape the browser sandbox and gain system-level access. The attacker would need to craft a malicious HTML page to trigger the vulnerability. This is a critical privilege escalation path because sandbox escapes turn browser compromises into full system compromises.

  • CVE-2026-9946HIGH 8.3

    A use-after-free vulnerability in Google Chrome's ANGLE graphics library could allow an attacker who has already compromised the browser's renderer process to break out of Chrome's security sandbox and execute code with system-level privileges. The flaw affects Chrome versions before 148.0.7778.216 and requires user interaction—typically visiting a malicious website—to trigger the vulnerability chain.

  • CVE-2026-9948HIGH 8.3

    Google Chrome on macOS contains a use-after-free vulnerability in its Views component that could allow an attacker to escape the browser's sandbox. The attack requires two conditions: the attacker must first compromise Chrome's renderer process (the sandboxed component that executes web content), and the victim must interact with a specially crafted webpage. If successful, the attacker gains access beyond the sandbox, potentially compromising the entire system. This vulnerability affects Chrome versions prior to 148.0.7778.216 on macOS.

  • CVE-2026-9949HIGH 8.3

    A use-after-free memory vulnerability exists in Google Chrome's Core component on Windows that could allow an attacker to escape the browser's sandbox. The vulnerability requires the attacker to have already compromised Chrome's renderer process and trick a user into visiting a malicious webpage. If successfully exploited, an attacker could gain the same privileges as the Windows user running Chrome, potentially compromising the entire system.

  • CVE-2026-9951HIGH 8.3

    Google Chrome before version 148.0.7778.216 contains a use-after-free vulnerability in its user interface rendering engine. This flaw allows an attacker to craft a malicious HTML page that, when visited by a user, can trigger memory corruption. The vulnerability is particularly dangerous because it may enable attackers to break out of Chrome's sandbox—the security boundary that isolates the browser from the underlying operating system—potentially gaining direct access to system resources and user data. Exploitation requires user interaction (clicking or visiting a malicious site) and involves complex attack conditions, but the potential for sandbox escape elevates the risk significantly.

  • CVE-2026-9970HIGH 8.3

    A use-after-free memory vulnerability exists in Google Chrome's WebGL component that could allow an attacker to escape the browser sandbox. An attacker would first need to compromise Chrome's renderer process—typically through a separate exploit or social engineering—and then could use a specially crafted HTML page to gain unauthorized access outside the browser's security boundaries. This vulnerability affects Chrome versions before 148.0.7778.216 on Windows, macOS, and Linux systems.

  • CVE-2026-9988HIGH 8.3

    A use-after-free memory flaw in Chrome's WebRTC component on Linux could allow an attacker to escape the browser's security sandbox. By crafting a malicious webpage, an attacker who tricks a user into visiting it could potentially break out of Chrome's isolation protections and execute code with system-level privileges. This affects Chrome versions before 148.0.7778.216 on Linux systems.

  • CVE-2026-9993HIGH 8.3

    A use-after-free memory vulnerability exists in Google Chrome's rendering engine that allows an attacker to escape the browser's sandbox if they have already compromised the renderer process. The vulnerability is triggered when a user opens a malicious PDF file. This is a critical threat because it could allow an attacker who has gained code execution within the browser to break out of Chrome's security boundaries and gain access to the underlying operating system.

  • CVE-2026-9994HIGH 8.3

    A use-after-free vulnerability exists in Google Chrome's core rendering engine on Windows systems. An attacker who has already compromised the browser's renderer process can exploit this flaw through a specially crafted HTML page to escape the browser sandbox—breaking out of Chrome's security isolation layer. This means an attacker could potentially gain full system access from within the constrained renderer environment.

  • CVE-2026-9997HIGH 8.3

    Google Chrome versions prior to 148.0.7778.216 contain a use-after-free vulnerability in the Input component that could allow an attacker to escape the browser's sandbox. The attack requires the attacker to have already compromised Chrome's renderer process and trick a user into visiting a malicious HTML page. If successful, the attacker could break out of the sandbox and gain access to the underlying operating system.

  • CVE-2026-45476HIGH 8.2

    A use-after-free flaw in the Linux MANA network driver used by Microsoft Azure allows a user with high-level system privileges to escape their confined context and gain full control over the system. Because the vulnerability requires the attacker to already have elevated privileges, the immediate attack surface is limited to administrative users or services running with high permissions—but successful exploitation would allow them to achieve complete system compromise.

