By vendor

Google vulnerabilities

Known CVEs affecting Google products, prioritized by severity, with SEC.co remediation and detection guidance.

649 published vulnerabilities · page 1 of 7

  • CVE-2026-10002HIGH 8.8

    A use-after-free memory flaw in PDFium, the PDF rendering engine embedded in Google Chrome, allows attackers to corrupt heap memory by tricking users into opening a specially crafted PDF file. The vulnerability affects Chrome versions before 148.0.7778.216 and requires user interaction to trigger. An attacker exploiting this could achieve code execution with the same privileges as the Chrome process.

  • CVE-2026-10007HIGH 8.8

    Google Chrome versions prior to 148.0.7778.216 contain a use-after-free memory safety flaw in SVG rendering that allows attackers to execute arbitrary code within the browser's sandbox by tricking users into visiting a malicious webpage. An attacker needs only to craft a deceptive HTML page and convince a user to open it—no special privileges or complex interaction are required beyond the initial click.

  • CVE-2026-10013HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's WebCodecs component that could allow an attacker to run malicious code within Chrome's sandbox by tricking a user into visiting a specially crafted website. The vulnerability affects Chrome versions before 148.0.7778.216 and requires user interaction (clicking a link or visiting a page) to be exploited. While the code execution occurs within the sandbox, this still represents a significant security risk as sandbox escapes are a known attack progression path.

  • CVE-2026-10015HIGH 8.8

    Google Chrome versions before 148.0.7778.216 contain an integer overflow vulnerability in the WTF (Web Template Framework) component that allows attackers to execute arbitrary code within the browser's sandbox environment. An attacker can exploit this by tricking a user into visiting a specially crafted webpage, leading to potential code execution with the privileges of the browser process.

  • CVE-2026-10016HIGH 8.8

    A use-after-free flaw exists in Google Chrome's DOM implementation that allows an attacker to execute code within the browser's sandbox by tricking a user into visiting a malicious website. The vulnerability affects Chrome versions before 148.0.7778.216 and requires user interaction (clicking a link or opening a page) but does not require any special permissions or account privileges.

  • CVE-2026-10019HIGH 8.8

    A vulnerability in Google Chrome's ANGLE graphics library (versions before 148.0.7778.216) allows attackers to trick users into visiting a malicious webpage that leaks sensitive data from other websites the user is currently viewing. The flaw stems from improper handling of large numbers in memory calculations, which an attacker can exploit to read cross-origin information that should remain isolated. Users on Windows, macOS, and Linux systems running affected Chrome versions are at risk.

  • CVE-2026-10021HIGH 8.8

    Google Chrome versions before 148.0.7778.216 contain a vulnerability in USB input handling that allows attackers to execute arbitrary code on a user's computer by tricking them into visiting a malicious website. The flaw stems from insufficient validation of untrusted data, meaning Chrome doesn't properly check or sanitize input before processing it through the USB subsystem. An attacker would need to craft a deceptive HTML page and convince a user to visit it, but once clicked, the attack requires no special privileges and can fully compromise the affected system.

  • CVE-2026-10882HIGH 8.8

    Google Chrome contains a use-after-free vulnerability in its network handling code that can allow attackers to execute arbitrary code on a user's system. The flaw affects Chrome versions prior to 149.0.7827.53 and is triggered when a victim visits a specially crafted webpage. Because successful exploitation requires user interaction (visiting a malicious site), the attack surface is primarily limited to social engineering scenarios, though the browser's ubiquity makes this a meaningful threat.

  • CVE-2026-10883HIGH 8.8

    A type confusion vulnerability in Google Chrome's ANGLE graphics library allows attackers to corrupt heap memory through specially crafted web pages. The flaw requires user interaction (visiting a malicious site) but can lead to complete system compromise—confidentiality, integrity, and availability are all at risk. Chrome versions before 149.0.7827.53 are affected.

  • CVE-2026-10885HIGH 8.8

    A use-after-free vulnerability exists in Chrome for iOS that allows attackers to execute arbitrary code on an iPhone or iPad by tricking users into visiting a malicious webpage. The flaw affects Google Chrome on iOS versions before 149.0.7827.53. Because it requires user interaction (clicking a link or viewing a page) but needs no special privileges, it poses a meaningful risk to mobile users, particularly if weaponized through social engineering or drive-by downloads.

  • CVE-2026-10888HIGH 8.8

    Google Chrome versions before 149.0.7827.53 contain a use-after-free memory vulnerability in the Cast Streaming feature that allows attackers on your local network to run arbitrary code on affected machines. An attacker doesn't need valid credentials or user interaction to exploit this—just the ability to send crafted network traffic to a vulnerable Chrome instance. This is a serious vulnerability because it bridges network access to code execution on systems within the same network segment.

  • CVE-2026-10890HIGH 8.8

    Google Chrome contains a use-after-free vulnerability in its Cast functionality that could allow an attacker on your local network to corrupt the browser's memory and potentially execute malicious code. The flaw affects Chrome versions prior to 149.0.7827.53 and requires no user interaction to trigger—an attacker simply needs to send specially crafted network traffic to exploit it. This is a local network attack vector, meaning the attacker must be on the same network segment as the target system.

