By vendor

Apple vulnerabilities

Known CVEs affecting Apple products, prioritized by severity, with SEC.co remediation and detection guidance.

712 published vulnerabilities · page 7 of 8

  • CVE-2026-14153MEDIUM 5.3

    Google Chrome versions before 150.0.7871.47 contain a UI spoofing vulnerability in the Glic component. An attacker can craft a malicious HTML page that, when viewed by a user who performs specific UI gestures (like clicks or interactions), displays fake interface elements that deceive the user into believing they're interacting with legitimate browser controls or content. This is a social engineering attack that relies on user interaction but can expose sensitive information through misdirection.

  • CVE-2026-28898MEDIUM 5.3

    Swift-NIO-HTTP2, Apple's open-source networking library for HTTP/2 protocol handling, contains a validation gap in its HTTP/2-to-HTTP/1.1 converter. The library failed to check pseudo-header values (like :path, :authority, :scheme, :method, and :status) for control characters—specifically carriage return (CR), line feed (LF), and null (NUL) bytes—before translating HTTP/2 frames into HTTP/1.1 messages. An attacker could craft malicious HTTP/2 requests or responses containing these characters to bypass security controls or potentially inject unintended content into downstream systems that process the converted HTTP/1.1 messages. Version 1.44.1 and later reject such messages at the connection level.

  • CVE-2026-43704MEDIUM 5.3

    A memory management flaw in Apple's Safari browser and related operating systems could allow a malicious web extension to crash the browser or application unexpectedly. The vulnerability (CVE-2026-43704) stems from improper handling of memory after it has been freed, a class of bug that can be exploited by attackers who craft malicious extensions. Apple has patched the issue across Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS.

  • CVE-2026-11276MEDIUM 5.1

    Google Chrome versions before 149.0.7827.53 contain a flaw in how the Cast feature (which enables screen mirroring and media streaming to nearby devices) processes network traffic. An attacker physically present on the same local network can send specially crafted traffic to bypass access controls that would normally prevent unauthorized casting operations. This is a local network attack that doesn't require user interaction but is limited in scope—it cannot crash systems or execute arbitrary code, only manipulate casting permissions.

  • CVE-2026-9942MEDIUM 5.0

    CVE-2026-9942 is a memory safety issue in ANGLE, the graphics abstraction layer used by Google Chrome. When a remote attacker has already compromised Chrome's renderer process, they can exploit this uninitialized memory condition to break out of Chrome's site isolation sandbox using a specially crafted HTML page. Site isolation is Chrome's primary defense against cross-site data theft; bypassing it allows an attacker to read data from other websites the user is visiting. This requires the renderer process to be already compromised, meaning it is a post-compromise escalation rather than an entry point.

  • CVE-2026-9979MEDIUM 5.0

    CVE-2026-9979 is a site isolation bypass vulnerability in Google Chrome that allows an attacker to escape the security boundary between different websites if they have already compromised Chrome's rendering engine. An attacker would need to trick a user into visiting a malicious HTML page while the renderer process is already under their control. Site isolation is Chrome's core defense mechanism that prevents one website's scripts from accessing another website's data; this vulnerability undermines that protection in a limited but serious scenario.

  • CVE-2026-9980MEDIUM 5.0

    Google Chrome versions before 148.0.7778.216 contain a flaw in how it validates input when printing documents. An attacker who has already compromised Chrome's rendering engine can exploit this to bypass Site Isolation, a security boundary that separates data between websites. This requires both a prior compromise of the renderer process and user interaction, making it a secondary attack in a chain rather than a standalone entry point.

  • CVE-2026-14154MEDIUM 4.8

    CVE-2026-14154 is a UI spoofing vulnerability in Google Chrome's DevTools that requires an attacker to trick a user into installing a malicious extension. Once installed, the extension can display fake interface elements to deceive users, potentially leading to credential theft or social engineering attacks. While Google rates this as low severity, the attack chain depends on user action to install the extension, which limits but does not eliminate risk.

  • CVE-2026-34694MEDIUM 4.8

    Adobe Experience Manager Forms JEE contains a stored cross-site scripting (XSS) vulnerability in form fields that allows a high-privileged attacker to inject malicious JavaScript code. When other users visit a page containing the compromised form field, the malicious script executes in their browser, potentially compromising their session, credentials, or sensitive data. The vulnerability affects versions LTS SP1, 6.5.24.0 and earlier.

  • CVE-2026-11233MEDIUM 4.7

    CVE-2026-11233 is a same-origin policy bypass vulnerability in Google Chrome's FoldableAPIs feature. An attacker who has already gained control of Chrome's renderer process—the component that executes web page code—can use a specially crafted HTML page to break through Chrome's security boundary and access data from websites the user visits. This requires the attacker to have already compromised the renderer, making it a secondary exploit rather than a direct entry point. The vulnerability affects Chrome versions prior to 149.0.7827.53.

  • CVE-2026-11249MEDIUM 4.7

    Google Chrome versions before 149.0.7827.53 contain a use-after-free vulnerability in the Network component. If an attacker compromises Chrome's renderer process—the sandboxed part that runs web content—they could read sensitive data from the browser's memory using a specially crafted HTML page. This is a memory safety issue: the code attempts to access data after it has already been freed, potentially exposing unencrypted information that was in use moments before.

  • CVE-2026-13034MEDIUM 4.7

    Google Chrome versions before 149.0.7827.197 contain a flaw in how it handles passwords that allows an attacker who has already compromised Chrome's renderer process to break out of site isolation—Chrome's critical security boundary that prevents malicious websites from accessing data belonging to other websites. An attacker would need to trick a user into visiting a specially crafted webpage after first gaining control of the renderer, but if successful, could view sensitive information like passwords or cookies from other sites.

