By vendor

Google vulnerabilities

Known CVEs affecting Google products, prioritized by severity, with SEC.co remediation and detection guidance.

1195 published vulnerabilities · page 11 of 12

  • CVE-2026-11031MEDIUM 4.3

    Google Chrome's Password Manager fails to properly validate input from network traffic before displaying it to users. An attacker can craft malicious network data that tricks the Password Manager interface into showing fake or misleading information—for example, a phishing prompt that looks legitimate. This affects Chrome versions before 149.0.7827.53 on Windows, macOS, and Linux.

  • CVE-2026-11062MEDIUM 4.3

    Google Chrome versions before 149.0.7827.53 contain a vulnerability in how it enforces policies on browser extensions. An attacker could create a malicious extension that, if installed by a user, would be able to inject malicious scripts or HTML code into sensitive browser pages. While the technical barrier is relatively low (it requires social engineering to trick a user into installing the extension), the impact is limited to tampering with page content rather than stealing data or causing system crashes.

  • CVE-2026-11107MEDIUM 4.3

    Google Chrome versions before 149.0.7827.53 contain a flaw in how the browser handles the Downloads feature that allows an attacker to trick users with a deceptive webpage. Specifically, an attacker could craft a malicious HTML page that, when viewed in an affected Chrome browser, would display fake or misleading interface elements to deceive users—a technique called UI spoofing. The vulnerability requires user interaction (visiting the malicious page) but does not compromise confidentiality or system availability; the primary risk is deception around the integrity of what the user sees on their screen.

  • CVE-2026-11126MEDIUM 4.3

    A flaw in Google Chrome's Developer Tools (DevTools) allows an attacker to access data from different websites if they can trick a user into installing a malicious browser extension. The vulnerability has a CVSS score of 4.3 (Medium severity) and requires user interaction—specifically, the user must be convinced to install the malicious extension. Once installed, the crafted extension can exploit improper input validation in DevTools to leak cross-origin data that should normally be protected by browser security policies.

  • CVE-2026-11155MEDIUM 4.3

    Google Chrome versions prior to 149.0.7827.53 contain a flaw in how CSS is processed that could allow an attacker to trick a user into visiting a malicious website where sensitive data from other sites (cross-origin data) could be leaked. The attack requires user interaction—specifically clicking a link or visiting a crafted page—but does not require the attacker to have special permissions or bypass other security controls. The leaked information would be visible only to the attacker, not modified or destroyed.

  • CVE-2026-11156MEDIUM 4.3

    Google Chrome versions prior to 149.0.7827.53 contain a flaw in how it handles CSS styling rules that can allow an attacker to extract data from other websites you have open in your browser. An attacker would need to trick you into visiting a malicious webpage, and if successful could read sensitive information from other tabs or windows—such as content from your email, banking site, or other services—that you're simultaneously visiting. This is a cross-origin data leak vulnerability affecting the browser's CSS implementation.

  • CVE-2026-11159MEDIUM 4.3

    A memory safety issue in Google Chrome's Skia graphics library allows attackers to steal data from websites you visit. By crafting a malicious HTML page, an attacker could trick your browser into exposing information that should remain private to other websites—a cross-origin data leak. The vulnerability requires user interaction (clicking or viewing the page) but doesn't require special browser settings or authentication. Google patched this in Chrome 149.0.7827.53 and later versions.

  • CVE-2026-11161MEDIUM 4.3

    Google Chrome versions prior to 149.0.7827.53 contain a flaw in how it handles cross-origin data transfers. An attacker can craft a malicious HTML page that, when visited by a user, leaks sensitive information from websites the user is logged into or has visited. The vulnerability requires user interaction (clicking or visiting the page) but does not require special browser permissions or user sophistication to exploit.

  • CVE-2026-11162MEDIUM 4.3

    Google Chrome versions before 149.0.7827.53 contain a vulnerability in how the browser handles CSS that can allow attackers to steal data from other websites. An attacker would need to trick a user into visiting a malicious webpage, but once there, the flawed CSS implementation could expose sensitive information from pages the user has open in other tabs or windows. The risk is limited to information disclosure—the vulnerability does not allow attackers to modify data or crash the browser.

  • CVE-2026-11178MEDIUM 4.3

    A security gap in Chrome's WebView component on Android devices allows attackers to steal sensitive information from websites you visit. By tricking a user into opening a malicious webpage, an attacker can bypass Chrome's normal protections and read data that should be restricted to other websites. This affects Chrome versions before 149.0.7827.53. The vulnerability requires user interaction—someone must click a link or open a malicious page—but doesn't require special privileges or advanced technical setup.

  • CVE-2026-11192MEDIUM 4.3

    Google Chrome's password manager has a flaw that fails to properly check information coming from the network. An attacker can exploit this by sending crafted network traffic to trick the browser's UI into displaying fake or misleading content—for example, mimicking legitimate login prompts or security warnings. The attacker cannot steal data or crash the browser, but they can manipulate what users see, potentially leading to credential theft or social engineering attacks if the spoofed interface convinces users to enter sensitive information.

  • CVE-2026-11212MEDIUM 4.3

    A vulnerability in Google Chrome's developer tools (DevTools) fails to properly enforce security policies that should prevent extensions from accessing data across different websites. An attacker could trick a user into installing a malicious Chrome extension, which could then exploit this flaw to steal sensitive information from websites the user visits. The issue affects Chrome versions before 149.0.7827.53.

  • CVE-2026-11216MEDIUM 4.3

    Google Chrome contains a flaw in how it displays security warnings for file input operations. An attacker can craft a malicious webpage that tricks users into performing specific mouse or keyboard actions—such as clicking or dragging—that trigger the file picker dialog. By manipulating the visual presentation of this dialog, the attacker can deceive the user about what action they're performing, potentially leading them to upload sensitive files or authorize unintended operations. This is a user-interaction vulnerability: it requires the attacker to convince the user to engage in the specific gestures, but once they do, the spoofed UI can create false impression of legitimacy.