  • CVE-2026-10891HIGH 8.8

    A use-after-free vulnerability in Google Chrome's graphics (GFX) component allows an attacker to corrupt Chrome's memory by tricking a user into visiting a malicious webpage. Once the memory is compromised, the attacker could read sensitive data, modify page content, or crash the browser. The issue affects Chrome on Linux systems running versions before 149.0.7827.53.

  • CVE-2026-10893HIGH 8.8

    A use-after-free memory vulnerability exists in Google Chrome's Chromoting remote desktop feature that could allow an attacker to run malicious code on a victim's computer through specially crafted network traffic. The flaw affects Chrome versions before 149.0.7827.53 and requires user interaction to trigger. The vulnerability has been assigned a CVSS score of 8.8 (High severity).

  • CVE-2026-10895HIGH 8.8

    A use-after-free vulnerability in Chrome's Ozone component allows attackers to run arbitrary code on a user's computer by tricking them into visiting a malicious website. The flaw exists in versions of Chrome before 149.0.7827.53 and requires user interaction (clicking a link, visiting a page) but no special privileges. Once exploited, an attacker gains full control over the affected browser process and potentially the underlying system.

  • CVE-2026-10896HIGH 8.8

    A use-after-free vulnerability in Chrome for iOS allows attackers to execute arbitrary code on affected devices when a user visits a malicious website. The flaw exists in memory management within Chrome's iOS implementation and does not require any special user interaction beyond visiting a crafted HTML page. Google has assigned this a Critical severity rating within Chromium's internal severity scale, and CVSS scoring reflects it as HIGH (8.8).

  • CVE-2026-10897HIGH 8.8

    Google Chrome versions prior to 149.0.7827.53 contain a flaw in how the GPU rendering engine handles certain HTML constructs. An attacker can craft a malicious web page that, when visited by a user, exploits this flaw to break out of Chrome's security sandbox—the isolation layer that normally prevents malicious code from accessing the underlying operating system. This is a serious issue because sandbox escapes give attackers direct access to your computer's resources, files, and credentials.

  • CVE-2026-10902HIGH 8.8

    A use-after-free memory vulnerability exists in Chrome's Ozone component that allows attackers to execute arbitrary code by tricking users into visiting a specially crafted webpage. The flaw requires user interaction (clicking a link or visiting a site) but poses a critical threat because successful exploitation grants full control over the browser process and potentially the underlying system.

  • CVE-2026-10903HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's WebRTC implementation that allows an attacker to execute arbitrary code within Chrome's sandbox by convincing a user to visit a malicious website. The vulnerability affects Chrome versions prior to 149.0.7827.53 and can lead to complete compromise of the browser process, including reading sensitive data, modifying content, and disrupting availability.

  • CVE-2026-10904HIGH 8.8

    Google Chrome versions prior to 149.0.7827.53 contain a flaw in the V8 JavaScript engine that allows attackers to break out of the browser sandbox and run malicious code with full privileges. An attacker can exploit this by tricking a user into visiting a specially crafted website. Once triggered, the vulnerability bypasses Chrome's security boundary—the sandbox that normally isolates web content from the rest of the system—giving an attacker direct access to execute arbitrary code on the victim's machine.

  • CVE-2026-10907HIGH 8.8

    A memory safety vulnerability in Google Chrome's ANGLE rendering library allows an attacker to craft a malicious webpage that, when visited by a user, could corrupt the browser's memory heap. This out-of-bounds write flaw can lead to code execution with the privileges of the user running Chrome. The vulnerability requires user interaction—someone must visit the compromised or attacker-controlled page—but needs no special browser configuration or user permissions to trigger the exploit.

  • CVE-2026-10910HIGH 8.8

    Google Chrome contains a type confusion vulnerability in its V8 JavaScript engine that allows an attacker to execute arbitrary code within the browser's sandbox by sending a specially crafted HTML page to a user. The vulnerability requires user interaction (clicking a link or visiting a malicious site) but no special privileges. Once exploited, an attacker gains the ability to run code inside the sandbox, potentially leading to data theft, credential capture, or lateral movement to the underlying system.

  • CVE-2026-10913HIGH 8.8

    A use-after-free vulnerability exists in the ANGLE graphics library component of Google Chrome on Windows. An attacker can craft a malicious HTML page that, when visited by a user, triggers memory corruption within Chrome's sandbox environment. While the sandbox limits direct system compromise, successful exploitation allows arbitrary code execution within that sandboxed context, potentially leading to data theft, credential capture, or lateral movement attempts. The vulnerability requires user interaction (visiting a malicious page) but no special privileges.

  • CVE-2026-10914HIGH 8.8

    A use-after-free vulnerability in ANGLE (the graphics abstraction layer used by Chrome on Windows) allows an attacker to execute code within Chrome's sandbox by tricking a user into visiting a malicious website. The vulnerability affects Chrome versions before 149.0.7827.53 and requires user interaction (visiting a crafted HTML page) but does not require any special privileges. Once exploited, the attacker gains the capabilities of the Chrome sandbox process, which is a significant security boundary but still constrains their access compared to the host system.

  • CVE-2026-10922HIGH 8.8

    CVE-2026-10922 is a same-origin policy bypass vulnerability in Google Chrome's Developer Tools that allows an attacker to access data or perform actions they normally shouldn't be able to. The flaw stems from inadequate validation of untrusted input, meaning malicious network traffic can exploit it if a user performs certain interactions with the DevTools interface. While the attack requires user interaction, it carries significant impact—unauthorized access to sensitive information, unauthorized modifications, or disruption of services are all possible. The vulnerability affects Chrome versions prior to 149.0.7827.53 across Windows, macOS, and Linux systems.

