By vendor

Google vulnerabilities

Known CVEs affecting Google products, prioritized by severity, with SEC.co remediation and detection guidance.

1195 published vulnerabilities · page 12 of 12

  • CVE-2026-14126MEDIUM 4.3

    Google Chrome on Android has a flaw in how it displays security information to users. An attacker could create a malicious webpage that tricks users into thinking they're visiting a legitimate website when they're actually on the attacker's site. This happens because Chrome isn't properly validating or displaying domain information in certain scenarios. The vulnerability requires user interaction—specifically clicking a link or visiting a crafted page—but doesn't directly expose sensitive data or break the browser's core security model.

  • CVE-2026-14127MEDIUM 4.3

    Google Chrome versions prior to 150.0.7871.47 contain a flaw in how the browser handles printing functionality that could allow an attacker to trick users into believing they are interacting with legitimate content when they are not. The vulnerability requires the attacker to have first compromised the Chrome renderer process—the sandboxed component responsible for displaying web content—and then use a specially crafted webpage to create a fake or misleading user interface. While the underlying issue is classified as low severity by the Chromium project, the CVSS scoring reflects the user interaction required and the limited scope of potential impact.

  • CVE-2026-14128MEDIUM 4.3

    A flaw in Google Chrome for iOS allows attackers to trick users by making the browser's address bar (Omnibox) display a fake URL. An attacker would craft a malicious web page and trick a user into visiting it; when the user views the address bar, they see a spoofed URL instead of the actual malicious site they're on. This leverages a user interaction requirement—the victim must actively look at the URL bar—which limits the immediate risk, but the deception could enable phishing or social engineering attacks.

  • CVE-2026-14130MEDIUM 4.3

    Google Chrome versions before 150.0.7871.47 contain a flaw in the browser's address bar (Omnibox) security indicators that allows an attacker to deceive users through visual spoofing. When a user visits a malicious webpage, the attacker can craft HTML content that makes the browser's security UI display false information—such as misleading indicators about the site's legitimacy or HTTPS status. The vulnerability requires user interaction (visiting the crafted page) but does not directly compromise data confidentiality or system availability; the primary risk is user deception leading to credential theft or other social engineering attacks.

  • CVE-2026-14134MEDIUM 4.3

    Google Chrome on Android has a flaw in its Autofill feature that allows an attacker to trick users with fake interface elements on a malicious webpage. An attacker could craft a page that mimics Chrome's autofill UI to deceive users into entering or confirming sensitive information, but the attack requires user interaction and is limited to Android devices running Chrome versions before 150.0.7871.47. The vulnerability does not involve data theft or system crashes, but focuses on visual deception.

  • CVE-2026-14136MEDIUM 4.3

    Google Chrome on iOS versions before 150.0.7871.47 contain a UI spoofing vulnerability that allows attackers to deceive users through a crafted web page. The vulnerability stems from inadequate input validation, enabling malicious actors to manipulate the browser interface in ways that mislead users about the actual content or origin of what they're viewing. While the underlying severity is rated Low by Chromium, the CVSS score of 4.3 reflects the human interaction requirement and limited direct impact—this is primarily a social engineering vector rather than a system compromise threat.

  • CVE-2026-14140MEDIUM 4.3

    Google Chrome on Android versions before 150.0.7871.47 contains a vulnerability that allows attackers to deceive users through fake interface elements. An attacker can craft a malicious web page that, when visited, displays misleading UI elements—such as fake prompts, buttons, or address bars—to trick users into performing unintended actions. The vulnerability stems from insufficient validation of user-supplied input and does not require the attacker to have any special privileges or access. However, the user must actively visit a malicious page and interact with it for the attack to succeed.

  • CVE-2026-14141MEDIUM 4.3

    Google Chrome on Android has a flaw in how it displays security information when using the Document Picture-in-Picture feature. An attacker can craft a webpage that tricks users into believing they're visiting a legitimate website when they're actually on a malicious one. This happens because the security indicator that normally shows you the real domain being visited can be hidden or spoofed. The vulnerability affects Chrome versions before 150.0.7871.47 on Android devices.

