By vendor
Apple vulnerabilities
Known CVEs affecting Apple products, prioritized by severity, with SEC.co remediation and detection guidance.
712 published vulnerabilities · page 5 of 8
- CVE-2026-11089MEDIUM 6.5
Google Chrome versions before 149.0.7827.53 contain a memory disclosure vulnerability in its media handling code. If an attacker gains control of Chrome's renderer process—the component responsible for displaying web content—they can craft a malicious HTML page to read uninitialized data from memory, potentially exposing sensitive information like passwords, encryption keys, or other confidential data. The vulnerability requires a prior compromise of the renderer, meaning it's typically chained with another exploit to be effective in the wild.
- CVE-2026-11090MEDIUM 6.5
Google Chrome versions before 149.0.7827.53 contain a flaw in the ANGLE graphics library that can be exploited to leak data across website boundaries. An attacker could craft a malicious webpage that, when visited, causes Chrome to inadvertently expose sensitive information from other origins a user has open. This requires user interaction (visiting the malicious page) but does not require special privileges. The vulnerability affects Windows, macOS, and Linux systems running vulnerable Chrome versions.
- CVE-2026-11093MEDIUM 6.5
Google Chrome versions before 149.0.7827.53 contain a flaw in how the browser handles printing functionality that could allow an attacker who has already compromised Chrome's rendering engine to steal sensitive data from websites the user visits. The attacker would need to trick the user into visiting a malicious webpage after gaining control of the renderer process. This is a medium-severity issue because it requires an intermediate compromise and user interaction, but the potential for cross-origin data leakage makes it worth prompt attention.
- CVE-2026-11096MEDIUM 6.5
A memory reading flaw in Chrome's WebRTC component allows attackers to trick users into visiting a malicious webpage that steals sensitive data from the browser's memory. The vulnerability requires user interaction (clicking a link or visiting a site) but needs no special privileges, making it a practical attack vector for information theft. Google patched this in Chrome version 149.0.7827.53 and later.
- CVE-2026-11104MEDIUM 6.5
CVE-2026-11104 is a memory information disclosure flaw in ANGLE, a graphics abstraction library used by Google Chrome. An attacker who has already compromised Chrome's renderer process can craft a malicious HTML page to read uninitialized memory and leak sensitive data. This is not a trivial attack—it requires the renderer to be compromised first—but once that foothold exists, the vulnerability can amplify the damage by exposing additional secrets from the browser process. Chrome versions before 149.0.7827.53 are vulnerable.
- CVE-2026-11105MEDIUM 6.5
A flaw in Google Chrome's WebUI component fails to properly validate user-supplied input, allowing an attacker who has already compromised Chrome's renderer process to trick the browser into leaking sensitive data from other websites. The vulnerability requires the renderer to be compromised first, which significantly limits the attack surface. Chrome versions before 149.0.7827.53 are affected.
- CVE-2026-11106MEDIUM 6.5
A flaw in Google Chrome's media handling allows attackers to trick users into visiting a malicious web page that can steal private data from other websites the user has visited. The vulnerability requires user interaction—someone must click a link or visit the crafted page—but once they do, an attacker can bypass Chrome's normal security boundaries that keep websites isolated from each other. This affects Chrome on Windows, macOS, and Linux systems.
- CVE-2026-11109MEDIUM 6.5
A vulnerability in the ANGLE graphics library used by Google Chrome can leak sensitive data from websites you're viewing to an attacker. An attacker would need to trick you into visiting a specially crafted webpage, but requires no special browser extensions or user interaction beyond visiting the page. The vulnerability affects Chrome versions prior to 149.0.7827.53 on Windows, macOS, and Linux systems.
- CVE-2026-11110MEDIUM 6.5
A flaw in Google Chrome's graphics rendering engine (ANGLE) can leak sensitive data from websites you visit to attackers. The vulnerability exists in Chrome versions before 149.0.7827.53 and requires a user to click on or interact with a malicious webpage. When exploited, it exposes confidential information that should remain isolated between different websites.
- CVE-2026-11121MEDIUM 6.5
CVE-2026-11121 is a medium-severity vulnerability in Skia, the graphics rendering engine used by Google Chrome. The flaw involves improper validation of untrusted input that could allow an attacker who has already compromised the browser's renderer process to extract sensitive data across origin boundaries using a specially crafted web page. This is not an initial entry point into systems, but rather a post-compromise escalation vector that broadens the damage an attacker can do once inside the browser process.
- CVE-2026-11123MEDIUM 6.5
A flaw in ANGLE (the graphics abstraction layer used by Google Chrome) allows attackers to trick users into visiting a malicious website that reads sensitive information directly from Chrome's memory. The vulnerability was patched in Chrome version 149.0.7827.53. Because it requires user interaction (clicking a link or visiting a page), it's less critical than remotely exploitable flaws, but the memory disclosure risk—potentially exposing authentication tokens, cached data, or other secrets—warrants prompt patching.
- CVE-2026-11128MEDIUM 6.5
Google Chrome versions before 149.0.7827.53 contain a flaw in the Web Share feature that allows attackers to steal data from other websites. The vulnerability requires tricking a user into clicking or interacting with elements on a malicious webpage. Once triggered, an attacker can access information from cross-origin sources—essentially reading data they shouldn't have access to. This is a client-side issue affecting individual users rather than servers, and the bar for exploitation is user interaction on a crafted page.