  • CVE-2026-10923HIGH 8.8

    A use-after-free memory flaw in Google Chrome's web app installation feature for Android allows a local attacker to crash the browser or execute arbitrary code by providing a malicious file. The vulnerability affects Chrome versions before 149.0.7827.53 and requires user interaction (opening or installing a crafted app). While the attack requires local access and user involvement, the consequences—including full system compromise through code execution—make this a significant risk for Android users.

  • CVE-2026-10926HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's Cast functionality that allows an attacker positioned on the same local network to execute arbitrary code on an affected system. The flaw requires no user interaction and can be triggered through specially crafted network traffic. This is a local network attack with high impact—an attacker gaining code execution can read sensitive data, modify system files, and disrupt operations.

  • CVE-2026-10928HIGH 8.8

    A script injection vulnerability in Google Chrome's Headless mode allows attackers to execute arbitrary code on a user's system through a malicious HTML page. The flaw requires user interaction—specifically, the victim must open a crafted webpage in an affected Chrome version—but once triggered, an attacker gains the same privileges as the user running the browser, including the ability to read files, modify data, or install malware.

  • CVE-2026-10932HIGH 8.8

    Google Chrome for Android contains a use-after-free vulnerability in its UI handling that allows an attacker to send a malicious HTML page to a user. If the user opens it, the flaw can corrupt Chrome's memory and potentially give the attacker control over the browser. The vulnerability was present in Chrome versions before 149.0.7827.53 on Android devices.

  • CVE-2026-10935HIGH 8.8

    A type confusion vulnerability in Google Chrome's V8 JavaScript engine allows attackers to execute arbitrary code within the browser's sandbox by tricking users into visiting a malicious website. The vulnerability affects Chrome versions prior to 149.0.7827.53 and requires user interaction (clicking a link or visiting a page). While the code executes within the sandbox, successful exploitation could allow attackers to read, modify, or delete user data accessible to the browser.

  • CVE-2026-10936HIGH 8.8

    A type confusion flaw in Chrome's V8 JavaScript engine allows attackers to execute arbitrary code within the browser's sandbox by tricking users into viewing a specially crafted webpage. The vulnerability requires user interaction (clicking a link or visiting a site) but no authentication or special privileges. Successful exploitation could give an attacker the ability to run malicious code with the same permissions as the Chrome process.

  • CVE-2026-10939HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's WebRTC component that allows an attacker to execute arbitrary code within Chrome's sandbox by tricking a user into visiting a malicious webpage. The vulnerability affects Chrome versions prior to 149.0.7827.53 across Windows, macOS, and Linux. While the exploit requires user interaction (clicking a link or visiting a site), the impact is severe: an attacker gains code execution within the browser process.

  • CVE-2026-10941HIGH 8.8

    A memory access vulnerability in the Skia graphics engine used by Google Chrome allows attackers to run malicious code within Chrome's sandbox by tricking users into visiting a specially crafted webpage. The attack requires user interaction (clicking a link or visiting a site) but needs no special privileges. While the code runs in a sandbox environment, successful exploitation could compromise data confidentiality, integrity, and availability within that isolated context.

  • CVE-2026-10943HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's WebRTC component that allows attackers to execute arbitrary code within the browser's sandbox. An attacker can exploit this by crafting a malicious HTML page that, when visited by a user, triggers the vulnerability. Although the code execution occurs in a sandbox (limiting direct system access), the vulnerability has a CVSS score of 8.8, indicating it poses a significant risk to confidentiality, integrity, and availability. Chrome versions before 149.0.7827.53 are affected.

  • CVE-2026-10945HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's PDF handling that allows attackers to execute code within Chrome's sandbox if they can trick a user into performing specific UI interactions with a malicious PDF file. The vulnerability affects Chrome versions prior to 149.0.7827.53 across Windows, macOS, and Linux systems.

  • CVE-2026-10947HIGH 8.8

    A use-after-free bug in Google Chrome's WebRTC implementation allows attackers to execute arbitrary code within the browser's sandbox by serving a specially crafted webpage. The vulnerability affects Chrome versions before 149.0.7827.53 and requires user interaction—the victim must visit a malicious page—but once triggered, it grants an attacker near-complete control over the isolated browser process. This is a memory safety issue where freed memory is incorrectly accessed, a common source of high-impact browser exploits.

  • CVE-2026-10948HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's WebRTC implementation that allows attackers to run malicious code within the browser's sandbox by tricking users into visiting a crafted webpage. The attacker needs user interaction (clicking a link or visiting a malicious site) but requires no special privileges or system access to exploit it. Once triggered, the vulnerability grants full read, write, and execution capabilities within the sandboxed Chrome process.

  • CVE-2026-10951HIGH 8.8

    A use-after-free flaw in Chrome's Autofill feature on iOS allows attackers to corrupt device memory if a user is tricked into performing specific interactions with a malicious webpage. The vulnerability requires user interaction but can lead to complete system compromise—reading sensitive data, modifying files, or crashing the browser.