  • CVE-2026-10887HIGH 8.1

    A use-after-free flaw in Chrome's Chromoting remote desktop feature on macOS allows attackers to execute arbitrary code by sending specially crafted network traffic. The vulnerability exists in versions prior to 149.0.7827.53 and requires no user interaction—an attacker on the network can trigger the bug remotely, making this a critical threat to any Mac user running an affected Chrome version.

  • CVE-2026-11185HIGH 8.1

    A use-after-free flaw in the V8 JavaScript engine affects Google Chrome versions before 149.0.7827.53. The vulnerability requires an attacker to trick a user into installing a malicious Chrome extension, which can then execute arbitrary code within the browser's sandbox. While the Chromium project rated this as Medium severity, the CVSS score of 8.1 reflects the high potential impact on confidentiality and integrity. This is a memory safety issue that leverages social engineering to gain code execution capabilities.

  • CVE-2026-11224HIGH 8.1

    A use-after-free vulnerability in Google Chrome's Chromoting remote desktop feature on Linux systems can allow an attacker to execute arbitrary code on a victim's machine through specially crafted network traffic. The attacker does not need any special privileges or user interaction beyond network access. This is a critical flaw in the remote desktop protocol handling that leaves systems open to full code execution compromise.

  • CVE-2026-11643HIGH 8.1

    A use-after-free vulnerability exists in Google Chrome's Proxy component that could allow attackers to execute arbitrary code on victim machines through specially crafted network traffic. The flaw affects Chrome versions prior to 149.0.7827.103 and has been rated as Critical by the Chromium security team. While no active exploitation has been confirmed in the wild, the vulnerability's remote nature and code execution potential make it a significant threat requiring prompt patching.

  • CVE-2026-42987HIGH 8.1

    CVE-2026-42987 is a use-after-free memory vulnerability in Windows Deployment Services (WDS) that allows an attacker to execute arbitrary code on vulnerable servers over the network without authentication or user interaction. The vulnerability affects multiple Windows Server versions and has a CVSS score of 8.1 (HIGH severity), indicating a significant risk to organizations relying on WDS for operating system deployment.

  • CVE-2026-45599HIGH 8.1

    A use-after-free vulnerability in Windows UPnP (upnp.dll) allows an attacker to run unauthorized code on affected systems over the network without requiring user interaction or special privileges. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server, making it a broad concern for enterprises. While exploitation requires specific network conditions (reflected in the CVSS score of 8.1), successful attacks could lead to complete system compromise.

  • CVE-2026-45635HIGH 8.1

    A type confusion vulnerability in Windows' Universal Plug and Play (UPnP) component allows attackers to execute code remotely on affected systems without authentication. The flaw stems from improper handling of incompatible data types in upnp.dll, which can be exploited over a network to gain full system compromise. This affects a broad range of Windows versions from Windows 10 through Windows 11, as well as Windows Server deployments.

  • CVE-2026-9964HIGH 8.1

    CVE-2026-9964 is a memory safety vulnerability in Chrome's Bluetooth implementation on macOS that can allow attackers to run malicious code on a victim's computer. The attack requires two user actions: the victim must first install a malicious Chrome extension, and then interact with Bluetooth functionality in a way that triggers the underlying flaw. Once those conditions are met, the attacker can execute arbitrary code with the same privileges as the Chrome process.

  • CVE-2026-11072HIGH 7.8

    A use-after-free flaw in Chrome's WebView component on Android allows a local attacker to run malicious code if a user opens a specially crafted file. The attacker needs physical or local access to the device and requires user interaction (opening the file), but once triggered, can gain full control over the affected application's privileges and data.

  • CVE-2026-40290HIGH 7.8

    OP-TEE is a trusted execution environment that provides a secure processing space on Arm-based processors. A race condition in OP-TEE versions 3.16.0 through 4.10.x creates a use-after-free vulnerability in the shared memory management code. The vulnerability occurs when OP-TEE is configured to manage secure partitions (a specific operational mode). A local user could exploit this by timing concurrent operations on shared memory to cause the system to access memory that has already been freed, potentially compromising the confidentiality, integrity, or availability of the secure environment.

  • CVE-2026-42905HIGH 7.8

    A use-after-free vulnerability exists in Windows DWM (Desktop Window Manager) Core Library that allows an authorized user on a Windows system to execute code and take control of the machine. The flaw requires the attacker to already have a user account on the system; it cannot be exploited remotely. When successfully exploited, an attacker can gain the highest level of system access (SYSTEM privilege), enabling complete compromise of the device. This is a local privilege escalation vulnerability affecting multiple versions of Windows 10, Windows 11, and Windows Server.