  • CVE-2026-11219MEDIUM 4.3

    Google Chrome versions before 149.0.7827.53 contain a flaw in how the browser implements navigation controls. An attacker can craft a malicious HTML page that, when visited, bypasses intended navigation restrictions—essentially allowing the page to navigate the browser or access certain destinations in ways it shouldn't be able to. The attack requires user interaction (clicking or visiting the page), but no special browser privileges. While Chromium rates this as Low severity internally, the CVSS scoring reflects Medium severity due to the potential for integrity compromise through navigation spoofing.

  • CVE-2026-11221MEDIUM 4.3

    A weakness in Google Chrome's PointerLock feature allows a threat actor who has already gained control of the browser's renderer process to deceive users through fake on-screen elements. The attacker would craft a malicious HTML page that tricks the browser into displaying misleading UI, potentially impersonating legitimate interface elements. This requires the renderer process to be compromised first, making it a secondary attack that typically follows another successful exploit.

  • CVE-2026-11228MEDIUM 4.3

    Google Chrome before version 149.0.7827.53 contains a flaw in how it handles file input operations that allows attackers to deceive users through visual manipulation. If an attacker can trick a user into performing specific clicks or interactions on a malicious webpage, they can spoof the browser interface—making fake buttons, dialogs, or other UI elements appear legitimate. This is a social engineering attack that relies on user interaction; the vulnerability itself is in Chrome's file input implementation.

  • CVE-2026-11234MEDIUM 4.3

    Google Chrome versions before 149.0.7827.53 contain a vulnerability in the FoldableAPIs feature that allows a remote attacker to bypass site isolation—Chrome's core security boundary that separates web pages from each other—if the attacker has already compromised the renderer process. Site isolation is one of Chrome's strongest defenses against malicious websites stealing data from other tabs or extensions. This vulnerability requires both a compromised renderer and user interaction, limiting the immediate threat but warranting timely patching.

  • CVE-2026-11245MEDIUM 4.3

    CVE-2026-11245 is a user interface spoofing vulnerability in Google Chrome's payment handling system. An attacker can craft a deceptive HTML page that tricks users into believing they are interacting with legitimate payment dialogs or security prompts, potentially leading to credential theft, social engineering, or other forms of user deception. The vulnerability requires user interaction (clicking or engaging with the malicious page) to be exploited, limiting its scope but not eliminating risk in realistic phishing or drive-by attack scenarios.

  • CVE-2026-11252MEDIUM 4.3

    Google Chrome versions before 149.0.7827.53 contain a flaw in how it enforces content policies that could allow an attacker to bypass certain access controls through a specially crafted web page. The vulnerability requires user interaction—an attacker would need to trick someone into visiting a malicious page—but does not leak sensitive data or crash the browser. Instead, it could allow unauthorized modification of content or settings the user intended to protect.

  • CVE-2026-11253MEDIUM 4.3

    Google Chrome contained a flaw in how it handled permissions that could allow an attacker to trick users into visiting a specially crafted web page and leak data from other websites the user was visiting. The vulnerability requires user interaction (clicking or viewing a malicious page) and only affects data confidentiality, not system availability or integrity. Google has patched this in Chrome 149.0.7827.53 and later.

  • CVE-2026-11254MEDIUM 4.3

    Google Chrome versions prior to 149.0.7827.53 contain a UI spoofing vulnerability in its permissions implementation. An attacker can craft a malicious HTML page that, when visited by a user, displays fake permission prompts or other interface elements to deceive users into granting access or performing unintended actions. The attack requires user interaction—specifically, the victim must visit the attacker's page—but does not require any special browser configuration or privilege level.

  • CVE-2026-11257MEDIUM 4.3

    Google Chrome versions before 149.0.7827.53 contain a flaw in how the browser implements navigation controls. An attacker can craft a malicious HTML page that, when visited by a user, bypasses the browser's built-in restrictions on where a page can navigate. This allows the attacker to redirect the user to unintended destinations or perform unwanted navigation actions, potentially leading to phishing, credential harvesting, or distribution of malware. The vulnerability requires user interaction (clicking or visiting the page) and affects Chrome on Windows, macOS, and Linux.

  • CVE-2026-11259MEDIUM 4.3

    Google Chrome versions before 149.0.7827.53 contain a flaw in how the Cast feature validates user-supplied input. This allows an attacker to craft a malicious webpage that, when visited, can bypass Chrome's same-origin policy—a critical security boundary that prevents websites from accessing data belonging to other sites. The attack requires user interaction (visiting the page) but requires no special privileges. While Chromium rates the underlying severity as Low, the ability to circumvent same-origin policy elevates practical risk.

  • CVE-2026-11260MEDIUM 4.3

    Google Chrome versions before 149.0.7827.53 contain a flaw in how it handles permissions that allows attackers to bypass the browser's Content Security Policy (CSP) protections via a specially crafted webpage. While the underlying browser vulnerability severity is rated as low, the CVSS assessment elevates this to medium risk because it requires user interaction but could enable an attacker to execute unintended behavior or inject content that CSP should block. The issue affects Chrome on Windows, macOS, and Linux.

  • CVE-2026-11261MEDIUM 4.3

    Google Chrome versions before 149.0.7827.53 contain a flaw in how it handles PDF rendering that could allow an attacker to trick users into believing they're viewing legitimate content when they're not. If an attacker has already compromised Chrome's rendering engine (the component that displays web pages), they can craft a specially designed HTML page to perform UI spoofing—making fake buttons, warnings, or other interface elements appear authentic. This is a medium-severity issue because it requires both a prior compromise of the renderer process and user interaction to be exploited.