  • CVE-2026-10952HIGH 8.8

    A use-after-free vulnerability in Google Chrome for iOS allows attackers to corrupt memory on affected iPhones by tricking users into visiting a malicious website. The flaw exists in how Chrome handles certain objects in memory after they've been freed, leaving dangling references that an attacker can manipulate through a crafted HTML page. If successfully exploited, this could lead to arbitrary code execution on the victim's device.

  • CVE-2026-10954HIGH 8.8

    A use-after-free memory safety bug in Google Chrome's Actor component allows attackers to run malicious code within the browser's sandbox by tricking users into visiting a specially crafted web page. The vulnerability affects Chrome versions before 149.0.7827.53 and requires user interaction—specifically clicking a link or visiting a malicious site—but no special privileges. Once triggered, an attacker gains the ability to read, modify, or delete data and potentially escape the sandbox to affect the underlying operating system.

  • CVE-2026-10955HIGH 8.8

    A type confusion vulnerability exists in ANGLE, the graphics abstraction layer used by Google Chrome on Windows. An attacker can craft a malicious web page that, when visited by a user, exploits this flaw to access memory outside intended boundaries. This could lead to information disclosure, data corruption, or system crashes. The vulnerability requires user interaction (visiting a malicious page) but needs no special privileges to trigger.

  • CVE-2026-10956HIGH 8.8

    Google Chrome versions before 149.0.7827.53 contain a use-after-free vulnerability in the MimeHandlerView component that could allow an attacker to run malicious code within Chrome's sandbox. An attacker would need to trick a user into visiting a specially crafted webpage to trigger the flaw. If successful, the attacker could gain code execution inside the sandboxed process, potentially compromising user data or enabling further system compromise depending on sandbox escape possibilities.

  • CVE-2026-10957HIGH 8.8

    A use-after-free flaw in Chrome's Glic component allows attackers to execute malicious code within the browser's sandbox by tricking users into visiting a specially crafted webpage. The vulnerability requires user interaction but needs no special privileges to exploit. An attacker could gain code execution in a sandboxed context, potentially reading sensitive data or further compromising the system depending on sandbox escape capabilities.

  • CVE-2026-10958HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome for iOS that could allow an attacker to execute arbitrary code on a user's iPhone. The flaw requires tricking a user into performing specific gestures (such as taps or swipes) while viewing a malicious webpage. Once exploited, an attacker gains full control over the browser process, potentially compromising sensitive data, installing malware, or pivoting to other device functions. Google has addressed this issue in Chrome version 149.0.7827.53 and later.

  • CVE-2026-10959HIGH 8.8

    Google Chrome on Android contains a use-after-free vulnerability in its Input component that could allow an attacker to execute arbitrary code within the browser's sandbox by tricking a user into visiting a malicious website. The vulnerability affects Chrome versions prior to 149.0.7827.53 and requires user interaction (clicking a link or visiting a crafted page) to trigger.

  • CVE-2026-10962HIGH 8.8

    A type confusion vulnerability in Google Chrome's media handling allows attackers to execute malicious code within the browser's sandbox through a specially crafted webpage. The vulnerability requires user interaction (visiting a malicious page) but poses significant risk because it bypasses browser security boundaries. Chrome versions prior to 149.0.7827.53 are affected across Windows, macOS, and Linux platforms.

  • CVE-2026-10963HIGH 8.8

    A flaw in Google Chrome's V8 JavaScript engine allows attackers to run malicious code within Chrome's security sandbox by tricking users into visiting a specially crafted webpage. The vulnerability stems from an integer overflow—a mathematical error where a number becomes too large for its storage space—that can be exploited without requiring any special permissions or user complexity beyond clicking a link. While the code executes inside the sandbox rather than directly on the operating system, successful exploitation still enables attackers to potentially steal data, modify information, or degrade browser functionality.

  • CVE-2026-10964HIGH 8.8

    A flaw in Google Chrome's JavaScript engine (V8) can allow an attacker to run malicious code within the browser's sandbox by tricking a user into visiting a specially crafted webpage. The vulnerability stems from an integer overflow—a type of memory handling error—that undermines the sandbox's security boundary. While the code runs in a confined environment, this still represents a significant security risk because it can be chained with other vulnerabilities to escape the sandbox and compromise the underlying system.

  • CVE-2026-10965HIGH 8.8

    A vulnerability in Google Chrome's DevTools allows attackers to execute malicious code within Chrome's sandbox by tricking users into visiting a specially crafted webpage. The flaw stems from an integer overflow—a coding error where a number exceeds its maximum value—that can be exploited without requiring special browser settings or elevated permissions. Chrome versions before 149.0.7827.53 are affected.

  • CVE-2026-10975HIGH 8.8

    A use-after-free vulnerability in Google Chrome's WebRTC component allows an attacker to execute arbitrary code within the Chrome sandbox by tricking a user into visiting a specially crafted website. The vulnerability affects Chrome versions prior to 149.0.7827.53 and requires user interaction—specifically clicking a link or visiting a malicious page—but does not require any special privileges. Once exploited, an attacker gains the ability to run code with the same permissions as the Chrome process, potentially compromising sensitive data or escalating further.