  • CVE-2026-14143MEDIUM 4.3

    Google Chrome on iOS contains a flaw in how it displays password-related security warnings and UI elements. An attacker can craft a malicious webpage that tricks users into thinking they're interacting with legitimate Chrome security prompts when they're actually viewing attacker-controlled content. This UI spoofing could lead users to enter sensitive information or bypass security checks they would otherwise trust. The vulnerability affects Chrome versions before 150.0.7871.47 on Apple iOS devices.

  • CVE-2026-14410MEDIUM 4.3

    A flaw in Google Chrome's Skia graphics library (versions before 150.0.7871.46) allows an attacker who has already compromised the browser's rendering engine to trick users with fake UI elements. The attacker crafts a malicious webpage that, once loaded in an already-compromised renderer, displays spoofed interface components—such as fake address bars or security warnings—to deceive users into taking unwanted actions. The attack requires the renderer process to be compromised first, meaning this is a secondary exploitation technique rather than a standalone attack vector.

  • CVE-2026-14418MEDIUM 4.3

    A vulnerability in Google Chrome's ANGLE graphics library prior to version 150.0.7871.46 could allow an attacker to leak data from other websites if a user visits a malicious page. The issue stems from uninitialized memory being processed in a way that exposes cross-origin information. While the CVSS score is moderate (4.3), the Chromium team rated it as High severity due to the nature of cross-origin data exposure. An attacker would need to trick a user into visiting a crafted HTML page, but no special privileges are required.

  • CVE-2026-15108MEDIUM 4.3

    Google Chrome contains an integer overflow vulnerability in its Extensions API that could allow an attacker to read memory outside intended bounds. The vulnerability requires social engineering—an attacker must convince a user to install a malicious extension. Once installed, the crafted extension can exploit the flaw to access sensitive data from Chrome's memory. This is a client-side attack with medium severity, as successful exploitation depends on user interaction and results in information disclosure rather than code execution.

  • CVE-2026-15124MEDIUM 4.3

    Google Chrome versions before 150.0.7871.115 contain a weakness in how the browser enforces the same-origin policy, a critical security boundary that prevents websites from accessing data belonging to other websites. An attacker can craft a malicious HTML page that, when visited by a user, exploits this weakness to read sensitive information—such as passwords or authentication tokens—from other websites you're logged into. The attack requires user interaction (visiting the malicious page) but doesn't need any special privileges or complex technical setup.

  • CVE-2026-15130MEDIUM 4.3

    Google Chrome versions before 150.0.7871.115 contain a flaw in how the browser enforces navigation policies that could allow an attacker to bypass the site isolation security feature. Site isolation is a critical Chrome security boundary that prevents malicious websites from accessing data belonging to other sites. An attacker could exploit this by crafting a malicious HTML page and tricking a user into visiting it, potentially allowing unauthorized access to sensitive information from other websites the user is logged into.

  • CVE-2026-15131MEDIUM 4.3

    Google Chrome versions before 150.0.7871.115 contain a flaw in how the browser handles navigation that allows an attacker to bypass site isolation, a core security boundary in Chrome. By crafting a malicious HTML page, a remote attacker can trick a user into visiting it, potentially allowing unauthorized access to data from other websites the user has open. The attack requires user interaction but no special privileges. Google rates this as Medium severity.

  • CVE-2026-9907MEDIUM 4.3

    A memory read vulnerability in Google Chrome's Dawn graphics component allows attackers to access sensitive data from different website origins. An attacker can craft a malicious web page that, when visited by a user, tricks Chrome into reading memory beyond intended boundaries and leaking information from other websites the user may have open. This affects Windows systems running Chrome versions prior to 148.0.7778.216.

  • CVE-2026-9911MEDIUM 4.3

    CVE-2026-9911 is a memory safety issue in the ANGLE graphics library used by Google Chrome. When a user visits a specially crafted webpage, an attacker can read small amounts of sensitive data from the browser's memory. The vulnerability requires user interaction—visiting the malicious page—but needs no special permissions or browser configuration to exploit. While the data exposure is limited in scope, it could leak sensitive information like passwords, tokens, or cached credentials stored in memory.

  • CVE-2026-9913MEDIUM 4.3

    A flaw in the ANGLE graphics library component of Google Chrome prior to version 148.0.7778.216 could allow an attacker to access memory outside intended bounds when a user visits a malicious website. The vulnerability requires user interaction (visiting a crafted page) but does not require special privileges. Potential impacts include disclosure of sensitive information, though the attacker cannot modify data or crash the browser directly through this flaw.