  • CVE-2026-11264MEDIUM 4.3

    Google Chrome versions before 149.0.7827.53 contain a flaw in how Content Security Policy (CSP) is enforced. An attacker can craft a malicious HTML page that, when visited by a user, bypasses the browser's CSP protections. This allows the attacker to inject or execute content that the website owner intended to block, potentially leading to credential theft, session hijacking, or other attacks that degrade site security. The vulnerability requires user interaction—the victim must visit the malicious page—and does not directly compromise the browser itself or enable data exfiltration.

  • CVE-2026-11266MEDIUM 4.3

    Google Chrome versions before 149.0.7827.53 contain a flaw in the Safe Browsing feature that allows a remote attacker to bypass its protections by delivering a specially crafted file. An attacker would need to trick a user into opening or interacting with the malicious file, but if successful, the user's safety checks could be circumvented, potentially allowing access to sites or content that Safe Browsing would normally block.

  • CVE-2026-11267MEDIUM 4.3

    A vulnerability in Google Chrome's extension framework allows a malicious extension to bypass content security policy (CSP) protections if a user installs it. The issue stems from insufficient policy enforcement mechanisms that fail to properly validate extension behavior. While the underlying Chromium severity is rated as Low, the CVSS assessment elevates it to Medium due to the user interaction requirement combined with potential integrity impact. An attacker would need to socially engineer a user into installing a compromised extension—a realistic but not trivial attack vector.

  • CVE-2026-11274MEDIUM 4.3

    A flaw in Google Chrome's DOM Distiller component on iOS allows attackers to bypass navigation restrictions through a specially crafted web page. The vulnerability requires user interaction to trigger—specifically, the victim must visit or interact with a malicious page. The impact is limited to breaking navigation boundaries; no data theft or system crashes are involved. Chrome versions prior to 149.0.7827.53 on iOS are affected.

  • CVE-2026-11277MEDIUM 4.3

    A vulnerability in Chrome for iOS allows an attacker to bypass certain access controls through a specially crafted HTML page. The issue stems from insufficient enforcement of security policies in the iOS version of Chrome. An attacker would need to trick a user into visiting a malicious webpage, but no special user privileges are required and the attack is straightforward to execute. The primary risk is unauthorized modification of data or application behavior—not data theft or system crashes.

  • CVE-2026-11280MEDIUM 4.3

    A flaw in Google Chrome's sign-in interface on iOS allows an attacker to trick users with a fake login screen. By crafting a malicious web page, an attacker could make it appear that a legitimate Chrome sign-in prompt is appearing, potentially deceiving users into entering credentials or sensitive information. The vulnerability requires user interaction—visiting a crafted page—but does not require authentication or special privileges to attempt. While Google classifies this at low severity internally, the CVSS score reflects medium risk due to the integrity impact of potential credential theft or trust erosion.

  • CVE-2026-11285MEDIUM 4.3

    Google Chrome on iOS versions before 149.0.7827.53 contain a flaw that allows attackers to trick users with fake, spoofed user interface elements embedded in malicious web pages. An attacker would need to convince a user to visit a crafted HTML page, but no special privileges are required and the attack can be delivered over the network. The vulnerability does not compromise data confidentiality or availability, but could deceive users about what they are viewing or interacting with.

  • CVE-2026-11286MEDIUM 4.3

    A flaw in Google Chrome's Wallet component allows attackers who have already compromised a browser's renderer process to trick users with fake UI elements displayed on a web page. This requires the attacker to first gain control of the renderer—the part of the browser that displays web content—which is a significant prerequisite but not impossible in real-world scenarios where other vulnerabilities or social engineering may be chained together.

  • CVE-2026-11291MEDIUM 4.3

    A flaw in how Google Chrome handles autofill on Android devices allows an attacker to craft a malicious webpage that can bypass the browser's same-origin policy protections. By tricking a user into visiting their page, an attacker could potentially manipulate how Chrome autofills data in unexpected ways. Google rates this as low severity internally, though the CVSS score reflects it as medium risk due to the user interaction required and limited scope of potential impact.

  • CVE-2026-11292MEDIUM 4.3

    Google Chrome versions before 149.0.7827.53 contain a flaw in the Blink rendering engine that allows attackers to bypass Content Security Policy (CSP) protections through a specially crafted webpage. An attacker would need to trick a user into visiting a malicious site, where the weakness could enable injection of unintended content or scripts that CSP was supposed to prevent. While Chromium rates this as low severity, the CVSS score reflects moderate impact potential because CSP bypass can lead to unauthorized modifications of page behavior.

  • CVE-2026-11294MEDIUM 4.3

    Google Chrome versions prior to 149.0.7827.53 contain a flaw in password handling that allows attackers to create fake or misleading login screens through specially crafted web pages. An attacker would need to trick a user into visiting a malicious website, but once there, the browser's UI protections don't adequately prevent visual deception. This is not an authentication bypass—it's a user interface trick that could mislead people about whether they're interacting with legitimate Chrome UI or attacker-controlled content.

  • CVE-2026-11298MEDIUM 4.3

    A vulnerability in Google Chrome for iOS allows attackers to bypass the same-origin policy—a critical security boundary that prevents websites from accessing data belonging to other sites—by tricking users into visiting a specially crafted webpage. The flaw affects Chrome versions before 149.0.7827.53 on iPhones and iPads. While the Chromium project rated this as low severity, the CVSS score reflects a medium severity due to the potential for information disclosure or unauthorized content modification in cross-origin contexts.