- CVE-2026-11129MEDIUM 6.5
Google Chrome versions before 149.0.7827.53 contain a flaw in how the browser handles extensions that could allow an attacker to steal sensitive data from websites you visit. An attacker would need to trick you into visiting a malicious webpage, but if successful, they could read information from other sites you have open—potentially including login credentials, private messages, or financial data. This is a medium-severity issue that affects Chrome on Windows, macOS, and Linux.
- CVE-2026-11132MEDIUM 6.5
A flaw in Chrome's Paint component allows attackers to bypass the same-origin policy—a fundamental browser security boundary—by tricking users into visiting a malicious webpage. The vulnerability affects Chrome versions before 149.0.7827.53. While an attacker cannot steal data directly through this weakness, they can modify or inject content in ways the browser should have blocked, potentially enabling follow-up attacks that compromise user sessions or inject malware. The flaw requires user interaction (visiting a crafted page) but is otherwise straightforward to exploit.
- CVE-2026-11133MEDIUM 6.5
A vulnerability in Google Chrome's Paint feature allows attackers to bypass the same-origin policy—a critical browser security boundary—through a specially crafted web page. An attacker could trick a user into visiting a malicious site and potentially access or modify content from another origin without permission. The vulnerability requires user interaction (clicking a link or visiting a page) but does not require special privileges. Chrome versions before 149.0.7827.53 are affected.
- CVE-2026-11134MEDIUM 6.5
Google Chrome versions before 149.0.7827.53 contain a flaw in how the Media component handles certain HTML content. An attacker can craft a malicious webpage that, when visited by a user, leaks sensitive data that should be restricted to one website (cross-origin data) to an attacker-controlled site. The vulnerability requires user interaction—the victim must visit the crafted page—but no special browser configuration or user privileges are needed. This is a confidentiality risk, not a data destruction or service disruption issue.
- CVE-2026-11135MEDIUM 6.5
Google Chrome's Autofill feature fails to properly enforce security policies, allowing attackers to trick users into bypassing security controls through specially crafted web pages. An attacker cannot steal data directly, but can manipulate what gets filled into form fields—potentially leading users to submit sensitive information to the wrong destination or trigger unintended actions. The vulnerability requires user interaction (clicking or interacting with the page) and affects Chrome versions before 149.0.7827.53.
- CVE-2026-11137MEDIUM 6.5
CVE-2026-11137 is a memory disclosure vulnerability in ANGLE, the graphics abstraction layer used by Google Chrome. A remote attacker can trick a user into visiting a specially crafted webpage that reads uninitialized memory from the Chrome process, potentially exposing sensitive data like passwords, tokens, or other information temporarily stored in RAM. The attack requires user interaction (clicking a link or visiting a malicious site) but no special privileges. This affects Chrome versions prior to 149.0.7827.53 across Windows, macOS, and Linux.
- CVE-2026-11138MEDIUM 6.5
A memory initialization flaw in Google Chrome's ANGLE graphics component allows attackers to expose sensitive data across different websites when users visit a malicious webpage. An attacker would need to craft a specially designed HTML page and trick a user into viewing it; the vulnerability itself requires no special browser configuration and affects all major operating systems where Chrome runs.
- CVE-2026-11139MEDIUM 6.5
A flaw in Google Chrome's Paint implementation allows attackers to steal sensitive information from one website and expose it to another. An attacker can craft a specially designed web page that, when visited by a user, exploits this vulnerability to read data across security boundaries that browsers normally enforce. The vulnerability affects Chrome versions before 149.0.7827.53 and requires user interaction—the victim must visit the malicious page—but does not require special permissions or system access.
- CVE-2026-11140MEDIUM 6.5
A memory reading vulnerability in Google Chrome's Chromecast feature allows an attacker who has already compromised the browser's renderer process to steal sensitive data from the browser's memory by serving a specially crafted web page. The vulnerability requires the attacker to have control of the renderer—the component that displays websites—but once achieved, they can extract information without needing special privileges or modifying the page's normal function.
- CVE-2026-11141MEDIUM 6.5
Google Chrome versions before 149.0.7827.53 contain a flaw in the audio subsystem that can leak sensitive data from memory. An attacker who has already compromised the renderer process—the component that executes web content—can craft a malicious HTML page to read uninitialized memory and extract potentially confidential information. This requires an existing foothold in the renderer, making it a secondary-stage exploitation technique rather than a direct entry vector.
- CVE-2026-11142MEDIUM 6.5
A flaw in Google Chrome's Paint feature prior to version 149.0.7827.53 allows attackers to bypass the browser's same-origin policy through a maliciously crafted webpage. An attacker could trick a user into visiting their page and potentially access or manipulate content that should be isolated from other websites. The vulnerability requires user interaction but poses a meaningful integrity risk to web security boundaries.
- CVE-2026-11168MEDIUM 6.5
A vulnerability in Google Chrome's extension system allows an attacker who has already compromised the browser's renderer process to extract sensitive data from memory using a specially crafted webpage. The vulnerability requires the attacker to have control over the renderer process first, which limits the immediate attack surface but poses significant risk if combined with other exploits. The issue stems from improper implementation in how extensions interact with the rendering engine.
- CVE-2026-11176MEDIUM 6.5
Google Chrome versions before 149.0.7827.53 contain a flaw in how the browser handles media content that could allow an attacker to trick a user into visiting a malicious webpage and steal sensitive data from other websites the user is logged into. The attacker cannot exploit this remotely without user interaction—the victim must visit the crafted page—but once there, the browser's media handling could be bypassed to reveal cross-origin information that should remain private.