  • CVE-2026-9919MEDIUM 4.3

    A WebGL processing flaw in Google Chrome for Android allows attackers to read data they shouldn't have access to by tricking users into visiting a malicious webpage. The vulnerability exists in how Chrome handles certain graphics operations and can leak information across website boundaries, but only affects the Android version of Chrome and requires user interaction to exploit.

  • CVE-2026-9921MEDIUM 4.3

    Google Chrome on Android contains a flaw in its WebGL graphics processing where memory buffers may not be properly initialized before use. An attacker can exploit this by crafting a malicious HTML page that, when visited, allows them to read sensitive information from other websites—a cross-origin data leak. The vulnerability requires user interaction (clicking a link or viewing a page) but does not require special privileges or complex attack setup.

  • CVE-2026-9929MEDIUM 4.3

    A flaw in how Google Chrome on Android handles WebGL—a technology that enables 3D graphics in web browsers—could allow an attacker to trick a user into visiting a malicious webpage and expose data from other websites the user has open. The attacker cannot force this to happen; the user must interact with the page, such as by clicking or scrolling. This is a cross-origin data leak, meaning sensitive information from one domain could become visible to JavaScript code running on an attacker's domain.

  • CVE-2026-9930MEDIUM 4.3

    An out-of-bounds write vulnerability exists in the Dawn graphics component of Google Chrome on macOS. An attacker can craft a malicious HTML page that, when viewed by a user, writes data to memory locations outside the intended bounds of a buffer. This memory corruption could allow an attacker to modify sensitive data or potentially achieve code execution, though the CVSS assessment indicates the integrity impact is limited. The vulnerability requires user interaction—the victim must visit or be directed to the malicious page—and affects Chrome versions prior to 148.0.7778.216 on macOS.

  • CVE-2026-9935MEDIUM 4.3

    CVE-2026-9935 is a memory safety issue in Google Chrome's ANGLE graphics library that allows attackers to steal sensitive data from other websites. When you visit a malicious webpage, an attacker can craft it to leak information that should be isolated to other sites you have open. The vulnerability requires user interaction—you must visit the attack page—but the bar for exploitation is otherwise low. Google has classified this as High severity internally, though the CVSS score reflects a more limited scope.

  • CVE-2026-9943MEDIUM 4.3

    A memory access flaw in Google Chrome's WebGL implementation on Android allows attackers to read data from other websites through a specially crafted web page. When a user visits the malicious page, the attacker can extract information (such as authentication tokens, session cookies, or sensitive content) from sites the user is logged into. This is a cross-origin data leak—meaning the attacker can access information meant to be isolated to other domains.

  • CVE-2026-9955MEDIUM 4.3

    A vulnerability in Google Chrome on iOS versions before 148.0.7778.216 allows attackers to extract sensitive information from websites the user visits. An attacker would craft a malicious webpage and trick a user into visiting it; the page can then read data intended to be private to other websites. This is a cross-origin data leak—a violation of the browser's same-origin policy that normally prevents websites from accessing each other's information.

  • CVE-2026-12453MEDIUM 4.2

    Google Chrome versions before 149.0.7827.155 contain a flaw where insufficient input validation allows an attacker who has already compromised the browser's renderer process to circumvent the same-origin policy through a specially crafted webpage. This means a sandboxed renderer could potentially access or modify data from websites it should not be able to reach, though the attacker must first gain control of the renderer itself—a significant prerequisite.

  • CVE-2026-12456MEDIUM 4.2

    A vulnerability in how Google Chrome handles extensions before version 149.0.7827.155 allows a malicious extension to bypass the same-origin policy, which normally prevents web pages from accessing data belonging to other websites. An attacker would need to trick a user into installing a specially crafted malicious extension. If successful, the extension could read or modify sensitive information from other websites the user visits. This is a user-consent attack—the user must be socially engineered into installing the extension first.

  • CVE-2026-12457MEDIUM 4.2

    Google Chrome versions prior to 149.0.7827.155 contain a flaw in how extensions are implemented that allows an attacker who has already compromised Chrome's renderer process to escape the site isolation sandbox and access content from different websites. Site isolation is Chrome's core defense that prevents malicious code running on one site from stealing data from another. This vulnerability requires the attacker to have already gained code execution in the renderer—a significant prerequisite—but if achieved, it undermines that critical isolation boundary.