  • CVE-2026-11300MEDIUM 4.3

    Google Chrome versions before 149.0.7827.53 contain a flaw in how it handles permissions that allows an attacker to trick users with a specially crafted web page. The attack doesn't steal data or crash the browser—instead, it displays fake permission dialogs or UI elements that might convince a user to grant access they shouldn't. The attacker needs the victim to visit the malicious page, but no special user configuration is required beforehand.

  • CVE-2026-11302MEDIUM 4.3

    A security flaw in Google Chrome for iOS allows attackers to bypass access controls through a specially crafted web page. The vulnerability requires user interaction—a person must visit the malicious page—but does not require any special privileges or system access to attempt exploitation. While Chromium's internal assessment classified this as low severity, the CVSS score of 4.3 reflects moderate concern, primarily because it can lead to unauthorized actions or changes within the browser's trust model, though it does not expose sensitive data or crash the application.

  • CVE-2026-11309MEDIUM 4.3

    Google Chrome versions before 149.0.7827.53 contain a flaw in how the browser enforces policies for the History feature. An attacker can craft a deceptive webpage that tricks users into believing they're interacting with legitimate browser UI elements or content. While the vulnerability requires user interaction and doesn't directly expose sensitive data or crash the browser, the spoofing capability could be weaponized in social engineering campaigns to steal credentials or manipulate user behavior.

  • CVE-2026-11665MEDIUM 4.3

    A flaw in Google Chrome's graphics rendering engine (Dawn) on Windows could allow an attacker to trick a user into visiting a malicious webpage that leaks sensitive data from other websites the user is logged into. The vulnerability requires user interaction—the user must visit the crafted page—but does not require any special permissions or complex attack setup. The leaked data is limited in scope and does not include the ability to modify or destroy information.

  • CVE-2026-11668MEDIUM 4.3

    Google Chrome and Chrome OS contain a weakness in their video codec processing that could allow a remote attacker to steal data from other websites. The flaw stems from uninitialized memory in the codec layer—essentially, the browser fails to properly initialize certain memory regions before use. An attacker can craft a malicious video file that, when opened by a user, exploits this memory state to read sensitive information across security boundaries. The vulnerability affects Chrome on Linux and Chrome OS versions prior to 149.0.7827.103.

  • CVE-2026-11685MEDIUM 4.3

    Google Chrome on macOS contains a flaw in how it handles media capture permissions that could allow an attacker to trick you into revealing data meant to be private to a specific website. By crafting a malicious webpage, an attacker can bypass Chrome's protections and leak information across website boundaries—essentially stealing data that should stay isolated to one origin. The vulnerability requires user interaction, such as visiting a malicious page, but does not require special privileges or system-level access.

  • CVE-2026-11695MEDIUM 4.3

    Google Chrome prior to version 149.0.7827.103 contains a flaw in its password handling logic that could allow an attacker to leak sensitive data across website boundaries. An attacker would need to craft a malicious HTML page and convince a user to visit it, but the vulnerability itself does not require the user to take additional actions beyond normal browsing. The leaked data is restricted to information accessible within the browser context of the affected user.

  • CVE-2026-12446MEDIUM 4.3

    Google Chrome versions before 149.0.7827.155 contain a flaw in how passwords are handled that allows attackers to trick users into visiting a malicious website, which can then leak sensitive information from other websites the user has visited. The vulnerability requires user interaction—specifically clicking a link or visiting a crafted page—but does not require the user to install anything or be an administrator. Once triggered, an attacker gains access only to what the browser can see, not the user's entire system.

  • CVE-2026-12469MEDIUM 4.3

    A memory initialization flaw in Google Chrome's GPU rendering engine on Android can allow attackers to steal sensitive data from other websites. When you visit a malicious webpage, the attacker could potentially read information from other sites you're currently accessing in different tabs or windows, thanks to uninitialized data being exposed through graphics processing. This is a local attack requiring user interaction—the victim must click on or interact with a crafted link—but the potential for cross-origin data leakage makes it a meaningful security concern for mobile users.

  • CVE-2026-13021MEDIUM 4.3

    Google Chrome versions prior to 149.0.7827.197 contain a flaw in how it handles device-bound session credentials that could allow an attacker to bypass the browser's same-origin policy—a critical security boundary that normally prevents websites from accessing data belonging to other sites. An attacker could craft a malicious HTML page that, when visited by a user, potentially gains unauthorized access to sensitive information from other origins. The vulnerability requires user interaction (visiting a malicious page) and is limited to information disclosure; it does not enable data modification or system unavailability.

  • CVE-2026-13837MEDIUM 4.3

    Google Chrome versions prior to 150.0.7871.47 contain a flaw in CSS handling that allows attackers to deceive users through visual spoofing. By crafting a malicious HTML page, an attacker can trick the browser into displaying fake UI elements—such as bogus address bars, dialogs, or buttons—that appear legitimate but are actually part of the webpage content. This could enable phishing attacks or social engineering by making malicious content look like trusted browser or website elements.

  • CVE-2026-13842MEDIUM 4.3

    Google Chrome for iOS versions prior to 150.0.7871.47 contain a flaw that allows attackers to trick users by forging what appears in the browser's address bar (Omnibox). An attacker can craft a deceptive HTML page that makes it look like you're visiting a legitimate website when you're actually on a malicious one. This is a spoofing vulnerability—the attacker doesn't gain access to your data or crash your device, but can deceive you about where you actually are on the web.

  • CVE-2026-13865MEDIUM 4.3

    Google Chrome versions before 150.0.7871.47 contain a flaw that allows attackers to trick users with fake interface elements. An attacker could craft a malicious website that makes parts of the browser or page look different from what they actually are—for example, spoofing a login prompt or security warning. The vulnerability requires user interaction (visiting a crafted page) but doesn't require special privileges or browser extensions to exploit.