  • CVE-2026-13812MEDIUM 4.7

    A vulnerability in Google Chrome for iOS allows attackers to inject malicious scripts or HTML into web pages through specific user interactions. An attacker would need to convince a user to perform particular gestures on a crafted webpage to exploit this flaw. The vulnerability stems from insufficient validation of user-supplied input before processing it in the browser's rendering engine.

  • CVE-2026-43743MEDIUM 4.7

    CVE-2026-43743 is a race condition affecting Apple's operating systems that can cause an application to unexpectedly crash or terminate the system. The vulnerability requires an attacker to already have code execution on the device (local access) and involves a timing-sensitive flaw in how the operating system handles concurrent operations. While the impact is limited to availability—the system can be made to crash—the fix is straightforward through standard OS updates.

  • CVE-2026-13808MEDIUM 4.6

    Google Chrome on iOS versions before 150.0.7871.47 contain a flaw in how the browser validates user-supplied data, allowing someone with physical access to an iOS device to extract sensitive information from the browser's memory. This is a local-only attack that requires hands-on device access, but the potential exposure of sensitive data makes it worth patching promptly.

  • CVE-2026-11031MEDIUM 4.3

    Google Chrome's Password Manager fails to properly validate input from network traffic before displaying it to users. An attacker can craft malicious network data that tricks the Password Manager interface into showing fake or misleading information—for example, a phishing prompt that looks legitimate. This affects Chrome versions before 149.0.7827.53 on Windows, macOS, and Linux.

  • CVE-2026-11062MEDIUM 4.3

    Google Chrome versions before 149.0.7827.53 contain a vulnerability in how it enforces policies on browser extensions. An attacker could create a malicious extension that, if installed by a user, would be able to inject malicious scripts or HTML code into sensitive browser pages. While the technical barrier is relatively low (it requires social engineering to trick a user into installing the extension), the impact is limited to tampering with page content rather than stealing data or causing system crashes.

  • CVE-2026-11107MEDIUM 4.3

    Google Chrome versions before 149.0.7827.53 contain a flaw in how the browser handles the Downloads feature that allows an attacker to trick users with a deceptive webpage. Specifically, an attacker could craft a malicious HTML page that, when viewed in an affected Chrome browser, would display fake or misleading interface elements to deceive users—a technique called UI spoofing. The vulnerability requires user interaction (visiting the malicious page) but does not compromise confidentiality or system availability; the primary risk is deception around the integrity of what the user sees on their screen.

  • CVE-2026-11126MEDIUM 4.3

    A flaw in Google Chrome's Developer Tools (DevTools) allows an attacker to access data from different websites if they can trick a user into installing a malicious browser extension. The vulnerability has a CVSS score of 4.3 (Medium severity) and requires user interaction—specifically, the user must be convinced to install the malicious extension. Once installed, the crafted extension can exploit improper input validation in DevTools to leak cross-origin data that should normally be protected by browser security policies.

  • CVE-2026-11155MEDIUM 4.3

    Google Chrome versions prior to 149.0.7827.53 contain a flaw in how CSS is processed that could allow an attacker to trick a user into visiting a malicious website where sensitive data from other sites (cross-origin data) could be leaked. The attack requires user interaction—specifically clicking a link or visiting a crafted page—but does not require the attacker to have special permissions or bypass other security controls. The leaked information would be visible only to the attacker, not modified or destroyed.

  • CVE-2026-11156MEDIUM 4.3

    Google Chrome versions prior to 149.0.7827.53 contain a flaw in how it handles CSS styling rules that can allow an attacker to extract data from other websites you have open in your browser. An attacker would need to trick you into visiting a malicious webpage, and if successful could read sensitive information from other tabs or windows—such as content from your email, banking site, or other services—that you're simultaneously visiting. This is a cross-origin data leak vulnerability affecting the browser's CSS implementation.

  • CVE-2026-11159MEDIUM 4.3

    A memory safety issue in Google Chrome's Skia graphics library allows attackers to steal data from websites you visit. By crafting a malicious HTML page, an attacker could trick your browser into exposing information that should remain private to other websites—a cross-origin data leak. The vulnerability requires user interaction (clicking or viewing the page) but doesn't require special browser settings or authentication. Google patched this in Chrome 149.0.7827.53 and later versions.

  • CVE-2026-11161MEDIUM 4.3

    Google Chrome versions prior to 149.0.7827.53 contain a flaw in how it handles cross-origin data transfers. An attacker can craft a malicious HTML page that, when visited by a user, leaks sensitive information from websites the user is logged into or has visited. The vulnerability requires user interaction (clicking or visiting the page) but does not require special browser permissions or user sophistication to exploit.

  • CVE-2026-11162MEDIUM 4.3

    Google Chrome versions before 149.0.7827.53 contain a vulnerability in how the browser handles CSS that can allow attackers to steal data from other websites. An attacker would need to trick a user into visiting a malicious webpage, but once there, the flawed CSS implementation could expose sensitive information from pages the user has open in other tabs or windows. The risk is limited to information disclosure—the vulnerability does not allow attackers to modify data or crash the browser.

  • CVE-2026-11192MEDIUM 4.3

    Google Chrome's password manager has a flaw that fails to properly check information coming from the network. An attacker can exploit this by sending crafted network traffic to trick the browser's UI into displaying fake or misleading content—for example, mimicking legitimate login prompts or security warnings. The attacker cannot steal data or crash the browser, but they can manipulate what users see, potentially leading to credential theft or social engineering attacks if the spoofed interface convinces users to enter sensitive information.