  • CVE-2026-12460MEDIUM 4.2

    Google Chrome versions prior to 149.0.7827.155 contain a weakness in how the browser enforces file system access policies. An attacker who has already compromised Chrome's renderer process (the part that executes web content) can exploit this flaw by serving a specially crafted PDF file to bypass Site Isolation—Chrome's security feature that isolates web content from different sites. The vulnerability requires both an existing renderer compromise and user interaction, limiting its standalone exploitability but reflecting a real protection gap once a renderer is already under attacker control.

  • CVE-2026-13024MEDIUM 4.2

    Google Chrome versions prior to 149.0.7827.197 contain a flaw in how it validates user input during navigation operations. An attacker who has already compromised Chrome's renderer process—the component that interprets and displays web content—can exploit this weakness to bypass Chrome's site isolation security feature. Site isolation is a critical defense that prevents malicious websites from accessing data belonging to other sites. This vulnerability requires an attacker to have already gained control of the renderer process, making it a secondary attack that follows initial compromise.

  • CVE-2026-13857MEDIUM 4.2

    A flaw in Google Chrome's geometry rendering engine allows an attacker to trick users into performing specific on-screen gestures—such as clicking or dragging in particular areas—which enables UI spoofing. By hosting a malicious HTML page, an attacker can make the browser display fake interface elements that appear legitimate, potentially deceiving users into taking unintended actions. The vulnerability requires user interaction and affects Chrome versions before 150.0.7871.47.

  • CVE-2026-13860MEDIUM 4.2

    Google Chrome on Windows contains a flaw in its Autofill security user interface that allows an attacker to trick users into performing specific gestures on a malicious webpage, resulting in UI spoofing. The vulnerability requires user interaction and does not lead to information disclosure, but can allow an attacker to manipulate what appears on screen or degrade application availability. Chrome versions prior to 150.0.7871.47 on Windows are affected.

  • CVE-2026-13895MEDIUM 4.2

    Google Chrome's autofill feature contained a flaw that could allow an attacker to trick users into performing specific actions on a malicious webpage, creating a false appearance of legitimate browser or website content. The vulnerability requires user interaction and is considered moderately severe. Google Chrome versions prior to 150.0.7871.47 are affected.

  • CVE-2026-13905MEDIUM 4.2

    Google Chrome for iOS contains a race condition that could allow an attacker with physical access to an iOS device to read sensitive information from the browser's process memory. The vulnerability requires the attacker to be present at the device and involves timing-sensitive manipulation, making opportunistic exploitation difficult. This affects Chrome versions before 150.0.7871.47 on iOS.

  • CVE-2026-13907MEDIUM 4.2

    Google Chrome on iOS contains a user interface spoofing vulnerability that could allow an attacker to deceive users into believing they are interacting with legitimate content when they are not. The vulnerability requires the attacker to convince a user to perform specific gestures on a crafted webpage, but does not require the user to have special privileges or for the attacker to have prior network access. Patches are available in Chrome 150.0.7871.47 and later.

  • CVE-2026-13956MEDIUM 4.2

    Google Chrome versions before 150.0.7871.47 contain a flaw in how the PageInfo security UI displays information to users. An attacker can craft a malicious HTML page that, when shown to a user alongside specific browser interactions, tricks the user into believing they're interacting with legitimate security information. The attacker must convince the user to perform certain UI gestures to make the spoofing work. The impact is limited to tampering with what the user sees on screen, not to stealing data or causing system crashes.

  • CVE-2026-13957MEDIUM 4.2

    Google Chrome versions before 150.0.7871.47 contain a security UI flaw in its Extensions feature that allows attackers to execute unauthorized scripts or inject HTML content into web pages—a technique called Unsafe Cross-Site Scripting (UXSS). The attack requires two conditions: first, an attacker must trick a user into installing a malicious browser extension, and second, the user must visit a specially crafted webpage. Once those conditions are met, the attacker gains the ability to run arbitrary code within the browser's rendering context.

  • CVE-2026-13973MEDIUM 4.2

    Google Chrome versions before 150.0.7871.47 contain a UI implementation flaw that allows attackers to display fake interface elements—like fake login prompts or warning dialogs—if they can trick users into specific mouse or keyboard interactions on a malicious website. The attacker cannot steal data directly, but can confuse users into revealing passwords or credentials by making the fake UI look legitimate.