  • CVE-2026-13867MEDIUM 4.3

    Google Chrome versions prior to 150.0.7871.47 contain a vulnerability in the Geolocation feature that allows attackers to deceive users through fake UI elements. By crafting a malicious HTML page, a remote attacker can manipulate what users see on screen—a technique known as UI spoofing—without requiring any special system access or authentication. The attack requires user interaction, such as visiting a compromised website, but does not result in data theft or system compromise.

  • CVE-2026-13902MEDIUM 4.3

    A flaw in Google Chrome for iOS allows an attacker to trick users by making fake content appear in the browser UI. An attacker would need to craft a malicious webpage and convince a user to visit it; the browser would then display misleading interface elements that could be mistaken for genuine browser controls or trusted content. This is a medium-severity issue that affects user trust and could enable phishing or social engineering attacks.

  • CVE-2026-13912MEDIUM 4.3

    Google Chrome on iOS versions before 150.0.7871.47 contain a flaw in how the Safe Browsing feature validates and displays security information. An attacker can craft a malicious web page that tricks users by spoofing the browser's user interface—making it appear as though Chrome is displaying legitimate security warnings or information when it is not. This deceives users into taking actions they would not normally take, such as entering credentials or downloading files. The vulnerability requires user interaction (visiting the malicious page) to be exploited.

  • CVE-2026-13916MEDIUM 4.3

    A vulnerability in Chrome for iOS allows an attacker to trick users into believing they are seeing legitimate content or UI elements when they are actually viewing a forged interface. An attacker would craft a specially designed web page and serve it to a user; if the user visits the page, the attacker could spoof the browser's user interface—for example, making a phishing page look like a legitimate login screen. This affects Chrome versions prior to 150.0.7871.47 on iOS devices. The attack requires user interaction (visiting the malicious page) but no special permissions or system access.

  • CVE-2026-13941MEDIUM 4.3

    Google Chrome on Android contains a flaw in how it handles SiteSettings that allows attackers to deceive users visually through a specially crafted web page. An attacker can craft HTML that tricks Chrome's interface into displaying misleading information to the user—for example, making it appear that a dangerous permission has been denied when it was actually granted, or vice versa. This is a social engineering vector that relies on user interaction (visiting the malicious page) but does not require special browser permissions or system privileges to execute.

  • CVE-2026-13946MEDIUM 4.3

    A security flaw in Google Chrome on iOS allows attackers to steal data from different websites by tricking users into viewing a specially crafted webpage. The vulnerability stems from improper handling of script injections, which can expose information that should remain hidden between websites. An attacker needs user interaction—typically clicking a link or visiting a malicious site—to exploit this, making it a moderate rather than critical risk.

  • CVE-2026-13952MEDIUM 4.3

    A flaw in Google Chrome's PerformanceAPIs allows attackers to steal data from different websites without proper authorization. An attacker can craft a malicious webpage that, when visited by a user, reads sensitive information from other sites the user has open. The vulnerability requires user interaction—the victim must visit the attacker's page—but no special browser settings or advanced technical knowledge are needed to exploit it. Google has patched this issue in Chrome version 150.0.7871.47 and later.

  • CVE-2026-13959MEDIUM 4.3

    Google Chrome versions before 150.0.7871.47 contain a flaw in Blink (Chrome's rendering engine) that fails to properly validate user input in HTML pages. An attacker can exploit this by crafting a malicious HTML page that, when visited, bypasses the same-origin policy—a critical browser security boundary that prevents websites from accessing data or performing actions on behalf of other sites. The vulnerability requires user interaction (visiting a malicious page) but poses a moderate integrity risk.

  • CVE-2026-13960MEDIUM 4.3

    Google Chrome versions before 150.0.7871.47 contain a flaw in the password management system that allows attackers to deceive users through visual trickery. By crafting a malicious web page, an attacker can make Chrome's interface appear to show something it isn't—for example, a legitimate password prompt or security warning—fooling users into taking actions they wouldn't normally take. This is a UI spoofing attack: the attacker doesn't break into systems directly, but manipulates what users see on screen to trick them into compromising their own credentials or security.

  • CVE-2026-13966MEDIUM 4.3

    Google Chrome contains a flaw in how it handles browser history that allows an attacker to trick users into believing they are viewing legitimate content when they are not. An attacker can craft a malicious webpage that, when visited, spoofs the appearance of the browser's UI—such as the address bar or other interface elements—to deceive users about what site they are actually on or what action they are performing. This requires user interaction (clicking or viewing the page) but does not require any special system privileges. The issue affects Chrome versions before 150.0.7871.47.

  • CVE-2026-13972MEDIUM 4.3

    Google Chrome versions before 150.0.7871.47 contain a flaw in how the browser's Paint component handles HTML rendering that allows attackers to trick users into thinking they're interacting with legitimate interface elements when they're actually viewing spoofed content. An attacker could craft a malicious webpage that, when visited, displays fake buttons, address bars, or other UI elements to deceive users into performing unintended actions. The attack requires user interaction—specifically visiting the malicious page—but no special privileges or difficult technical conditions.

  • CVE-2026-13978MEDIUM 4.3

    Google Chrome versions before 150.0.7871.47 contain a vulnerability in how the browser enforces policies within its PageInfo component, which displays website permission and security information to users. An attacker can craft a malicious HTML page that tricks users into believing they are interacting with legitimate Chrome UI elements—such as permission prompts or security warnings—when they are actually seeing attacker-controlled content. This UI spoofing attack requires user interaction to succeed but could lead to credential theft, social engineering, or other deceptive practices if the fake UI is convincing enough.

  • CVE-2026-13979MEDIUM 4.3

    Google Chrome versions before 150.0.7871.47 contain a UI spoofing vulnerability in the Paint feature. An attacker can craft a malicious HTML page that, when visited by a user, tricks the browser into displaying misleading visual elements—making it appear that legitimate security warnings or interface elements are present when they are not. This is a client-side attack requiring user interaction but poses a real risk of social engineering and credential theft.