  • CVE-2026-11212MEDIUM 4.3

    A vulnerability in Google Chrome's developer tools (DevTools) fails to properly enforce security policies that should prevent extensions from accessing data across different websites. An attacker could trick a user into installing a malicious Chrome extension, which could then exploit this flaw to steal sensitive information from websites the user visits. The issue affects Chrome versions before 149.0.7827.53.

  • CVE-2026-11216MEDIUM 4.3

    Google Chrome contains a flaw in how it displays security warnings for file input operations. An attacker can craft a malicious webpage that tricks users into performing specific mouse or keyboard actions—such as clicking or dragging—that trigger the file picker dialog. By manipulating the visual presentation of this dialog, the attacker can deceive the user about what action they're performing, potentially leading them to upload sensitive files or authorize unintended operations. This is a user-interaction vulnerability: it requires the attacker to convince the user to engage in the specific gestures, but once they do, the spoofed UI can create false impression of legitimacy.

  • CVE-2026-11219MEDIUM 4.3

    Google Chrome versions before 149.0.7827.53 contain a flaw in how the browser implements navigation controls. An attacker can craft a malicious HTML page that, when visited, bypasses intended navigation restrictions—essentially allowing the page to navigate the browser or access certain destinations in ways it shouldn't be able to. The attack requires user interaction (clicking or visiting the page), but no special browser privileges. While Chromium rates this as Low severity internally, the CVSS scoring reflects Medium severity due to the potential for integrity compromise through navigation spoofing.

  • CVE-2026-11221MEDIUM 4.3

    A weakness in Google Chrome's PointerLock feature allows a threat actor who has already gained control of the browser's renderer process to deceive users through fake on-screen elements. The attacker would craft a malicious HTML page that tricks the browser into displaying misleading UI, potentially impersonating legitimate interface elements. This requires the renderer process to be compromised first, making it a secondary attack that typically follows another successful exploit.

  • CVE-2026-11228MEDIUM 4.3

    Google Chrome before version 149.0.7827.53 contains a flaw in how it handles file input operations that allows attackers to deceive users through visual manipulation. If an attacker can trick a user into performing specific clicks or interactions on a malicious webpage, they can spoof the browser interface—making fake buttons, dialogs, or other UI elements appear legitimate. This is a social engineering attack that relies on user interaction; the vulnerability itself is in Chrome's file input implementation.

  • CVE-2026-11234MEDIUM 4.3

    Google Chrome versions before 149.0.7827.53 contain a vulnerability in the FoldableAPIs feature that allows a remote attacker to bypass site isolation—Chrome's core security boundary that separates web pages from each other—if the attacker has already compromised the renderer process. Site isolation is one of Chrome's strongest defenses against malicious websites stealing data from other tabs or extensions. This vulnerability requires both a compromised renderer and user interaction, limiting the immediate threat but warranting timely patching.

  • CVE-2026-11245MEDIUM 4.3

    CVE-2026-11245 is a user interface spoofing vulnerability in Google Chrome's payment handling system. An attacker can craft a deceptive HTML page that tricks users into believing they are interacting with legitimate payment dialogs or security prompts, potentially leading to credential theft, social engineering, or other forms of user deception. The vulnerability requires user interaction (clicking or engaging with the malicious page) to be exploited, limiting its scope but not eliminating risk in realistic phishing or drive-by attack scenarios.

  • CVE-2026-11252MEDIUM 4.3

    Google Chrome versions before 149.0.7827.53 contain a flaw in how it enforces content policies that could allow an attacker to bypass certain access controls through a specially crafted web page. The vulnerability requires user interaction—an attacker would need to trick someone into visiting a malicious page—but does not leak sensitive data or crash the browser. Instead, it could allow unauthorized modification of content or settings the user intended to protect.

  • CVE-2026-11253MEDIUM 4.3

    Google Chrome contained a flaw in how it handled permissions that could allow an attacker to trick users into visiting a specially crafted web page and leak data from other websites the user was visiting. The vulnerability requires user interaction (clicking or viewing a malicious page) and only affects data confidentiality, not system availability or integrity. Google has patched this in Chrome 149.0.7827.53 and later.

  • CVE-2026-11254MEDIUM 4.3

    Google Chrome versions prior to 149.0.7827.53 contain a UI spoofing vulnerability in its permissions implementation. An attacker can craft a malicious HTML page that, when visited by a user, displays fake permission prompts or other interface elements to deceive users into granting access or performing unintended actions. The attack requires user interaction—specifically, the victim must visit the attacker's page—but does not require any special browser configuration or privilege level.

  • CVE-2026-11257MEDIUM 4.3

    Google Chrome versions before 149.0.7827.53 contain a flaw in how the browser implements navigation controls. An attacker can craft a malicious HTML page that, when visited by a user, bypasses the browser's built-in restrictions on where a page can navigate. This allows the attacker to redirect the user to unintended destinations or perform unwanted navigation actions, potentially leading to phishing, credential harvesting, or distribution of malware. The vulnerability requires user interaction (clicking or visiting the page) and affects Chrome on Windows, macOS, and Linux.

  • CVE-2026-11259MEDIUM 4.3

    Google Chrome versions before 149.0.7827.53 contain a flaw in how the Cast feature validates user-supplied input. This allows an attacker to craft a malicious webpage that, when visited, can bypass Chrome's same-origin policy—a critical security boundary that prevents websites from accessing data belonging to other sites. The attack requires user interaction (visiting the page) but requires no special privileges. While Chromium rates the underlying severity as Low, the ability to circumvent same-origin policy elevates practical risk.

  • CVE-2026-11260MEDIUM 4.3

    Google Chrome versions before 149.0.7827.53 contain a flaw in how it handles permissions that allows attackers to bypass the browser's Content Security Policy (CSP) protections via a specially crafted webpage. While the underlying browser vulnerability severity is rated as low, the CVSS assessment elevates this to medium risk because it requires user interaction but could enable an attacker to execute unintended behavior or inject content that CSP should block. The issue affects Chrome on Windows, macOS, and Linux.