- CVE-2026-11180MEDIUM 6.5
Google Chrome versions before 149.0.7827.53 contain a flaw in how SVG (Scalable Vector Graphics) content is handled that could allow an attacker to steal data from other websites. An attacker would need to trick a user into visiting a malicious webpage, but does not require any special browser plugins or user permissions beyond normal browsing. The vulnerability affects Chrome on Windows, macOS, and Linux.
- CVE-2026-11182MEDIUM 6.5
Google Chrome contains a vulnerability in how it processes SVG (Scalable Vector Graphics) content that could allow an attacker to steal sensitive data from websites you visit. An attacker would need to trick you into visiting a malicious webpage, but if successful, they could potentially read information that should be protected between different websites—such as authentication tokens, account details, or other private data. The vulnerability affects Chrome versions before 149.0.7827.53.
- CVE-2026-11183MEDIUM 6.5
CVE-2026-11183 is a memory safety vulnerability in Google Chrome's GWP-ASan security feature that allows an attacker with local access to read sensitive data from the browser's memory by tricking a user into opening a malicious file. While the flaw requires user interaction and doesn't allow remote code execution, it can expose confidential information such as cached credentials, session tokens, or other sensitive data held in process memory.
- CVE-2026-11189MEDIUM 6.5
A flaw in Google Chrome's developer tools allowed attackers to bypass navigation restrictions through malicious browser extensions. If a user installed a crafted extension, an attacker could manipulate Chrome's navigation controls to reach restricted pages or resources. The vulnerability requires user action—specifically, convincing someone to install the malicious extension—but once installed, no additional user interaction is needed for the bypass itself.
- CVE-2026-11190MEDIUM 6.5
Google Chrome versions before 149.0.7827.53 contain a flaw in how it handles browser extensions. An attacker could create a malicious extension that, if installed by a user, bypasses Chrome's access control protections. This means the extension could perform actions it should not be permitted to do—such as accessing restricted resources or modifying system behavior—without proper authorization checks. The attack requires user action to install the extension, but once installed, the damage is contained to what the extension itself can access rather than affecting the entire system.
- CVE-2026-11193MEDIUM 6.5
Google Chrome's Password Manager contained a flaw that failed to properly enforce access controls, allowing an attacker to bypass security restrictions through a malicious webpage. An attacker could craft a specially designed HTML page that, when visited by a user, circumvents the protections meant to prevent unauthorized access to password management features. This requires user interaction—the victim must visit the attacker's page—but no special privileges are needed on the attacker's side. The vulnerability does not lead to data theft or system crashes, but rather prevents the password manager from properly enforcing who can access its functions.
- CVE-2026-11194MEDIUM 6.5
A vulnerability in Google Chrome's network implementation could allow an attacker to trick users into visiting a specially crafted webpage that leaks sensitive data from other websites the user is logged into. The attack requires user interaction (clicking or visiting the malicious page) but does not require special browser configuration or user privileges. While the confidentiality impact is high, the vulnerability does not allow attackers to modify data or disable services.
- CVE-2026-11195MEDIUM 6.5
Google Chrome versions before 149.0.7827.53 contain a flaw in how the browser handles MHTML (MIME Encapsulation of Aggregate HTML Documents) content. An attacker can craft a malicious web page that, when visited by a user who performs specific interactions with the page (such as clicking or other UI gestures), leaks sensitive data from websites the user has visited in other browser tabs or windows. The vulnerability requires user interaction to trigger and does not allow attackers to modify data or crash the browser, but it does enable unauthorized access to cross-origin information that should remain private.
- CVE-2026-11196MEDIUM 6.5
Google Chrome versions before 149.0.7827.53 contain a type confusion bug in XML processing that allows an attacker to craft a malicious XML file. When a user opens this file in Chrome, the vulnerability can leak sensitive data from the browser's memory without requiring special user permissions or network-level access. The flaw affects Windows, macOS, and Linux users. While the attack requires user interaction (opening a file), the potential exposure of process memory makes this a notable security concern for organizations where users handle untrusted documents.
- CVE-2026-11197MEDIUM 6.5
Google Chrome versions prior to 149.0.7827.53 contain a flaw in how Worker threads enforce same-origin policy. An attacker who has already compromised your browser's rendering engine can craft a malicious webpage to trick the Worker into allowing cross-origin requests it should block. This is a post-compromise scenario—the attacker must first gain control of the renderer process—but once inside, they can escalate their privileges by accessing data from other websites.
- CVE-2026-11200MEDIUM 6.5
A flaw in Google Chrome's WebRTC implementation allows attackers to steal private data from other websites through a malicious HTML page. An attacker would need to trick a user into visiting their crafted webpage while Chrome is running, but no special technical privileges are required. The vulnerability affects Chrome versions before 149.0.7827.53 across Windows, macOS, and Linux.
- CVE-2026-11203MEDIUM 6.5
Google Chrome on macOS has a flaw in how it handles GPU-related processes that could allow an attacker to steal sensitive data from websites you visit. The vulnerability requires user interaction—you would need to visit a malicious or compromised website—but once there, an attacker could potentially access information from other sites you have open in the browser. Google has patched this in Chrome version 149.0.7827.53 and later.
- CVE-2026-11204MEDIUM 6.5
A flaw in Google Chrome's sign-in implementation on iOS allows an attacker to bypass navigation restrictions by directing a user to a specially crafted webpage. The vulnerability requires user interaction—specifically visiting a malicious page—but does not require elevated permissions. While the attacker cannot read sensitive data or crash the application, they can manipulate the browser's navigation behavior in ways the user did not intend.