  • CVE-2026-10978HIGH 8.8

    A use-after-free vulnerability in Google Chrome's Chromoting component allows attackers to execute arbitrary code on Windows systems. An attacker can trigger the flaw by sending specially crafted network traffic to a target who is using Chrome's remote desktop or remote assistance feature. Successful exploitation grants the attacker the same privileges as the Chrome process, potentially leading to complete system compromise. The vulnerability requires user interaction (for example, accepting a remote connection or visiting a malicious site that initiates Chromoting), but otherwise presents a direct path to code execution without requiring special system privileges or authentication.

  • CVE-2026-10982HIGH 8.8

    A use-after-free flaw in Google Chrome's WebXR implementation allows attackers to run malicious code within the browser's sandbox by tricking users into visiting a specially crafted webpage. The vulnerability affects Chrome versions before 149.0.7827.53 on Windows, macOS, and Linux. While sandboxed, successful exploitation could compromise user data and enable further attacks. User interaction (clicking a link or visiting a site) is required to trigger the vulnerability.

  • CVE-2026-10986HIGH 8.8

    A flaw in how Google Chrome processes media files can allow an attacker to execute code within Chrome's sandbox by tricking a user into opening a malicious file. The vulnerability stems from improper handling of numeric values in media processing, creating a window for code execution. While sandboxed, successful exploitation could grant an attacker access to sensitive data or control within the browser process.

  • CVE-2026-10987HIGH 8.8

    Google Chrome versions before 149.0.7827.53 contain an integer overflow flaw in the V8 JavaScript engine that allows attackers to run malicious code within Chrome's sandbox using a specially crafted webpage. An attacker would need to trick a user into visiting a malicious site, but requires no special privileges or browser plugins. The vulnerability is rated High severity.

  • CVE-2026-10988HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's Views component that could allow an attacker to escape the browser's sandbox. The flaw requires an attacker to first compromise Chrome's renderer process—the sandboxed component that processes web content—and then serve a specially crafted HTML page to trigger the vulnerability. If successfully exploited, an attacker could break out of the sandbox and execute code with the full privileges of the Chrome process, potentially compromising the underlying system. Chrome versions prior to 149.0.7827.53 are affected.

  • CVE-2026-10989HIGH 8.8

    A flaw in Google Chrome's V8 JavaScript engine allows attackers to corrupt memory on a victim's computer through a specially crafted web page, but only if the user performs specific interactions with the page. The vulnerability requires user action and comes from an inappropriate implementation in Chrome versions before 149.0.7827.53. Once exploited, an attacker could read sensitive data, modify files, or crash the browser.

  • CVE-2026-10991HIGH 8.8

    Google Chrome contains a use-after-free memory vulnerability in its V8 JavaScript engine that can allow an attacker to run malicious code within Chrome's sandbox. The flaw requires user interaction—specifically, the victim must perform certain UI gestures (like clicking or interacting with specific page elements) while viewing a specially crafted webpage. Once triggered, the vulnerability could allow code execution with the privileges of the Chrome process, potentially compromising the user's browsing session and data. This affects Chrome versions prior to 149.0.7827.53 across Windows, macOS, and Linux systems.

  • CVE-2026-10995HIGH 8.8

    A heap buffer overflow vulnerability exists in Google Chrome's TabStrip component that could allow an attacker to corrupt memory on a user's system. The attack requires convincing a user to perform specific gestures while viewing a malicious webpage. While Chromium's maintainers classified this as medium severity, the actual impact—potential code execution with high integrity and confidentiality compromise—warrants close attention from security teams.

  • CVE-2026-11000HIGH 8.8

    A use-after-free vulnerability in Google Chrome's font handling on Linux allows attackers to execute arbitrary code within the browser's sandbox by tricking users into visiting a specially crafted webpage. The vulnerability affects Chrome versions before 149.0.7827.53 and requires user interaction (clicking a link or viewing a page) to trigger, but carries no special privilege requirements.

  • CVE-2026-11003HIGH 8.8

    Google Chrome versions before 149.0.7827.53 contain a use-after-free vulnerability in its WebRTC component that could allow an attacker to run arbitrary code within Chrome's sandbox by tricking a user into visiting a malicious web page. While the underlying flaw is rated Medium severity by Chromium, the CVSS score reflects the practical impact: network delivery with minimal user friction and full compromise of confidentiality, integrity, and availability within the sandboxed process.

  • CVE-2026-11024HIGH 8.8

    A stack buffer overflow vulnerability exists in the Skia graphics library, which is used by Google Chrome. An attacker could craft a malicious HTML page that, when viewed by a user, potentially corrupts stack memory and compromises the browser process. The vulnerability requires user interaction (visiting a malicious webpage) but presents significant risk because it can lead to code execution with the privileges of the Chrome process. Google Chrome versions prior to 149.0.7827.53 are affected.

  • CVE-2026-11028HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's media handling on Linux and ChromeOS. If an attacker compromises Chrome's renderer process—the sandboxed component that interprets web content—they can craft a malicious HTML page to execute arbitrary code within that sandbox. This is a post-compromise attack that escalates the damage from a renderer breach but does not grant escape from the sandbox itself.

  • CVE-2026-11030HIGH 8.8

    Google Chrome versions prior to 149.0.7827.53 contain a use-after-free vulnerability in the Network component that can be triggered by malicious network traffic. An attacker who crafts and delivers hostile network packets to a user's browser could potentially corrupt the heap memory, leading to code execution with the privileges of the browser process. User interaction (such as visiting a malicious website or receiving crafted network data) is required for exploitation.