  • CVE-2026-11261MEDIUM 4.3

    Google Chrome versions before 149.0.7827.53 contain a flaw in how it handles PDF rendering that could allow an attacker to trick users into believing they're viewing legitimate content when they're not. If an attacker has already compromised Chrome's rendering engine (the component that displays web pages), they can craft a specially designed HTML page to perform UI spoofing—making fake buttons, warnings, or other interface elements appear authentic. This is a medium-severity issue because it requires both a prior compromise of the renderer process and user interaction to be exploited.

  • CVE-2026-11264MEDIUM 4.3

    Google Chrome versions before 149.0.7827.53 contain a flaw in how Content Security Policy (CSP) is enforced. An attacker can craft a malicious HTML page that, when visited by a user, bypasses the browser's CSP protections. This allows the attacker to inject or execute content that the website owner intended to block, potentially leading to credential theft, session hijacking, or other attacks that degrade site security. The vulnerability requires user interaction—the victim must visit the malicious page—and does not directly compromise the browser itself or enable data exfiltration.

  • CVE-2026-11266MEDIUM 4.3

    Google Chrome versions before 149.0.7827.53 contain a flaw in the Safe Browsing feature that allows a remote attacker to bypass its protections by delivering a specially crafted file. An attacker would need to trick a user into opening or interacting with the malicious file, but if successful, the user's safety checks could be circumvented, potentially allowing access to sites or content that Safe Browsing would normally block.

  • CVE-2026-11267MEDIUM 4.3

    A vulnerability in Google Chrome's extension framework allows a malicious extension to bypass content security policy (CSP) protections if a user installs it. The issue stems from insufficient policy enforcement mechanisms that fail to properly validate extension behavior. While the underlying Chromium severity is rated as Low, the CVSS assessment elevates it to Medium due to the user interaction requirement combined with potential integrity impact. An attacker would need to socially engineer a user into installing a compromised extension—a realistic but not trivial attack vector.

  • CVE-2026-11274MEDIUM 4.3

    A flaw in Google Chrome's DOM Distiller component on iOS allows attackers to bypass navigation restrictions through a specially crafted web page. The vulnerability requires user interaction to trigger—specifically, the victim must visit or interact with a malicious page. The impact is limited to breaking navigation boundaries; no data theft or system crashes are involved. Chrome versions prior to 149.0.7827.53 on iOS are affected.

  • CVE-2026-11277MEDIUM 4.3

    A vulnerability in Chrome for iOS allows an attacker to bypass certain access controls through a specially crafted HTML page. The issue stems from insufficient enforcement of security policies in the iOS version of Chrome. An attacker would need to trick a user into visiting a malicious webpage, but no special user privileges are required and the attack is straightforward to execute. The primary risk is unauthorized modification of data or application behavior—not data theft or system crashes.

  • CVE-2026-11280MEDIUM 4.3

    A flaw in Google Chrome's sign-in interface on iOS allows an attacker to trick users with a fake login screen. By crafting a malicious web page, an attacker could make it appear that a legitimate Chrome sign-in prompt is appearing, potentially deceiving users into entering credentials or sensitive information. The vulnerability requires user interaction—visiting a crafted page—but does not require authentication or special privileges to attempt. While Google classifies this at low severity internally, the CVSS score reflects medium risk due to the integrity impact of potential credential theft or trust erosion.

  • CVE-2026-11285MEDIUM 4.3

    Google Chrome on iOS versions before 149.0.7827.53 contain a flaw that allows attackers to trick users with fake, spoofed user interface elements embedded in malicious web pages. An attacker would need to convince a user to visit a crafted HTML page, but no special privileges are required and the attack can be delivered over the network. The vulnerability does not compromise data confidentiality or availability, but could deceive users about what they are viewing or interacting with.

  • CVE-2026-11286MEDIUM 4.3

    A flaw in Google Chrome's Wallet component allows attackers who have already compromised a browser's renderer process to trick users with fake UI elements displayed on a web page. This requires the attacker to first gain control of the renderer—the part of the browser that displays web content—which is a significant prerequisite but not impossible in real-world scenarios where other vulnerabilities or social engineering may be chained together.

  • CVE-2026-11292MEDIUM 4.3

    Google Chrome versions before 149.0.7827.53 contain a flaw in the Blink rendering engine that allows attackers to bypass Content Security Policy (CSP) protections through a specially crafted webpage. An attacker would need to trick a user into visiting a malicious site, where the weakness could enable injection of unintended content or scripts that CSP was supposed to prevent. While Chromium rates this as low severity, the CVSS score reflects moderate impact potential because CSP bypass can lead to unauthorized modifications of page behavior.

  • CVE-2026-11294MEDIUM 4.3

    Google Chrome versions prior to 149.0.7827.53 contain a flaw in password handling that allows attackers to create fake or misleading login screens through specially crafted web pages. An attacker would need to trick a user into visiting a malicious website, but once there, the browser's UI protections don't adequately prevent visual deception. This is not an authentication bypass—it's a user interface trick that could mislead people about whether they're interacting with legitimate Chrome UI or attacker-controlled content.

  • CVE-2026-11298MEDIUM 4.3

    A vulnerability in Google Chrome for iOS allows attackers to bypass the same-origin policy—a critical security boundary that prevents websites from accessing data belonging to other sites—by tricking users into visiting a specially crafted webpage. The flaw affects Chrome versions before 149.0.7827.53 on iPhones and iPads. While the Chromium project rated this as low severity, the CVSS score reflects a medium severity due to the potential for information disclosure or unauthorized content modification in cross-origin contexts.