  • CVE-2026-42978HIGH 7.8

    CVE-2026-42978 is a privilege escalation vulnerability in Windows Push Notifications that affects multiple versions of Windows 10, Windows 11, and Windows Server. An authenticated attacker with local access can exploit a race condition—a timing-based flaw where concurrent operations on a shared resource lack proper synchronization—to gain elevated system privileges. This is a local attack requiring an existing user account, but the consequences are severe: an attacker could gain administrative control of the affected system. The vulnerability is not currently being exploited in the wild according to public disclosures.

  • CVE-2026-42979HIGH 7.8

    A race condition in Windows Push Notifications allows an attacker who already has local access to a computer to gain higher-level privileges. The vulnerability exploits a timing gap in how the notification system handles shared resources, enabling privilege escalation. This is a local attack that requires an authorized user account to initiate, but could allow an attacker to break out of restricted accounts and gain administrative control.

  • CVE-2026-42983HIGH 7.8

    A use-after-free flaw exists in Windows Desktop Window Manager (DWM) Core Library that allows an attacker with local system access to escape their privilege level and gain full system control. The vulnerability requires the attacker to already have a foothold on the machine, but once exploited, it grants administrator-level access. This is a classic privilege escalation attack that becomes dangerous when combined with other attack chains—for instance, an attacker who gains initial access through a phishing email or vulnerable web browser can weaponize this flaw to lock down the system permanently.

  • CVE-2026-42986HIGH 7.8

    A use-after-free flaw in Microsoft's Graphics Component allows an authorized local user to escalate their privileges to a higher level of system access. The vulnerability requires the attacker to already have login credentials and local system access, but once exploited can lead to full control of the affected machine. This is a memory safety issue where freed memory is accessed, potentially allowing arbitrary code execution at elevated privilege levels.

  • CVE-2026-42991HIGH 7.8

    CVE-2026-42991 is a race condition in Windows Push Notifications that allows an authorized local user to escalate their privileges to a higher level of access. The vulnerability requires an attacker who already has login credentials and cannot be exploited remotely. It affects multiple versions of Windows 10, Windows 11, and Windows Server. While the barrier to exploitation is moderate due to timing constraints, the impact is severe—an attacker could gain system-level control.

  • CVE-2026-44802HIGH 7.8

    A memory safety flaw in the Windows Desktop Window Manager (DWM) Core Library allows a logged-in user to crash the system or potentially run code with elevated privileges. The vulnerability stems from use-after-free code—a situation where freed memory is accessed again—affecting multiple versions of Windows 10, Windows 11, and Windows Server. An attacker must already have a user account on the machine to exploit it, making this a local privilege escalation risk rather than a remote attack vector.

  • CVE-2026-44804HIGH 7.8

    A use-after-free flaw in Windows Desktop Window Manager (DWM) Core Library permits an authorized local user to escalate their privileges to a higher level of system access. The vulnerability requires legitimate account credentials and local system access but does not require user interaction. An attacker with such access could exploit this flaw to gain elevated permissions and control critical system functions.

  • CVE-2026-44807HIGH 7.8

    A use-after-free memory flaw exists in Windows DWM (Desktop Window Manager) Core Library that allows an authenticated local user to escalate their privileges. An attacker who already has user-level access to a system can exploit this to gain system or administrator-level control. The vulnerability requires local access and user interaction is not needed once an attacker is on the machine.

  • CVE-2026-44808HIGH 7.8

    A memory corruption flaw in Windows Desktop Window Manager (DWM) Core Library allows a user with local system access to escalate their privileges to a higher level of system access. The vulnerability stems from improper handling of memory buffers and requires an authenticated user to trigger, but does not require user interaction once triggered. This is a local privilege escalation vector that could allow an attacker with initial system access to gain administrative control.

  • CVE-2026-44809HIGH 7.8

    A use-after-free vulnerability exists in Windows' Common Log File System Driver that allows a user with local access to elevate their privileges to a higher level of system access. While the attacker must already have an account and authentication on the target system, the flaw enables them to break out of their current permission boundary and gain full control. This is a local privilege escalation (LPE) vulnerability affecting recent Windows 11 and Windows Server 2025 versions.

  • CVE-2026-44811HIGH 7.8

    A heap-based buffer overflow exists in Windows DWM (Desktop Window Manager) Core Library that allows a user already logged into a Windows 11 system to elevate their privileges to a higher level of access. An attacker with an existing local account would need to craft specific input or manipulate the DWM process to trigger the memory corruption, potentially gaining system-level permissions. This is a local-only vulnerability and does not enable remote compromise.