- CVE-2026-11206MEDIUM 6.5
A vulnerability in Google Chrome's Service Worker implementation allows attackers to access sensitive data from websites you visit, even data that should be restricted to specific origins. An attacker can craft a malicious web page that, when visited, exploits insufficient policy checks to leak cross-origin information. This requires user interaction—you must visit the attacker's page—but once there, the browser's protections are bypassed without additional warnings or user awareness.
- CVE-2026-11208MEDIUM 6.5
A use-after-free vulnerability exists in the codec handling components of Google Chrome versions prior to 149.0.7827.53. An attacker can craft a malicious HTML page that, when visited by a user, exploits this memory safety flaw to read sensitive data directly from the browser process's memory. The vulnerability requires user interaction (visiting a malicious site) but does not require any special privileges to exploit.
- CVE-2026-11209MEDIUM 6.5
Google Chrome versions before 149.0.7827.53 contain a flaw in how it handles password data that could allow an attacker who has already compromised Chrome's renderer process to read sensitive information from memory using a specially crafted webpage. The vulnerability requires that the attacker first gain control of the renderer process—a significant precondition—but once achieved, could expose data stored in process memory without modifying or disabling system functions.
- CVE-2026-11210MEDIUM 6.5
Google Chrome versions before 149.0.7827.53 contain a flaw in Safe Browsing that allows attackers to bypass access controls when a user opens a specially crafted RAR archive file. An attacker would need to trick a user into opening a malicious RAR file, but once they do, the browser's safety mechanisms fail to properly restrict what the file can access. This is a moderate-severity issue that affects Chrome on Windows, macOS, and Linux.
- CVE-2026-11214MEDIUM 6.5
A flaw in Google Chrome for iOS allows attackers to trick users into visiting a malicious website that can leak data from other websites the user has open in their browser. The attacker needs the victim to interact with the malicious page (such as clicking a link), but no special technical skills or authentication are required on the attacker's side. This is a cross-origin data leak vulnerability affecting Chrome on iPhones and iPads running iOS.
- CVE-2026-11217MEDIUM 6.5
CVE-2026-11217 is a medium-severity flaw in Google Chrome's Fenced Frames feature that could allow an attacker who has already compromised a renderer process to circumvent Chrome's site isolation security boundary. Site isolation is a core defense that prevents malicious websites from accessing data from other sites in your browser. A remote attacker would need to trick a user into visiting a specially crafted webpage while the renderer has already been compromised, creating a two-stage attack scenario. Google has rated this as low severity on the Chromium scale, though the CVSS score reflects the integrity impact of bypassing site isolation.
- CVE-2026-11220MEDIUM 6.5
A flaw in Google Chrome's navigation handling prior to version 149.0.7827.53 allows a remote attacker who has already compromised the renderer process to bypass the browser's site isolation protection using a specially crafted HTML page. Site isolation is a critical Chrome security boundary designed to prevent malicious websites from accessing data from other sites. This vulnerability requires the attacker to have already gained code execution in the renderer process, making it a secondary or chained attack rather than a direct entry point.
- CVE-2026-11222MEDIUM 6.5
Google Chrome versions before 149.0.7827.53 contain a flaw in how the browser's tab strip displays security information to users. An attacker can craft a malicious webpage that tricks the browser's security UI, making it appear as though the user is visiting a legitimate website when they are actually on a attacker-controlled domain. This is a user-interface spoofing vulnerability that relies on tricking the visual indicators users depend on to verify they're on the correct website.
- CVE-2026-11223MEDIUM 6.5
A vulnerability in Google Chrome allows an attacker who has already compromised the browser's renderer process to bypass the same-origin policy—a fundamental security boundary that prevents malicious websites from accessing data belonging to other sites. The attacker would craft a specially designed HTML page to exploit insufficient input validation in Chrome's network handling. This requires the renderer process to be compromised first, making it a secondary attack that compounds an existing breach rather than a standalone entry point.
- CVE-2026-11225MEDIUM 6.5
Google Chrome before version 149.0.7827.53 contains a flaw that allows attackers to perform domain spoofing—making a malicious website appear to come from a trusted domain. An attacker would need to trick a user into visiting a crafted link, but once clicked, the browser's address bar or other visual indicators could misrepresent the true origin of the site. This affects Chrome on Windows, macOS, and Linux.
- CVE-2026-11227MEDIUM 6.5
Google Chrome versions before 149.0.7827.53 contain a flaw in how it displays security information in tab hover cards—the small popup that appears when you hover over a browser tab. An attacker can craft a deceptive domain name that, when displayed in this hover card, makes it appear to be a legitimate website you trust. This is a domain spoofing attack: the user sees what looks like one domain but is actually visiting a different one. The vulnerability requires user interaction (hovering over the tab and being deceived) but could help an attacker trick users into thinking they're on a safe site when they're not.
- CVE-2026-11258MEDIUM 6.5
Google Chrome versions before 149.0.7827.53 contain a flaw in how the browser handles file system access permissions. An attacker can craft a malicious webpage that, when visited, tricks users into performing specific clicks or gestures that bypass the browser's normal access controls. This allows the attacker to gain unauthorized access to files on the user's computer that would normally be protected. The vulnerability requires user interaction and social engineering to exploit, but once triggered, could expose sensitive files.