  • CVE-2026-11041HIGH 8.8

    A vulnerability in Google Chrome's media handling on Windows systems allows an attacker who has already compromised Chrome's renderer process to break out of the browser's security sandbox through a specially crafted web page. This sandbox escape is the critical concern: while the attacker must first gain control of the renderer, doing so grants them access to the underlying Windows system with the privileges of the Chrome user. The vulnerability affects Chrome versions before 149.0.7827.53.

  • CVE-2026-11042HIGH 8.8

    Google Chrome versions before 149.0.7827.53 contain a use-after-free flaw in its Views component that can allow attackers to corrupt browser memory. An attacker must convince a user to perform specific interactions with a malicious webpage to trigger the vulnerability, potentially leading to code execution or data theft. While Chromium rates this as medium severity, the CVSS score of 8.8 reflects the high impact if successfully exploited.

  • CVE-2026-11046HIGH 8.8

    A flaw in Google Chrome's media handling allows an attacker who has already compromised the browser's renderer process to break out of the sandbox and run arbitrary code with full system privileges. The vulnerability stems from insufficient validation of untrusted input when processing media files, and requires user interaction (such as opening a crafted HTML page) to trigger. Chrome versions prior to 149.0.7827.53 are affected across Windows, macOS, and Linux systems.

  • CVE-2026-11049HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's Password Manager that could allow an attacker to run malicious code within Chrome's sandbox by tricking a user into visiting a specially crafted website. The flaw affects Chrome versions before 149.0.7827.53 across Windows, macOS, and Linux. While the Chromium project rates this as medium severity, the CVSS score of 8.8 reflects the combination of network accessibility, lack of authentication requirements, and potential for high-impact code execution.

  • CVE-2026-11050HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's V8 JavaScript engine that allows attackers to execute arbitrary code within the browser's sandbox by tricking users into visiting a malicious webpage. The flaw requires user interaction (clicking a link or visiting a site) but needs no special privileges to exploit. While Chromium's security team rated this as medium severity internally, the CVSS score of 8.8 reflects the high impact if successfully exploited—attackers could steal data, modify content, or crash the browser.

  • CVE-2026-11054HIGH 8.8

    A use-after-free memory flaw in Chrome's WebRTC component allows an attacker to execute arbitrary code within the browser's sandbox by tricking a user into visiting a malicious webpage. The vulnerability affects Chrome versions prior to 149.0.7827.53 and impacts multiple operating systems including Windows, macOS, and Linux. Successful exploitation requires user interaction (clicking a link or visiting a site) but can lead to complete compromise of the affected browser process.

  • CVE-2026-11055HIGH 8.8

    A use-after-free vulnerability in ANGLE (Google's graphics library) affects Chrome on Windows systems prior to version 149.0.7827.53. An attacker can craft a malicious webpage that, when visited, executes arbitrary code within Chrome's sandbox environment. While the Chromium team rated this as medium severity internally, the CVSS score of 8.8 reflects the practical impact: any user visiting a hostile site is at risk, no user interaction beyond clicking a link is required, and successful exploitation grants code execution.

  • CVE-2026-11059HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's Blink rendering engine that allows attackers to execute arbitrary code within the browser's sandbox by tricking users into visiting a malicious website. The flaw affects Chrome versions prior to 149.0.7827.53 and requires user interaction (clicking a link or visiting a page) but poses significant risk because successful exploitation grants an attacker the ability to run code with the privileges of the Chrome process.

  • CVE-2026-11060HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's media handling on Windows systems. An attacker can craft a malicious HTML page that, when visited by a user, exploits this flaw to execute arbitrary code within Chrome's sandbox. While the sandbox provides a layer of isolation, successful exploitation would still allow the attacker to run code with the privileges of the Chrome process, potentially leading to data theft, credential capture, or lateral movement to the system itself.

  • CVE-2026-11068HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's WebSocket implementation that could allow an attacker to execute arbitrary code within the browser's sandbox by tricking a user into visiting a malicious webpage. The flaw affects Chrome versions before 149.0.7827.53 and impacts Windows, macOS, and Linux systems. While the underlying code defect is classified as Medium severity by the Chromium project, the CVSS score of 8.8 reflects the practical risk: an attacker needs only to convince a user to visit a crafted page, requires no special privileges, and can achieve full code execution within the sandbox boundary.

  • CVE-2026-11071HIGH 8.8

    A use-after-free memory vulnerability exists in Google Chrome's Base component on Linux systems. An attacker who has already compromised Chrome's renderer process can craft a malicious web page to read sensitive data directly from the browser's memory. While the underlying flaw carries a Medium severity rating from Chromium, the CVSS score reflects the potential for information disclosure combined with the practical attack surface. Chrome version 149.0.7827.53 and later on Linux contain the fix.

  • CVE-2026-11074HIGH 8.8

    A use-after-free vulnerability in Google Chrome's WebRTC component on Linux systems allows attackers to execute arbitrary code if a user visits a specially crafted webpage. The vulnerability stems from improper memory management in the WebRTC implementation, where code attempts to access memory that has already been freed. This can be exploited remotely without requiring special user privileges, though user interaction (visiting a malicious page) is necessary. The issue affects Chrome versions prior to 149.0.7827.53 on Linux.