  • CVE-2026-13980MEDIUM 4.3

    Google Chrome for iOS versions before 150.0.7871.47 contain a flaw that allows attackers to trick users through misleading user interface elements. An attacker could craft a malicious webpage that, when visited, displays fake Chrome UI components—such as address bars or security indicators—to deceive users into believing they're interacting with legitimate browser elements. This is a spoofing vulnerability that relies on user interaction; attackers must convince someone to visit a crafted page, but no special user permissions or technical sophistication is required on the user's end.

  • CVE-2026-13981MEDIUM 4.3

    Google Chrome on iOS contains a UI spoofing vulnerability that allows attackers to deceive users by manipulating how the browser interface appears. An attacker can craft a malicious HTML page that, when visited, tricks users into believing they're interacting with legitimate UI elements—such as address bars or security warnings—when they're actually viewing attacker-controlled content. This vulnerability requires user interaction (visiting the malicious page) but does not compromise data confidentiality or system availability.

  • CVE-2026-13984MEDIUM 4.3

    Google Chrome versions before 150.0.7871.47 contain a flaw in the TabStrip component's security interface that allows an attacker to deceive users through visual spoofing. By crafting a malicious web page, an attacker can manipulate what the browser displays to make it appear legitimate while performing unwanted actions. The attack requires user interaction—specifically, the user must visit the malicious page—but does not require any special privileges or complex browser configurations to execute.

  • CVE-2026-13987MEDIUM 4.3

    A vulnerability in Google Chrome on Android allows attackers to deceive users through fake security warnings or misleading interface elements. By crafting a malicious HTML page, a remote attacker can make Chrome's security UI appear different from what it actually is—for example, displaying a fake warning dialog or masking the real address bar—to trick users into trusting untrustworthy content or performing unintended actions. The attack requires user interaction (clicking or viewing the page) but no special privileges. This affects Chrome versions prior to 150.0.7871.47 on Android devices.

  • CVE-2026-13991MEDIUM 4.3

    A vulnerability in Chrome for iOS allows attackers to trick users through fake interface elements on specially crafted websites. When a user visits a malicious page, an attacker can make it appear as though legitimate interface elements (like buttons or address bars) are showing something they're not, potentially tricking the user into taking unintended actions. This requires user interaction—the user must visit the malicious site and interact with it—but the barrier to exploitation is low.

  • CVE-2026-13994MEDIUM 4.3

    Google Chrome on Android contains a flaw in how it manages user credentials that allows attackers to trick users with fake authentication dialogs or credential prompts. An attacker hosting a specially crafted website could deceive users into believing they're interacting with legitimate Chrome security features, potentially leading to credential theft or other user manipulation. The vulnerability requires user interaction—specifically visiting a malicious webpage—but poses a real risk because users generally trust browser UI elements.

  • CVE-2026-13995MEDIUM 4.3

    A flaw in Google Chrome's autofill feature on Android devices allows an attacker to trick users with a fake website. The vulnerability exists because the browser doesn't properly validate input when displaying autofill suggestions, giving attackers an opening to create deceptive pages that mimic legitimate interfaces. This is a relatively low-risk issue—it requires user interaction and only affects how information appears on screen, not data theft or system crashes—but it's worth patching because social engineering attacks that fool users into revealing credentials remain a persistent threat.

  • CVE-2026-13999MEDIUM 4.3

    Google Chrome versions before 150.0.7871.47 contain a flaw that allows malicious browser extensions to trick users visually by displaying fake UI elements. An attacker must first convince a user to install a malicious extension, but once installed, the extension can spoof Chrome's user interface to deceive the user. This is classified as a medium-severity issue because it requires user interaction to install the extension and doesn't directly compromise system data or functionality on its own.

  • CVE-2026-14003MEDIUM 4.3

    A flaw in how Google Chrome enforces security policies for extensions allows a malicious extension to access and leak data from websites you visit across different origins—essentially reading information it shouldn't have access to. An attacker would need to trick you into installing a malicious extension first, but once installed, the extension can quietly exfiltrate sensitive cross-origin data without additional user interaction. This affects Chrome versions before 150.0.7871.47.

  • CVE-2026-14013MEDIUM 4.3

    Google Chrome versions before 150.0.7871.47 contain a flaw in how SVG (Scalable Vector Graphics) content is handled that allows attackers to trick users through misleading visual elements on a web page. An attacker would need to host a specially crafted HTML page and convince a user to visit it; once there, the vulnerability could be exploited to display fake UI elements—such as fake login prompts or warning dialogs—that appear to come from Chrome or a trusted application. This is primarily a user-trust issue rather than a direct system compromise.

  • CVE-2026-14020MEDIUM 4.3

    A flaw in Google Chrome's WebXR implementation allows a remote attacker to trick users into thinking they're interacting with legitimate interface elements when they're actually engaging with spoofed content. The vulnerability requires the attacker to first compromise Chrome's renderer process—the component that draws web pages—and then serve a malicious webpage to execute the UI spoofing attack. While the initial compromise is a prerequisite, once achieved, users can be deceived without additional interaction beyond normal web browsing.

  • CVE-2026-14031MEDIUM 4.3

    Google Chrome versions prior to 150.0.7871.47 contain a flaw in how the file input component handles user interactions, enabling attackers to deceive users through visual spoofing attacks. A malicious HTML page can trick users into believing they are interacting with legitimate browser UI elements when they are not, potentially leading to unintended actions or credential harvesting through deceptive interface overlays.