- CVE-2026-11271MEDIUM 6.5
Google Chrome versions before 149.0.7827.53 contain a flaw in password handling that could allow an attacker to trick users into revealing data from other websites. The vulnerability requires the attacker to craft a malicious webpage and convince the user to interact with it in a specific way—there is no automatic exploitation. The risk is confined to information disclosure; attackers cannot modify data or disrupt service. While the underlying Chromium project rates this as low severity, the CVSS score reflects the relatively low barrier to user interaction and the potential for cross-origin data leakage.
- CVE-2026-11283MEDIUM 6.5
Google Chrome on macOS contains a flaw in how it validates input when processing Shortcuts—a macOS feature that allows automation of tasks across applications. An attacker can craft a malicious file that, when opened by a user, bypasses Chrome's navigation restrictions, potentially redirecting the user to unintended web destinations. This requires user interaction (opening the file) but does not require special system privileges or network complexity. The vulnerability was patched in Chrome version 149.0.7827.53.
- CVE-2026-11284MEDIUM 6.5
Google Chrome versions prior to 149.0.7827.53 contain a side-channel vulnerability in the Performance APIs that allows an attacker to extract sensitive data across website boundaries. An attacker can craft a malicious webpage that, when visited by a user, leaks information from other websites the user is viewing or has visited. This works because certain performance measurement features can infer timing details that reveal cross-origin data, even though browsers are designed to isolate websites from each other.
- CVE-2026-11288MEDIUM 6.5
A vulnerability in Google Chrome's CSS handling allows an attacker to leak data from websites you visit to a different origin through a malicious webpage. The flaw stems from insufficient enforcement of browser security policies that normally prevent one website from accessing information from another. An attacker would need to trick you into visiting their crafted page while you're logged into or actively using other sites, but no special browser configuration or advanced user interaction is required beyond a standard click. This is a medium-severity issue affecting multiple operating systems through Chrome.
- CVE-2026-11289MEDIUM 6.5
A side-channel vulnerability in Google Chrome's Paint component allows attackers to leak sensitive cross-origin data through a specially crafted web page. An attacker would need to trick a user into visiting a malicious website, but once there, the vulnerability could expose information from other websites the user has open—a serious privacy breach. The issue affects Chrome versions before 149.0.7827.53 across Windows, macOS, and Linux.
- CVE-2026-11299MEDIUM 6.5
A flaw in how Google Chrome handles font data can lead to information disclosure when a user visits a malicious webpage. An attacker can craft a specially designed HTML page that exploits an integer overflow vulnerability in Chrome's font processing code, potentially allowing them to read sensitive data from the browser's memory. The vulnerability affects Chrome versions before 149.0.7827.53 and requires user interaction (visiting the malicious site) to trigger.
- CVE-2026-11653MEDIUM 6.5
Google Chrome versions before 149.0.7827.103 contain a flaw in how browser extensions are implemented that could allow an attacker to bypass site isolation—Chrome's core security mechanism that prevents websites from accessing each other's data. The attack requires two conditions: the attacker must first compromise Chrome's renderer process (the component that executes web pages), and then serve a specially crafted HTML page to the victim. While the technical barrier is high, successful exploitation would let malicious code access data across site boundaries, violating the security boundary that normally isolates sensitive information from different origins.
- CVE-2026-11658MEDIUM 6.5
A vulnerability in Google Chrome's extension validation system allows an attacker who has already compromised Chrome's renderer process to bypass site isolation—a critical security boundary that prevents malicious websites from accessing data across different sites. The flaw stems from insufficient checking of untrusted input in the Extensions subsystem. An attacker would need to trick a user into visiting a specially crafted HTML page while the renderer is already compromised, making this a secondary attack that compounds an existing breach rather than a standalone entry point.
- CVE-2026-12024MEDIUM 6.5
A flaw in Google Chrome's Developer Tools (DevTools) allows attackers to bypass the same-origin policy—a fundamental browser security boundary that prevents one website from accessing another's data. An attacker crafting a malicious HTML page could trick a user into visiting it, potentially gaining unauthorized access to sensitive information from other sites the user is logged into. The vulnerability affects Chrome versions before 149.0.7827.115 across Windows, macOS, and Linux.
- CVE-2026-12450MEDIUM 6.5
A flaw in Google Chrome's media handling allows attackers to extract sensitive information from your browser's memory through a specially crafted webpage. An attacker could trick you into visiting a malicious site and potentially access data that shouldn't be exposed—passwords, tokens, or other secrets processed by the browser. This requires user interaction (clicking or visiting the page) but no special permissions, making it a realistic threat for targeted attacks.
- CVE-2026-13022MEDIUM 6.5
Google Chrome versions prior to 149.0.7827.197 contain a flaw in the Autofill feature that allows an attacker with control of the browser's renderer process to extract sensitive data across website boundaries using a specially crafted web page. This is a moderate-severity issue that requires both the renderer process to be compromised and user interaction to exploit.
- CVE-2026-13793MEDIUM 6.5
Google Chrome versions before 150.0.7871.47 contain a flaw in how it enforces security policies for SVG (Scalable Vector Graphics) content. An attacker can craft a malicious web page that, when visited, leaks data from other websites the user has accessed or logged into. The attack requires user interaction—the victim must visit the attacker's page—but does not require special browser settings or privileges. This is a cross-origin data exposure vulnerability, meaning it breaks the browser's fundamental protection that prevents one website from accessing another's private information.