  • CVE-2026-11300MEDIUM 4.3

    Google Chrome versions before 149.0.7827.53 contain a flaw in how it handles permissions that allows an attacker to trick users with a specially crafted web page. The attack doesn't steal data or crash the browser—instead, it displays fake permission dialogs or UI elements that might convince a user to grant access they shouldn't. The attacker needs the victim to visit the malicious page, but no special user configuration is required beforehand.

  • CVE-2026-11302MEDIUM 4.3

    A security flaw in Google Chrome for iOS allows attackers to bypass access controls through a specially crafted web page. The vulnerability requires user interaction—a person must visit the malicious page—but does not require any special privileges or system access to attempt exploitation. While Chromium's internal assessment classified this as low severity, the CVSS score of 4.3 reflects moderate concern, primarily because it can lead to unauthorized actions or changes within the browser's trust model, though it does not expose sensitive data or crash the application.

  • CVE-2026-11309MEDIUM 4.3

    Google Chrome versions before 149.0.7827.53 contain a flaw in how the browser enforces policies for the History feature. An attacker can craft a deceptive webpage that tricks users into believing they're interacting with legitimate browser UI elements or content. While the vulnerability requires user interaction and doesn't directly expose sensitive data or crash the browser, the spoofing capability could be weaponized in social engineering campaigns to steal credentials or manipulate user behavior.

  • CVE-2026-11685MEDIUM 4.3

    Google Chrome on macOS contains a flaw in how it handles media capture permissions that could allow an attacker to trick you into revealing data meant to be private to a specific website. By crafting a malicious webpage, an attacker can bypass Chrome's protections and leak information across website boundaries—essentially stealing data that should stay isolated to one origin. The vulnerability requires user interaction, such as visiting a malicious page, but does not require special privileges or system-level access.

  • CVE-2026-11695MEDIUM 4.3

    Google Chrome prior to version 149.0.7827.103 contains a flaw in its password handling logic that could allow an attacker to leak sensitive data across website boundaries. An attacker would need to craft a malicious HTML page and convince a user to visit it, but the vulnerability itself does not require the user to take additional actions beyond normal browsing. The leaked data is restricted to information accessible within the browser context of the affected user.

  • CVE-2026-12446MEDIUM 4.3

    Google Chrome versions before 149.0.7827.155 contain a flaw in how passwords are handled that allows attackers to trick users into visiting a malicious website, which can then leak sensitive information from other websites the user has visited. The vulnerability requires user interaction—specifically clicking a link or visiting a crafted page—but does not require the user to install anything or be an administrator. Once triggered, an attacker gains access only to what the browser can see, not the user's entire system.

  • CVE-2026-13021MEDIUM 4.3

    Google Chrome versions prior to 149.0.7827.197 contain a flaw in how it handles device-bound session credentials that could allow an attacker to bypass the browser's same-origin policy—a critical security boundary that normally prevents websites from accessing data belonging to other sites. An attacker could craft a malicious HTML page that, when visited by a user, potentially gains unauthorized access to sensitive information from other origins. The vulnerability requires user interaction (visiting a malicious page) and is limited to information disclosure; it does not enable data modification or system unavailability.

  • CVE-2026-13842MEDIUM 4.3

    Google Chrome for iOS versions prior to 150.0.7871.47 contain a flaw that allows attackers to trick users by forging what appears in the browser's address bar (Omnibox). An attacker can craft a deceptive HTML page that makes it look like you're visiting a legitimate website when you're actually on a malicious one. This is a spoofing vulnerability—the attacker doesn't gain access to your data or crash your device, but can deceive you about where you actually are on the web.

  • CVE-2026-13902MEDIUM 4.3

    A flaw in Google Chrome for iOS allows an attacker to trick users by making fake content appear in the browser UI. An attacker would need to craft a malicious webpage and convince a user to visit it; the browser would then display misleading interface elements that could be mistaken for genuine browser controls or trusted content. This is a medium-severity issue that affects user trust and could enable phishing or social engineering attacks.

  • CVE-2026-13912MEDIUM 4.3

    Google Chrome on iOS versions before 150.0.7871.47 contain a flaw in how the Safe Browsing feature validates and displays security information. An attacker can craft a malicious web page that tricks users by spoofing the browser's user interface—making it appear as though Chrome is displaying legitimate security warnings or information when it is not. This deceives users into taking actions they would not normally take, such as entering credentials or downloading files. The vulnerability requires user interaction (visiting the malicious page) to be exploited.

  • CVE-2026-13916MEDIUM 4.3

    A vulnerability in Chrome for iOS allows an attacker to trick users into believing they are seeing legitimate content or UI elements when they are actually viewing a forged interface. An attacker would craft a specially designed web page and serve it to a user; if the user visits the page, the attacker could spoof the browser's user interface—for example, making a phishing page look like a legitimate login screen. This affects Chrome versions prior to 150.0.7871.47 on iOS devices. The attack requires user interaction (visiting the malicious page) but no special permissions or system access.

  • CVE-2026-13946MEDIUM 4.3

    A security flaw in Google Chrome on iOS allows attackers to steal data from different websites by tricking users into viewing a specially crafted webpage. The vulnerability stems from improper handling of script injections, which can expose information that should remain hidden between websites. An attacker needs user interaction—typically clicking a link or visiting a malicious site—to exploit this, making it a moderate rather than critical risk.

  • CVE-2026-13980MEDIUM 4.3

    Google Chrome for iOS versions before 150.0.7871.47 contain a flaw that allows attackers to trick users through misleading user interface elements. An attacker could craft a malicious webpage that, when visited, displays fake Chrome UI components—such as address bars or security indicators—to deceive users into believing they're interacting with legitimate browser elements. This is a spoofing vulnerability that relies on user interaction; attackers must convince someone to visit a crafted page, but no special user permissions or technical sophistication is required on the user's end.