  • CVE-2026-11076HIGH 8.8

    A type confusion vulnerability in Google Chrome's CSS handling allows attackers to execute malicious code within the browser's sandbox by tricking users into visiting a specially crafted webpage. The vulnerability affects Chrome versions prior to 149.0.7827.53 and requires user interaction (clicking a link or visiting a site), but once triggered, grants the attacker code execution capabilities despite the sandbox protections that normally isolate the browser from the rest of the system.

  • CVE-2026-11077HIGH 8.8

    A flaw in the Dawn graphics component of Google Chrome allows attackers to run malicious code within the browser's sandbox by tricking users into visiting a specially crafted website. The vulnerability requires user interaction (clicking a link or visiting a page) but doesn't require any special privileges. Once exploited, an attacker gains the same permissions as the Chrome process, potentially allowing them to steal data or compromise the system.

  • CVE-2026-11079HIGH 8.8

    Google Chrome contains a vulnerability in its video codec handling that allows attackers to write data outside the intended memory boundaries. An attacker can exploit this by crafting a malicious video file and tricking a user into opening it, potentially allowing the attacker to execute arbitrary code, steal sensitive information, or crash the browser. This affects Chrome versions prior to 149.0.7827.53 across Windows, macOS, and Linux systems.

  • CVE-2026-11080HIGH 8.8

    A use-after-free memory vulnerability exists in Google Chrome's WebView component on Android devices. An attacker can craft a malicious HTML page that, when visited by a user, triggers memory corruption in the browser's heap. This could allow the attacker to execute arbitrary code or crash the application. The vulnerability affects Chrome versions before 149.0.7827.53 on Android.

  • CVE-2026-11085HIGH 8.8

    A flaw in Google Chrome's GPU processing on Android devices allows attackers to trigger an integer overflow—a mathematical error where a number exceeds its storage limit—when rendering specially crafted web pages. This overflow can lead to out-of-bounds memory access, potentially allowing attackers to read sensitive data, modify system memory, or crash the application. The vulnerability requires user interaction (visiting a malicious page) but poses significant risk because it can be triggered remotely and affects a widely-used browser on millions of Android devices.

  • CVE-2026-11086HIGH 8.8

    A vulnerability in Google Chrome's Dawn graphics component allows an attacker who has already compromised the browser's renderer process to break out of the sandbox and execute arbitrary code with full system privileges. The attack requires user interaction (opening a malicious HTML page), but once triggered, it completely undermines Chrome's security architecture. Chrome versions prior to 149.0.7827.53 are affected on Windows, macOS, and Linux systems.

  • CVE-2026-11091HIGH 8.8

    A flaw in Google Chrome's graphics rendering engine (Dawn) allows attackers to trick users into visiting malicious web pages that can read sensitive data, modify files, or crash the browser. The vulnerability requires user interaction—specifically clicking a link or visiting a crafted website—but once triggered, it bypasses Chrome's memory protections. This affects Chrome versions before 149.0.7827.53 across Windows, macOS, and Linux.

  • CVE-2026-11092HIGH 8.8

    A flaw in Google Chrome's developer tools (DevTools) fails to properly enforce security policies, allowing an attacker to escalate privileges if they can trick a user into installing a malicious browser extension. The vulnerability affects Chrome versions before 149.0.7827.53 across Windows, macOS, and Linux. While the attacker needs user interaction (installing the extension), the resulting privilege escalation grants them high-impact access to the browser process and potentially sensitive data.

  • CVE-2026-11102HIGH 8.8

    Google Chrome versions before 149.0.7827.53 contain a flaw in how Isolated Web Apps are implemented that could allow an attacker to run malicious code inside Chrome's sandbox. The vulnerability requires user interaction—such as opening a malicious file—but does not require any special privileges. Once triggered, an attacker gains the ability to read sensitive data, modify information, or disrupt availability within the sandbox context.

  • CVE-2026-11108HIGH 8.8

    A flaw in how Google Chrome handles NFC (Near Field Communication) on Android devices allows an attacker to trick a user into visiting a malicious website, which can then escape the browser sandbox and gain elevated privileges on the device. The vulnerability requires user interaction—specifically clicking a link or visiting a page—but does not require the attacker to be network-adjacent or have special system access. Once exploited, an attacker gains the same privileges as the Chrome browser process, potentially enabling access to sensitive data or further system compromise.

  • CVE-2026-11116HIGH 8.8

    Google Chrome contains a use-after-free memory vulnerability in its Chromoting remote desktop feature that can be triggered by malicious network traffic. An attacker can send specially crafted packets to a targeted user, leading to arbitrary code execution on the victim's machine. The vulnerability requires user interaction—specifically, the user must be engaged in an active Chromoting session—but once triggered, it grants the attacker the same privileges as the Chrome process.

  • CVE-2026-11117HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's Views component on Windows systems. An attacker can exploit this flaw by crafting a malicious HTML page that, when visited by a user, allows remote code execution on the victim's machine. The vulnerability affects Chrome versions prior to 149.0.7827.53 and requires user interaction (visiting a malicious site), but once triggered, grants the attacker full system compromise capabilities.