- CVE-2026-13795MEDIUM 6.5
A vulnerability in Google Chrome for iOS allows attackers to bypass browser navigation restrictions through a specially crafted webpage. An affected user would need to visit a malicious page, but once there, the attacker can force navigation to restricted destinations that the browser normally blocks. This affects Chrome on iOS up to version 149 and is resolved in version 150.0.7871.47 and later.
- CVE-2026-13809MEDIUM 6.5
A flaw in Google Chrome's Safe Browsing feature on iOS allows attackers who have already compromised Chrome's rendering process to steal sensitive data from other websites through a specially crafted web page. The vulnerability enables cross-origin information leakage—meaning an attacker could potentially access data that should be isolated between different websites. This requires the attacker to have already gained control of the renderer process, which limits the immediate threat scope but represents a serious escalation risk if other vulnerabilities are chained together.
- CVE-2026-13820MEDIUM 6.5
A flaw in Skia, Google Chrome's graphics library, allows an attacker who has already compromised Chrome's renderer process to read memory outside intended boundaries. By serving a specially crafted webpage, the attacker can extract sensitive information that crosses origin boundaries—data they should not have access to. This requires the attacker to first gain control of the renderer process, which typically happens when a user visits a malicious or compromised website. The vulnerability affects Chrome on macOS prior to version 150.0.7871.47.
- CVE-2026-13828MEDIUM 6.5
A flaw in Google Chrome's Enterprise implementation allows attackers to extract sensitive data from browser memory by tricking users into visiting a specially crafted webpage. The vulnerability requires user interaction (clicking a link or viewing a page) but does not require any special privileges. While the underlying browser processes are not compromised or harmed, the attacker gains unauthorized access to information that may be confidential. This affects Chrome versions prior to 150.0.7871.47 across Windows, macOS, and Linux systems.
- CVE-2026-13833MEDIUM 6.5
A memory initialization flaw in Chrome's graphics engine (ANGLE) on macOS allows attackers to steal sensitive data from websites you visit. An attacker hosting a malicious webpage can craft it to trigger the vulnerability when you visit—no special user interaction beyond normal browsing is required beyond clicking a link. The leaked data remains confined to your current browser session, but the confidentiality risk is material.
- CVE-2026-13847MEDIUM 6.5
Google Chrome for iOS contains a flaw in how it validates user-supplied input when rendering web pages. An attacker can craft a malicious HTML page that, when viewed on an affected iOS device, leaks sensitive data from websites the user has visited or logged into—data that should be isolated between different web origins. The vulnerability affects Chrome versions prior to 150.0.7871.47 on iOS and requires user interaction (the user must visit the attacker's page), but once that happens, no additional steps are needed to compromise cross-origin data.
- CVE-2026-13862MEDIUM 6.5
Google Chrome on iOS has a flaw in how it enforces security policies for Web Authentication features like passkeys and security keys. An attacker positioned on the same network as a victim could craft a malicious webpage that tricks the browser into leaking sensitive data from other websites the user has visited. The issue requires the attacker to be on a privileged network position and requires user interaction to click on a malicious link, but if successful can expose confidential information across website boundaries.
- CVE-2026-13873MEDIUM 6.5
A memory reading flaw in Google Chrome's Layout component allows attackers to trick users into visiting a malicious webpage that reads sensitive data from the browser process. The attacker gains no ability to modify data or crash the system, but can potentially expose information that should remain private. This affects Chrome versions before 150.0.7871.47 across Windows, macOS, and Linux systems.
- CVE-2026-13879MEDIUM 6.5
Google Chrome contains a use-after-free memory vulnerability in its Bluetooth implementation that allows attackers on the same local network to extract sensitive data from the browser's memory by using a specially crafted Bluetooth device. This occurs before Chrome version 150.0.7871.47. The vulnerability is rated Medium severity and does not affect system stability or enable attackers to modify data, but it does create a risk of information disclosure from process memory.
- CVE-2026-13881MEDIUM 6.5
A flaw in how Google Chrome handles web app installations allows attackers to bypass the same-origin policy—a critical browser security boundary—by tricking users into visiting a malicious HTML page. The vulnerability affects Chrome versions before 150.0.7871.47 across Windows, macOS, and Linux. An attacker could craft a page that tricks Chrome into loading or interacting with resources from a different origin than the user expects, potentially enabling credential theft, session hijacking, or unauthorized data access.
- CVE-2026-13886MEDIUM 6.5
Google Chrome versions prior to 150.0.7871.47 contain a flaw in how Isolated Web Apps enforce content security policies. An attacker can craft a malicious HTML page that, when visited by a user, bypasses these protections—potentially allowing unauthorized modifications to web content or application behavior. The vulnerability requires user interaction (clicking a link or visiting a page) but does not require the victim to be logged in or have special privileges.
- CVE-2026-13889MEDIUM 6.5
A vulnerability in Google Chrome on iOS allows attackers to steal sensitive information across different websites through a specially crafted web page. The flaw exists in Chrome's WebAuthentication system and can leak data without requiring any user interaction beyond visiting a malicious page. This affects Chrome versions before 150.0.7871.47 on iOS devices.
- CVE-2026-13892MEDIUM 6.5
A flaw in Google Chrome for iOS versions before 150.0.7871.47 allows attackers to steal data from websites you visit while using another site, but only if they can trick you into performing specific gestures on their crafted webpage. The vulnerability does not let attackers modify data or crash your browser—it's limited to unauthorized viewing of cross-origin information.