  • CVE-2026-13981MEDIUM 4.3

    Google Chrome on iOS contains a UI spoofing vulnerability that allows attackers to deceive users by manipulating how the browser interface appears. An attacker can craft a malicious HTML page that, when visited, tricks users into believing they're interacting with legitimate UI elements—such as address bars or security warnings—when they're actually viewing attacker-controlled content. This vulnerability requires user interaction (visiting the malicious page) but does not compromise data confidentiality or system availability.

  • CVE-2026-13991MEDIUM 4.3

    A vulnerability in Chrome for iOS allows attackers to trick users through fake interface elements on specially crafted websites. When a user visits a malicious page, an attacker can make it appear as though legitimate interface elements (like buttons or address bars) are showing something they're not, potentially tricking the user into taking unintended actions. This requires user interaction—the user must visit the malicious site and interact with it—but the barrier to exploitation is low.

  • CVE-2026-14031MEDIUM 4.3

    Google Chrome versions prior to 150.0.7871.47 contain a flaw in how the file input component handles user interactions, enabling attackers to deceive users through visual spoofing attacks. A malicious HTML page can trick users into believing they are interacting with legitimate browser UI elements when they are not, potentially leading to unintended actions or credential harvesting through deceptive interface overlays.

  • CVE-2026-14066MEDIUM 4.3

    A vulnerability in Google Chrome for iOS allows attackers to bypass navigation restrictions through a specially crafted webpage. An attacker could create a malicious HTML page that, when visited by a user, circumvents Chrome's security controls that normally prevent unwanted navigation. This requires user interaction—the user must visit the malicious page—but does not require the attacker to have special privileges. The impact is limited to integrity concerns rather than data theft or system disruption.

  • CVE-2026-14073MEDIUM 4.3

    A flaw in Google Chrome's WebXR implementation fails to properly validate user-supplied input before processing navigation commands. An attacker can craft a malicious webpage that, when visited by a user, bypasses Chrome's navigation restrictions—allowing the page to navigate to unexpected URLs or perform unwanted redirects. The vulnerability requires user interaction (clicking or visiting the page) and affects Chrome versions prior to 150.0.7871.47. The issue stems from insufficient input sanitization in the WebXR code path, a component used for virtual and augmented reality experiences in the browser.

  • CVE-2026-14075MEDIUM 4.3

    A vulnerability in Chrome for iOS allows attackers to send HTTP requests with referrer information even when a web page has explicitly set a no-referrer policy. An attacker crafts a malicious HTML page that tricks the browser into ignoring this privacy protection, potentially leaking information about which website a user came from. This is a client-side bypass that requires user interaction—the user must visit the attacker's page—but could expose browsing patterns or sensitive context depending on the websites involved.

  • CVE-2026-14076MEDIUM 4.3

    Google Chrome versions before 150.0.7871.47 contain a weakness in how the browser enforces Content Security Policy (CSP), a security feature that restricts which resources a webpage can load. An attacker could craft a malicious HTML page that tricks the browser into loading content that should have been blocked by CSP rules, potentially allowing injection of unwanted scripts or other resources. The attack requires user interaction—the victim must visit the malicious page—but succeeds against unpatched Chrome installations on Windows, macOS, and Linux.

  • CVE-2026-14077MEDIUM 4.3

    Google Chrome on macOS contains a flaw in how it handles the Select element that allows attackers to trick users by making the browser's address bar (Omnibox) display fake URLs. An attacker would craft a malicious webpage that, when visited, could make it appear that the user is on a legitimate site when they're actually somewhere else. This is a spoofing vulnerability that relies on user interaction—the victim must visit the malicious page—but requires no special privileges to exploit.

  • CVE-2026-14092MEDIUM 4.3

    Google Chrome versions before 150.0.7871.47 contain a privacy flaw that allows attackers positioned on a network path between a user and servers to intercept and expose data that should remain isolated between different websites. An attacker must trick or socially engineer the user into visiting a malicious page, but once that happens, the browser's normal cross-origin protections can be bypassed through crafted network traffic. The issue affects Chrome on Windows, macOS, and Linux.

  • CVE-2026-14123MEDIUM 4.3

    Chrome on iOS versions before 150.0.7871.47 contain a flaw in how the browser's address bar (Omnibox) displays security information. An attacker can craft a malicious webpage that tricks the browser into showing a fake URL in the address bar, making it appear as though you're visiting a legitimate site when you're actually on an attacker's domain. This is a spoofing vulnerability that exploits the visual trust signals users rely on to verify they're on the correct website.

  • CVE-2026-14128MEDIUM 4.3

    A flaw in Google Chrome for iOS allows attackers to trick users by making the browser's address bar (Omnibox) display a fake URL. An attacker would craft a malicious web page and trick a user into visiting it; when the user views the address bar, they see a spoofed URL instead of the actual malicious site they're on. This leverages a user interaction requirement—the victim must actively look at the URL bar—which limits the immediate risk, but the deception could enable phishing or social engineering attacks.

  • CVE-2026-14136MEDIUM 4.3

    Google Chrome on iOS versions before 150.0.7871.47 contain a UI spoofing vulnerability that allows attackers to deceive users through a crafted web page. The vulnerability stems from inadequate input validation, enabling malicious actors to manipulate the browser interface in ways that mislead users about the actual content or origin of what they're viewing. While the underlying severity is rated Low by Chromium, the CVSS score of 4.3 reflects the human interaction requirement and limited direct impact—this is primarily a social engineering vector rather than a system compromise threat.