  • CVE-2026-14034MEDIUM 4.3

    CVE-2026-14034 is a navigation-bypass vulnerability in Google Chrome's WebXR implementation on Android. An attacker can craft a malicious HTML page that, when visited by a user, circumvents browser navigation restrictions. While the underlying Chromium severity is rated Low, the CVSS score of 4.3 reflects the requirement for user interaction and limited direct impact. The vulnerability does not enable data theft or system crashes but does allow unauthorized page navigation, which could facilitate phishing or redirect attacks.

  • CVE-2026-14039MEDIUM 4.3

    CVE-2026-14039 is a same-origin policy bypass vulnerability in Google Chrome's GetUserMedia implementation. An attacker could craft a malicious HTML page to trick users into visiting it, bypassing browser protections that normally prevent one website from accessing resources or data from another website. The vulnerability affects Chrome versions before 150.0.7871.47 and requires user interaction to exploit. While Google rates it as low severity internally, the CVSS score of 4.3 reflects the integrity impact and low attack complexity.

  • CVE-2026-14042MEDIUM 4.3

    A vulnerability in Google Chrome's Isolated Web Apps feature allows attackers to deceive users through visual manipulation. By sending a specially crafted HTML page, an attacker can spoof the browser's user interface—for example, making a fake login prompt or warning appear legitimate. The attacker cannot steal data or crash the browser, but can trick users into performing actions they wouldn't normally take. This affects Chrome versions before 150.0.7871.47.

  • CVE-2026-14045MEDIUM 4.3

    A flaw in Google Chrome's network handling allows attackers who have already compromised the browser's renderer process to steal sensitive data from websites the user visits. The attacker would craft a malicious webpage designed to leak information across security boundaries that normally keep data from different websites separate. This requires the attacker to have already gained control of Chrome's rendering engine, making this a post-compromise issue rather than a remote code execution vector.

  • CVE-2026-14046MEDIUM 4.3

    A flaw in Google Chrome's CustomTabs implementation on Android allows an attacker to circumvent the same-origin policy—a fundamental browser security boundary—by crafting a malicious HTML page. While Chromium rated this as low severity, the CVSS assessment reflects a medium risk because user interaction is required to exploit it, but the integrity impact (unauthorized modification of content or state) is real. The vulnerability affects Chrome versions prior to 150.0.7871.47 on Android devices.

  • CVE-2026-14047MEDIUM 4.3

    A vulnerability in Google Chrome's extension system allows a malicious extension to bypass the browser's content security policy (CSP), a critical security boundary designed to prevent injection attacks. An attacker would need to trick a user into installing the malicious extension first, but once installed, the extension could inject or modify content in ways that CSP normally blocks. This affects Chrome versions before 150.0.7871.47.

  • CVE-2026-14052MEDIUM 4.3

    Google Chrome versions before 150.0.7871.47 contain a flaw that allows attackers to bypass file system access restrictions through a specially crafted web page. An attacker would need to trick a user into visiting a malicious site, but once there, the vulnerability could allow unauthorized file operations that would normally be blocked by the browser's security policies.

  • CVE-2026-14053MEDIUM 4.3

    A vulnerability in Google Chrome's extension policy enforcement allowed attackers who had already compromised Chrome's renderer process to steal data from websites a user was visiting, bypassing the normal cross-origin protections that keep data private between sites. The flaw required an attacker to first gain control of Chrome's rendering engine—a significant prerequisite—and then trick a user into visiting a malicious webpage. This is a localized threat that affects only users whose Chrome instances have been compromised at a deep level.

  • CVE-2026-14054MEDIUM 4.3

    Google Chrome versions prior to 150.0.7871.47 contain a flaw in how the browser enforces navigation policies. An attacker can craft a malicious HTML page that, when visited by a user, bypasses restrictions meant to control where the browser can navigate. While the underlying vulnerability is rated Low by Chromium's own assessment, it does carry integrity risk—an attacker could potentially redirect users to unintended pages or manipulate the browser's navigation behavior in ways that undermine trust in the browser's security model.

  • CVE-2026-14057MEDIUM 4.3

    A vulnerability in Google Chrome's Federated Credential Management (FedCM) implementation allows attackers to bypass the same-origin policy—a fundamental browser security boundary that prevents malicious websites from accessing data belonging to other sites. An attacker could craft a deceptive HTML page to trick users into visiting it, potentially enabling unauthorized access to credentials or identity information. The vulnerability affects Chrome versions before 150.0.7871.47 and requires user interaction to exploit.

  • CVE-2026-14058MEDIUM 4.3

    Google Chrome versions before 150.0.7871.47 contain a policy enforcement gap in its HTML parser that allows remote attackers to circumvent Content Security Policy (CSP) protections. An attacker can craft a malicious HTML page that, when visited by a user, bypasses CSP restrictions that would normally prevent inline scripts, external resource loading, or other potentially dangerous content execution. This is a client-side vulnerability requiring user interaction—a victim must visit the attacker's page for the bypass to occur.

  • CVE-2026-14066MEDIUM 4.3

    A vulnerability in Google Chrome for iOS allows attackers to bypass navigation restrictions through a specially crafted webpage. An attacker could create a malicious HTML page that, when visited by a user, circumvents Chrome's security controls that normally prevent unwanted navigation. This requires user interaction—the user must visit the malicious page—but does not require the attacker to have special privileges. The impact is limited to integrity concerns rather than data theft or system disruption.

  • CVE-2026-14072MEDIUM 4.3

    Google Chrome contains a flaw in how it implements the SplitView feature that allows attackers to trick users by making malicious web content appear as legitimate browser UI elements. An attacker hosting a specially crafted web page can exploit this to perform UI spoofing—essentially overlaying fake buttons, address bars, or other interface elements—potentially deceiving users into taking actions they didn't intend. The vulnerability requires user interaction (visiting a malicious site) to exploit and does not allow data theft or system crashes, but the deception risk is real enough to warrant attention.