- CVE-2026-13894MEDIUM 6.5
Google Chrome prior to version 150.0.7871.47 contains a policy enforcement gap that allows an attacker positioned on the same network to manipulate how the browser handles navigation. By serving a specially crafted HTML page, an attacker can circumvent restrictions designed to prevent users from accessing certain sites or resources. The vulnerability requires the attacker to be in a network position to intercept or serve malicious content, and the user must interact with the page (clicking a link or performing an action), but does not result in direct data theft or system access.
- CVE-2026-13896MEDIUM 6.5
Google Chrome versions prior to 150.0.7871.47 contain a flaw in the Glic component that allows attackers to bypass navigation restrictions—mechanisms that prevent unauthorized page transitions or frame navigation. An attacker who crafts a malicious HTML page and tricks a user into visiting it can circumvent these protections, potentially redirecting the user to unintended destinations or manipulating browser navigation in ways that violate security policies. The vulnerability requires user interaction (clicking a link or visiting a page) but needs no special privileges to exploit.
- CVE-2026-13904MEDIUM 6.5
Google Chrome on iOS has a flaw in its Safe Browsing feature that allows attackers to bypass navigation restrictions designed to protect users from malicious sites. An attacker could craft a malicious HTML page that, when visited, tricks Chrome's safety mechanisms into allowing navigation to a blocked site. The vulnerability requires user interaction—the user must visit the attacker's page—but does not require special system privileges or browser configuration.
- CVE-2026-13908MEDIUM 6.5
Google Chrome on iOS versions before 150.0.7871.47 contain a flaw in the Omnibox (address bar) that allows attackers to bypass navigation security controls. An attacker could trick a user into performing specific gestures—like taps or swipes—while serving malicious network traffic, enabling the browser to navigate to unintended destinations or bypass intended restrictions. The vulnerability requires user interaction and network-level attack capability, but succeeds against users who may not notice subtle UI manipulation.
- CVE-2026-13913MEDIUM 6.5
Google Chrome on iOS has a weakness in how it enforces security policies for the autofill feature. A remote attacker can craft a malicious web page that, if a user interacts with it in specific ways, could leak sensitive data across website boundaries that should normally be hidden from each other. The vulnerability affects Chrome versions prior to 150.0.7871.47 and requires user interaction to exploit.
- CVE-2026-13917MEDIUM 6.5
Google Chrome for iOS contains a validation flaw that allows attackers to bypass navigation restrictions through a specially crafted web page. The vulnerability requires a user to perform specific interactions with the browser UI, but does not require any special privileges or configuration. An attacker could potentially redirect users to unintended destinations or manipulate the browsing experience by circumventing Chrome's navigation safeguards.
- CVE-2026-14035MEDIUM 6.5
Google Chrome versions prior to 150.0.7871.47 contain a Bluetooth-related security flaw that allows an attacker to extract sensitive information from the browser's memory. An attacker would need to trick a user into visiting a malicious webpage; if successful, the attacker could read data that shouldn't be accessible, such as authentication tokens, session data, or other confidential information stored in memory. Chrome itself rates this as low severity, though the CVSS score reflects moderate risk due to the ease of exploitation and the sensitivity of potential data exposure.
- CVE-2026-14048MEDIUM 6.5
A use-after-free flaw in Google Chrome's Chromecast component allows an attacker positioned on the same local network to extract sensitive data from the browser's memory using a specially crafted malicious peripheral device. The vulnerability affects Chrome versions before 150.0.7871.47 across Windows, macOS, and Linux systems.
- CVE-2026-14051MEDIUM 6.5
A memory disclosure vulnerability exists in Google Chrome's GamepadAPI prior to version 150.0.7871.47. An attacker who has already compromised Chrome's renderer process can craft a malicious webpage to read uninitialized memory, potentially exposing sensitive data. The vulnerability requires user interaction (visiting a crafted page) and prior renderer compromise, making it a secondary risk in multi-stage attack chains rather than an entry vector.
- CVE-2026-14059MEDIUM 6.5
A security weakness in Google Chrome's Related-Website-Sets feature allows attackers to trick users into visiting a malicious webpage that can steal data from other websites the user is logged into. The vulnerability affects Chrome versions before 150.0.7871.47 and requires user interaction (clicking a link or visiting the malicious page). While the Chromium project rated this as low severity, the CVSS score reflects a medium-risk profile because of its potential to expose sensitive cross-origin information without the user's knowledge.
- CVE-2026-14061MEDIUM 6.5
A flaw in Google Chrome's Dawn graphics component allows attackers to trick users into visiting specially crafted web pages that can leak sensitive information from the browser's memory. The vulnerability requires user interaction—the victim must visit a malicious site—but once they do, attackers may be able to read data that should remain private, such as authentication tokens or other browser state. This affects Chrome versions before 150.0.7871.47 across Windows, macOS, and Linux systems.
- CVE-2026-14065MEDIUM 6.5
CVE-2026-14065 is a navigation-bypass vulnerability in Google Chrome versions before 150.0.7871.47. An attacker who has already compromised Chrome's renderer process (the component that executes web page content) can craft a malicious HTML page to circumvent built-in navigation security controls. While this requires prior renderer compromise, the impact allows unauthorized navigation to restricted destinations. The Chromium project rates this as low severity, though the CVSS score of 6.5 reflects the potential for integrity violation.