  • CVE-2026-14143MEDIUM 4.3

    Google Chrome on iOS contains a flaw in how it displays password-related security warnings and UI elements. An attacker can craft a malicious webpage that tricks users into thinking they're interacting with legitimate Chrome security prompts when they're actually viewing attacker-controlled content. This UI spoofing could lead users to enter sensitive information or bypass security checks they would otherwise trust. The vulnerability affects Chrome versions before 150.0.7871.47 on Apple iOS devices.

  • CVE-2026-43708MEDIUM 4.3

    A cross-origin data exfiltration vulnerability in Apple's WebKit rendering engine affects Safari and multiple Apple operating systems. A malicious website can extract user data that should remain isolated to the user's own origin, bypassing the browser's same-origin policy. Apple has patched this issue across Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS with improved input validation to enforce proper origin boundaries.

  • CVE-2026-9930MEDIUM 4.3

    An out-of-bounds write vulnerability exists in the Dawn graphics component of Google Chrome on macOS. An attacker can craft a malicious HTML page that, when viewed by a user, writes data to memory locations outside the intended bounds of a buffer. This memory corruption could allow an attacker to modify sensitive data or potentially achieve code execution, though the CVSS assessment indicates the integrity impact is limited. The vulnerability requires user interaction—the victim must visit or be directed to the malicious page—and affects Chrome versions prior to 148.0.7778.216 on macOS.

  • CVE-2026-9935MEDIUM 4.3

    CVE-2026-9935 is a memory safety issue in Google Chrome's ANGLE graphics library that allows attackers to steal sensitive data from other websites. When you visit a malicious webpage, an attacker can craft it to leak information that should be isolated to other sites you have open. The vulnerability requires user interaction—you must visit the attack page—but the bar for exploitation is otherwise low. Google has classified this as High severity internally, though the CVSS score reflects a more limited scope.

  • CVE-2026-9955MEDIUM 4.3

    A vulnerability in Google Chrome on iOS versions before 148.0.7778.216 allows attackers to extract sensitive information from websites the user visits. An attacker would craft a malicious webpage and trick a user into visiting it; the page can then read data intended to be private to other websites. This is a cross-origin data leak—a violation of the browser's same-origin policy that normally prevents websites from accessing each other's information.

  • CVE-2026-12453MEDIUM 4.2

    Google Chrome versions before 149.0.7827.155 contain a flaw where insufficient input validation allows an attacker who has already compromised the browser's renderer process to circumvent the same-origin policy through a specially crafted webpage. This means a sandboxed renderer could potentially access or modify data from websites it should not be able to reach, though the attacker must first gain control of the renderer itself—a significant prerequisite.

  • CVE-2026-12456MEDIUM 4.2

    A vulnerability in how Google Chrome handles extensions before version 149.0.7827.155 allows a malicious extension to bypass the same-origin policy, which normally prevents web pages from accessing data belonging to other websites. An attacker would need to trick a user into installing a specially crafted malicious extension. If successful, the extension could read or modify sensitive information from other websites the user visits. This is a user-consent attack—the user must be socially engineered into installing the extension first.

  • CVE-2026-12457MEDIUM 4.2

    Google Chrome versions prior to 149.0.7827.155 contain a flaw in how extensions are implemented that allows an attacker who has already compromised Chrome's renderer process to escape the site isolation sandbox and access content from different websites. Site isolation is Chrome's core defense that prevents malicious code running on one site from stealing data from another. This vulnerability requires the attacker to have already gained code execution in the renderer—a significant prerequisite—but if achieved, it undermines that critical isolation boundary.

  • CVE-2026-12460MEDIUM 4.2

    Google Chrome versions prior to 149.0.7827.155 contain a weakness in how the browser enforces file system access policies. An attacker who has already compromised Chrome's renderer process (the part that executes web content) can exploit this flaw by serving a specially crafted PDF file to bypass Site Isolation—Chrome's security feature that isolates web content from different sites. The vulnerability requires both an existing renderer compromise and user interaction, limiting its standalone exploitability but reflecting a real protection gap once a renderer is already under attacker control.

  • CVE-2026-13024MEDIUM 4.2

    Google Chrome versions prior to 149.0.7827.197 contain a flaw in how it validates user input during navigation operations. An attacker who has already compromised Chrome's renderer process—the component that interprets and displays web content—can exploit this weakness to bypass Chrome's site isolation security feature. Site isolation is a critical defense that prevents malicious websites from accessing data belonging to other sites. This vulnerability requires an attacker to have already gained control of the renderer process, making it a secondary attack that follows initial compromise.

  • CVE-2026-13905MEDIUM 4.2

    Google Chrome for iOS contains a race condition that could allow an attacker with physical access to an iOS device to read sensitive information from the browser's process memory. The vulnerability requires the attacker to be present at the device and involves timing-sensitive manipulation, making opportunistic exploitation difficult. This affects Chrome versions before 150.0.7871.47 on iOS.

  • CVE-2026-13907MEDIUM 4.2

    Google Chrome on iOS contains a user interface spoofing vulnerability that could allow an attacker to deceive users into believing they are interacting with legitimate content when they are not. The vulnerability requires the attacker to convince a user to perform specific gestures on a crafted webpage, but does not require the user to have special privileges or for the attacker to have prior network access. Patches are available in Chrome 150.0.7871.47 and later.

  • CVE-2026-13973MEDIUM 4.2

    Google Chrome versions before 150.0.7871.47 contain a UI implementation flaw that allows attackers to display fake interface elements—like fake login prompts or warning dialogs—if they can trick users into specific mouse or keyboard interactions on a malicious website. The attacker cannot steal data directly, but can confuse users into revealing passwords or credentials by making the fake UI look legitimate.