  • CVE-2026-14073MEDIUM 4.3

    A flaw in Google Chrome's WebXR implementation fails to properly validate user-supplied input before processing navigation commands. An attacker can craft a malicious webpage that, when visited by a user, bypasses Chrome's navigation restrictions—allowing the page to navigate to unexpected URLs or perform unwanted redirects. The vulnerability requires user interaction (clicking or visiting the page) and affects Chrome versions prior to 150.0.7871.47. The issue stems from insufficient input sanitization in the WebXR code path, a component used for virtual and augmented reality experiences in the browser.

  • CVE-2026-14075MEDIUM 4.3

    A vulnerability in Chrome for iOS allows attackers to send HTTP requests with referrer information even when a web page has explicitly set a no-referrer policy. An attacker crafts a malicious HTML page that tricks the browser into ignoring this privacy protection, potentially leaking information about which website a user came from. This is a client-side bypass that requires user interaction—the user must visit the attacker's page—but could expose browsing patterns or sensitive context depending on the websites involved.

  • CVE-2026-14076MEDIUM 4.3

    Google Chrome versions before 150.0.7871.47 contain a weakness in how the browser enforces Content Security Policy (CSP), a security feature that restricts which resources a webpage can load. An attacker could craft a malicious HTML page that tricks the browser into loading content that should have been blocked by CSP rules, potentially allowing injection of unwanted scripts or other resources. The attack requires user interaction—the victim must visit the malicious page—but succeeds against unpatched Chrome installations on Windows, macOS, and Linux.

  • CVE-2026-14077MEDIUM 4.3

    Google Chrome on macOS contains a flaw in how it handles the Select element that allows attackers to trick users by making the browser's address bar (Omnibox) display fake URLs. An attacker would craft a malicious webpage that, when visited, could make it appear that the user is on a legitimate site when they're actually somewhere else. This is a spoofing vulnerability that relies on user interaction—the victim must visit the malicious page—but requires no special privileges to exploit.

  • CVE-2026-14079MEDIUM 4.3

    Google Chrome versions before 150.0.7871.47 contain a policy enforcement weakness that allows an attacker to bypass the same-origin policy—a core browser security boundary designed to prevent malicious websites from stealing data from legitimate ones. An attacker would need to trick a user into visiting a specially crafted webpage to exploit this flaw. Once successful, the attacker could manipulate or access content from other origins in ways the browser normally forbids, potentially enabling credential theft, session hijacking, or unauthorized access to sensitive user data across multiple websites.

  • CVE-2026-14080MEDIUM 4.3

    Google Chrome on Android versions before 150.0.7871.47 contain a flaw in the TabSwitcher component that fails to properly validate untrusted network data. An attacker can exploit this to bypass navigation restrictions—essentially forcing users to visit pages they shouldn't be able to reach—by sending specially crafted network traffic. The vulnerability requires user interaction (clicking or tapping) to trigger, but doesn't compromise data confidentiality or system availability.

  • CVE-2026-14089MEDIUM 4.3

    A flaw in Google Chrome's popup blocker allowed an attacker who had already gained control of Chrome's renderer process to trick users into seeing fake interface elements. The vulnerability stems from inadequate checking of user-supplied input, making it possible to craft a malicious webpage that displays spoofed UI when opened in the compromised renderer. This is a low-severity issue on Chromium's scale, though the CVSS rating reflects medium risk due to the user interaction required and limited scope of impact.

  • CVE-2026-14092MEDIUM 4.3

    Google Chrome versions before 150.0.7871.47 contain a privacy flaw that allows attackers positioned on a network path between a user and servers to intercept and expose data that should remain isolated between different websites. An attacker must trick or socially engineer the user into visiting a malicious page, but once that happens, the browser's normal cross-origin protections can be bypassed through crafted network traffic. The issue affects Chrome on Windows, macOS, and Linux.

  • CVE-2026-14105MEDIUM 4.3

    Google Chrome versions before 150.0.7871.47 contain a flaw in how the Speech API enforces origin policies. An attacker can craft a malicious web page that tricks the browser into allowing cross-origin access to speech functionality when it shouldn't. While the browser's Chromium team rated this as low severity, the impact is integrity-focused—an attacker could manipulate speech data or interactions across origin boundaries, potentially affecting users of web applications that rely on the Speech API.

  • CVE-2026-14110MEDIUM 4.3

    Google Chrome versions before 150.0.7871.47 contain a vulnerability in the Dark Mode feature that allows an attacker to deceive users through crafted web pages. By manipulating how Dark Mode renders interface elements, an attacker could trick users into believing they are interacting with legitimate browser controls or content when they are not. This is a client-side UI spoofing vulnerability that requires user interaction to exploit.

  • CVE-2026-14116MEDIUM 4.3

    Google Chrome versions before 150.0.7871.47 contain a vulnerability in the Developer Tools (DevTools) feature that can expose sensitive data across different websites. The flaw occurs because Chrome fails to properly validate user input within DevTools. An attacker can craft a malicious webpage that, if a user interacts with it in a specific way while DevTools is active, could leak information that should remain isolated between different websites. This is a user-interaction attack—the victim must perform deliberate actions for the vulnerability to be exploited.

  • CVE-2026-14123MEDIUM 4.3

    Chrome on iOS versions before 150.0.7871.47 contain a flaw in how the browser's address bar (Omnibox) displays security information. An attacker can craft a malicious webpage that tricks the browser into showing a fake URL in the address bar, making it appear as though you're visiting a legitimate site when you're actually on an attacker's domain. This is a spoofing vulnerability that exploits the visual trust signals users rely on to verify they're on the correct website.