- CVE-2026-14069MEDIUM 6.5
An integer overflow vulnerability exists in the WebNN (Web Neural Network) component of Google Chrome versions before 150.0.7871.47. An attacker could craft a malicious HTML page that, when visited, exploits this flaw to read sensitive data from the browser's memory. The vulnerability requires user interaction (visiting a malicious site) but does not require any special privileges or system access.
- CVE-2026-14070MEDIUM 6.5
A memory safety vulnerability in Google Chrome's WebNN (Web Neural Network) component allows attackers to leak sensitive data from the browser's memory. An attacker can craft a malicious webpage that, when visited by a user, exploits an integer overflow to read unintended data from the running process. While Chrome classified this as low severity internally, the confidentiality impact warrants attention from a defense perspective.
- CVE-2026-14071MEDIUM 6.5
Google Chrome versions before 150.0.7871.47 contain a side-channel vulnerability in the WebAudio component that allows attackers to extract sensitive cross-origin data through a specially crafted webpage. An attacker would need to trick a user into visiting a malicious site, but once there, they could potentially read data from other websites the user has open—a serious breach of browser security boundaries. The vulnerability is rated MEDIUM severity due to its reliance on user interaction and limited scope of impact.
- CVE-2026-14074MEDIUM 6.5
A side-channel vulnerability in Google Chrome's WebAuthentication implementation on iOS allows an attacker to leak sensitive cross-origin data through a crafted web page. The flaw exists in Chrome versions before 150.0.7871.47 and requires user interaction to trigger. An attacker would craft a malicious HTML page that, when visited by a victim, exploits timing or behavioral differences in the WebAuthentication API to infer or extract data from other websites the user has authenticated to.
- CVE-2026-14081MEDIUM 6.5
Google Chrome versions before 150.0.7871.47 contain a flaw in DevTools policy enforcement that could allow an attacker to extract sensitive data from browser process memory. The vulnerability requires social engineering—convincing a user to install a malicious extension—but once installed, the extension can bypass DevTools restrictions to access confidential information. This is not a flaw users can trigger by visiting a website; it hinges on the user's decision to add untrusted code to their browser.
- CVE-2026-14098MEDIUM 6.5
A flaw in how Google Chrome handles CSS allows an attacker to craft a malicious webpage that can read data from websites on different domains—a cross-origin information leak. The vulnerability affects Chrome versions before 150.0.7871.47. While the attack requires user interaction (visiting the malicious page), the potential impact is significant: sensitive information from other websites could be exposed to the attacker. This is classified as a medium-severity issue, though Chromium's own assessment rated the underlying CSS implementation flaw as low severity.
- CVE-2026-14100MEDIUM 6.5
CVE-2026-14100 is a data leakage vulnerability in Google Chrome's NetworkCache component that allows attackers to extract sensitive information across website boundaries. An attacker crafts a malicious HTML page and tricks a user into visiting it; the flaw then permits unauthorized access to data that should remain isolated between different websites. While Google rates the underlying defect as low severity, the practical impact—cross-origin data exposure—warrants a medium CVSS score because it requires user interaction but reliably compromises confidentiality.
- CVE-2026-14125MEDIUM 6.5
A flaw in the ANGLE graphics library used by Google Chrome can leak sensitive data from a user's computer memory to an attacker through a malicious webpage. When a user visits a crafted HTML page, uninitialized memory containing potentially sensitive information becomes accessible, allowing the attacker to read data that should have been protected. The vulnerability requires user interaction—specifically visiting a malicious site—but no special privileges or complex setup are needed on the attacker's side.
- CVE-2026-14148MEDIUM 6.5
A type confusion flaw in Google Chrome's CSS handling allows a remote attacker to trick a user into visiting a malicious webpage and potentially read sensitive data from the browser's process memory. The vulnerability requires user interaction (clicking a link or visiting a page) but no special privileges. While Chromium rates the severity as low, the ability to leak memory contents elevates practical risk for targeted attacks.
- CVE-2026-28979MEDIUM 6.5
An out-of-bounds memory access vulnerability exists in Apple's Safari browser and related Apple operating systems. When a user visits a malicious website, the flaw can crash the affected application unexpectedly. The vulnerability stems from insufficient bounds checking when processing web content, allowing an attacker to read from or write to memory locations outside intended boundaries. No data theft or system compromise occurs; the impact is limited to denial of service through application crashes.
- CVE-2026-39872MEDIUM 6.5
CVE-2026-39872 is a memory handling flaw in Apple's Safari browser and related operating systems that can crash the application when processing malicious web content. An attacker would need to trick a user into visiting a crafted webpage, but no additional privileges or special conditions are required. The crash itself does not compromise data confidentiality or integrity—it simply denies availability of the browser temporarily. This is a moderate-severity issue affecting Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS.
- CVE-2026-43663MEDIUM 6.5
CVE-2026-43663 is a memory handling vulnerability affecting Safari and multiple Apple operating systems. When a user visits or interacts with a maliciously crafted website, the affected application can crash unexpectedly. While the crash itself prevents normal operation, the vulnerability does not enable attackers to steal data or take control of the device—it is primarily a denial-of-service issue triggered by user interaction with hostile web content.
- CVE-2026-43676MEDIUM 6.5
An out-of-bounds memory access flaw in Apple's Safari browser and related operating systems can cause unexpected crashes when users visit websites containing malicious content. The vulnerability affects Safari on Mac, iPhone, and iPad, as well as visionOS and watchOS. While the issue results in denial of service rather than data theft or system compromise, it degrades user experience and could be chained with other exploits in targeted attacks. Apple has patched the vulnerability across its ecosystem.