  • CVE-2026-13983MEDIUM 4.2

    A vulnerability in Chrome on iOS allows attackers to trick users into believing they are visiting a legitimate website by spoofing the Omnibox (the URL bar that displays the website address). An attacker would need to convince a user to perform specific UI gestures—such as particular taps or swipes—on a crafted webpage to trigger the spoofing. The attack does not grant access to sensitive data but can mislead users about which site they are actually visiting, potentially leading to credential theft or other social engineering attacks. This affects Chrome for iOS versions prior to 150.0.7871.47.

  • CVE-2026-13992MEDIUM 4.2

    Google Chrome on macOS contains a UI implementation flaw that allows attackers to create convincing fake interface elements—a technique known as UI spoofing. An attacker would need to host a malicious webpage and convince a user to interact with specific interface elements in a particular way to trigger the vulnerability. The flaw affects Chrome versions prior to 150.0.7871.47 on macOS. While the attack requires user interaction and deliberate UI manipulation, it can lead to confusion about application state or permissions, potentially tricking users into unintended actions.

  • CVE-2026-13993MEDIUM 4.2

    Google Chrome versions before 150.0.7871.47 contain a flaw in how it displays security warnings during Web App installation. An attacker can craft a malicious webpage that, when a user performs specific interactions (like clicking or gesturing in a particular way), tricks the browser into displaying a misleading security UI. This allows the attacker to spoof a domain—making it appear that a trusted site is actually the attacker's site—potentially deceiving users into entering credentials or trusting malicious content. The attack requires deliberate user interaction and doesn't directly compromise data or system availability, but it can deceive users about what website they're interacting with.

  • CVE-2026-13998MEDIUM 4.2

    Google Chrome on macOS contains a flaw in how it displays security warnings when users interact with file input controls. An attacker could craft a deceptive web page that, when a user performs certain mouse or keyboard actions, disguises malicious activity as a legitimate system dialog. This allows the attacker to trick users into believing they are interacting with Chrome's genuine security interface rather than attacker-controlled content. The vulnerability requires user interaction and specific gestures to exploit, limiting its immediate risk but still representing a meaningful social engineering vector.

  • CVE-2026-14026MEDIUM 4.2

    Google Chrome versions before 150.0.7871.47 contain a UI security flaw in the SplitView feature that allows an attacker to trick users into performing certain click or gesture actions on a specially crafted webpage. When exploited, the vulnerability enables UI spoofing—displaying false security indicators or interface elements that mislead the user about what is actually happening in the browser. This could be used in social engineering attacks where an attacker makes the browser appear to show something it isn't, such as a fake security warning or address bar state.

  • CVE-2026-14028MEDIUM 4.2

    A flaw in Chrome for iOS versions before 150.0.7871.47 can be exploited to show users fake security or interface elements. An attacker would need to craft a malicious webpage and convince the user to perform specific touch gestures—such as tapping in particular ways—to trigger the spoofing. The vulnerability doesn't directly steal data or crash the browser, but it could deceive users into thinking they're interacting with legitimate Chrome UI when they're actually viewing attacker-controlled content.

  • CVE-2026-14137MEDIUM 4.2

    A vulnerability in Chrome for iOS allows attackers to trick users into performing specific gestures on a crafted webpage, resulting in fake UI elements appearing to come from Chrome itself. This 'UI spoofing' attack could mislead users about the source or nature of content they're interacting with, though the underlying browser functionality and user data remain protected. The attack requires user interaction and is rated Medium severity.

  • CVE-2026-14139MEDIUM 4.2

    Google Chrome versions prior to 150.0.7871.47 contain a UI spoofing vulnerability in the TabStrip component that could allow an attacker to deceive users through a malicious webpage. The attack requires the victim to perform specific user interface gestures—such as particular mouse or keyboard interactions—making it less likely to succeed in practice than attacks that trigger automatically. The vulnerability affects Chrome across Windows, macOS, and Linux systems.

  • CVE-2026-14144MEDIUM 4.2

    Google Chrome versions before 150.0.7871.47 contain a flaw in how the browser renders security-related UI elements in the Views framework. An attacker could craft a malicious webpage that, when viewed by a user who performs certain mouse or keyboard interactions, tricks the user into believing they are interacting with legitimate browser UI (like permission dialogs or address bar elements) when they are actually interacting with attacker-controlled content. This is a UI spoofing vulnerability that relies on convincing users to take specific actions on a specially crafted page.

  • CVE-2026-9986MEDIUM 4.2

    CVE-2026-9986 is a UI spoofing vulnerability in Google Chrome's OptimizationGuide component that could let an attacker deceive users about what they're seeing on a webpage. The vulnerability requires the attacker to have already compromised Chrome's rendering process—the engine that draws web content. While this limits the immediate attack scope, it represents a meaningful escalation risk for adversaries who have achieved code execution in that sandboxed component. The flaw stems from inadequate validation of user-supplied input before it's used to generate on-screen elements.

  • CVE-2026-10998MEDIUM 4.0

    CVE-2026-10998 is a memory safety issue in Google Chrome's media handling code that allows an attacker positioned on the same local network to read data from memory locations they shouldn't have access to. The vulnerability exists in Chrome versions before 149.0.7827.53. An attacker would need to send specially crafted network traffic to trigger an out-of-bounds read, which could potentially expose sensitive information resident in the browser's memory. This is a local-network-only threat, meaning the attacker must be on your network segment to exploit it.

  • CVE-2022-48575LOW 3.5

    CVE-2022-48575 is a local bypass vulnerability in macOS that allows someone with physical access to a Mac to circumvent the Login Window security prompt. The issue stems from inconsistent state handling in the authentication system—essentially, the login screen may fail to properly enforce its security state in certain conditions, potentially allowing unauthorized access. Apple has patched this in macOS Monterey 12.4 and later.