  • CVE-2026-11118HIGH 8.8

    A memory safety vulnerability exists in Google Chrome's WebRTC implementation that could allow attackers to run malicious code within the browser's sandbox. The flaw stems from a use-after-free condition—where the browser continues using memory that has already been freed—which can be triggered by visiting a specially crafted webpage. No special permissions or user interaction beyond clicking a link or viewing a page are required, making this a significant remote code execution risk despite being contained within the sandbox.

  • CVE-2026-11124HIGH 8.8

    A memory handling flaw in Chrome's Skia graphics library allows attackers to trigger heap corruption by serving a specially crafted webpage. The vulnerability requires user interaction (visiting a malicious page) but needs no special privileges and works across all major operating systems where Chrome runs. An attacker could achieve code execution with full system access—reading files, modifying data, installing malware, or pivoting to other systems.

  • CVE-2026-11125HIGH 8.8

    A use-after-free memory flaw in Google Chrome's compositing system allows attackers to run arbitrary code within Chrome's sandbox by tricking users into visiting a malicious webpage. The vulnerability affects Chrome versions before 149.0.7827.53 across Windows, macOS, and Linux. While contained by the sandbox, successful exploitation could grant an attacker the same privileges as the Chrome process, potentially compromising sensitive browser data and operations.

  • CVE-2026-11130HIGH 8.8

    A use-after-free vulnerability in Google Chrome's media handling allows attackers to run malicious code within Chrome's sandbox by tricking users into visiting a specially crafted website. While the underlying Chromium project rates this as Medium severity, the CVSS score of 8.8 reflects the practical risk: it requires user interaction (clicking a link or visiting a site), but once triggered, it can lead to full compromise of the Chrome process, potentially exposing sensitive data or enabling further attacks on the underlying system.

  • CVE-2026-11136HIGH 8.8

    Google Chrome versions prior to 149.0.7827.53 contain a use-after-free vulnerability in the Canvas component that allows attackers to execute arbitrary code within the browser sandbox. An attacker can exploit this flaw by crafting a malicious HTML page that, when visited by a user, triggers memory corruption and leads to code execution. The vulnerability requires user interaction (visiting a webpage) but needs no special privileges to trigger.

  • CVE-2026-11144HIGH 8.8

    A use-after-free memory flaw in Google Chrome's media handling allows an attacker to execute malicious code within Chrome's sandbox by tricking a user into opening a specially crafted video file. While sandboxed, successful exploitation could still grant an attacker significant control over the affected browser process and potentially access to sensitive user data.

  • CVE-2026-11147HIGH 8.8

    A use-after-free vulnerability exists in Chrome's WebML (Web Machine Learning) component on Windows. An attacker can craft a malicious HTML page that, when visited by a user, triggers code execution within Chrome's sandbox. Although the sandbox contains the damage, the vulnerability allows an attacker to breach browser process isolation and execute arbitrary code with the privileges of the Chrome renderer process.

  • CVE-2026-11164HIGH 8.8

    A use-after-free vulnerability exists in Blink, Google Chrome's rendering engine, affecting versions prior to 149.0.7827.53. An attacker can craft a malicious HTML page that, when visited by a user, exploits this memory safety flaw to execute arbitrary code within the Chrome sandbox. While sandboxed, successful exploitation grants an attacker code execution capabilities on the victim's machine, potentially enabling further compromise.

  • CVE-2026-11171HIGH 8.8

    A flaw in Blink, the rendering engine behind Google Chrome, allows attackers to trigger an integer overflow by sending a specially crafted web page. If a user visits a malicious site, the attacker can run malicious code within Chrome's sandbox. While the sandbox limits damage, this vulnerability bypasses a critical security boundary and is rated HIGH severity.

  • CVE-2026-11172HIGH 8.8

    A UI spoofing flaw in Chrome's Contact Picker on Android allows attackers to trick users via specially crafted web pages. When a user attempts to select a contact, a malicious site can mask its true identity or intentions by manipulating the security UI elements that normally help users understand what app or service is asking for contact information. This deceives users into granting access to their contacts under false pretenses.

  • CVE-2026-11173HIGH 8.8

    A memory writing vulnerability in Google Chrome's V8 JavaScript engine (used to execute web code) allows a specially crafted webpage to trigger an out-of-bounds write operation. An attacker who has already compromised the browser's rendering process can exploit this flaw to break out of the sandbox and run arbitrary code with the privileges of the Chrome process. This requires an attacker to first gain control of the renderer, making it a post-compromise escalation vector rather than a direct entry point.

  • CVE-2026-11175HIGH 8.8

    Google Chrome on Android contains a flaw in how it displays security-related UI elements within the Messages feature. An attacker can craft a malicious webpage that tricks users into thinking they're interacting with legitimate Chrome security dialogs or warnings, when they're actually seeing fake ones controlled by the attacker. This UI spoofing attack requires user interaction—the victim must visit the malicious page—but once they do, the attacker can deceive them into taking actions they wouldn't normally take, such as entering credentials or approving permissions.

  • CVE-2026-11177HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's Omnibox (the combined address and search bar). An attacker can craft a malicious HTML page that, when a user performs specific interactions with the Omnibox, triggers memory corruption. Successful exploitation requires user interaction—the attacker cannot silently compromise a machine, but if a targeted user visits a crafted page and engages with the address bar in a particular way, the attacker could potentially execute arbitrary code with the privileges of the Chrome process.