  • CVE-2026-13983MEDIUM 4.2

    A vulnerability in Chrome on iOS allows attackers to trick users into believing they are visiting a legitimate website by spoofing the Omnibox (the URL bar that displays the website address). An attacker would need to convince a user to perform specific UI gestures—such as particular taps or swipes—on a crafted webpage to trigger the spoofing. The attack does not grant access to sensitive data but can mislead users about which site they are actually visiting, potentially leading to credential theft or other social engineering attacks. This affects Chrome for iOS versions prior to 150.0.7871.47.

  • CVE-2026-13986MEDIUM 4.2

    A flaw in Google Chrome's Media UI on ChromeOS allows an attacker to deceive users through visual spoofing. By crafting a malicious webpage and convincing a user to perform specific gestures (such as clicks or interactions with media controls), an attacker can make the browser display fake UI elements that trick the user into taking unintended actions. This is a user-interaction dependent vulnerability with limited scope—it doesn't enable direct system compromise but can facilitate phishing, credential theft, or social engineering attacks.

  • CVE-2026-13992MEDIUM 4.2

    Google Chrome on macOS contains a UI implementation flaw that allows attackers to create convincing fake interface elements—a technique known as UI spoofing. An attacker would need to host a malicious webpage and convince a user to interact with specific interface elements in a particular way to trigger the vulnerability. The flaw affects Chrome versions prior to 150.0.7871.47 on macOS. While the attack requires user interaction and deliberate UI manipulation, it can lead to confusion about application state or permissions, potentially tricking users into unintended actions.

  • CVE-2026-13993MEDIUM 4.2

    Google Chrome versions before 150.0.7871.47 contain a flaw in how it displays security warnings during Web App installation. An attacker can craft a malicious webpage that, when a user performs specific interactions (like clicking or gesturing in a particular way), tricks the browser into displaying a misleading security UI. This allows the attacker to spoof a domain—making it appear that a trusted site is actually the attacker's site—potentially deceiving users into entering credentials or trusting malicious content. The attack requires deliberate user interaction and doesn't directly compromise data or system availability, but it can deceive users about what website they're interacting with.

  • CVE-2026-13997MEDIUM 4.2

    Google Chrome on Android contains a flaw in how it displays security warnings for browser extensions. An attacker can craft a malicious webpage that tricks users into performing certain taps or swipes, making the extension security UI appear different than it actually is. This deception (called UI spoofing) could lead users to install or interact with harmful extensions without realizing the danger. The vulnerability requires the attacker to convince a user to perform specific gestures, which makes it moderately difficult to exploit in the wild.

  • CVE-2026-13998MEDIUM 4.2

    Google Chrome on macOS contains a flaw in how it displays security warnings when users interact with file input controls. An attacker could craft a deceptive web page that, when a user performs certain mouse or keyboard actions, disguises malicious activity as a legitimate system dialog. This allows the attacker to trick users into believing they are interacting with Chrome's genuine security interface rather than attacker-controlled content. The vulnerability requires user interaction and specific gestures to exploit, limiting its immediate risk but still representing a meaningful social engineering vector.

  • CVE-2026-14026MEDIUM 4.2

    Google Chrome versions before 150.0.7871.47 contain a UI security flaw in the SplitView feature that allows an attacker to trick users into performing certain click or gesture actions on a specially crafted webpage. When exploited, the vulnerability enables UI spoofing—displaying false security indicators or interface elements that mislead the user about what is actually happening in the browser. This could be used in social engineering attacks where an attacker makes the browser appear to show something it isn't, such as a fake security warning or address bar state.

  • CVE-2026-14028MEDIUM 4.2

    A flaw in Chrome for iOS versions before 150.0.7871.47 can be exploited to show users fake security or interface elements. An attacker would need to craft a malicious webpage and convince the user to perform specific touch gestures—such as tapping in particular ways—to trigger the spoofing. The vulnerability doesn't directly steal data or crash the browser, but it could deceive users into thinking they're interacting with legitimate Chrome UI when they're actually viewing attacker-controlled content.

  • CVE-2026-14030MEDIUM 4.2

    A vulnerability in Google Chrome's SplitView feature on Linux allows an attacker to trick users into believing they are visiting a legitimate website by spoofing the address bar. This happens when a user performs certain UI interactions with a malicious webpage. The flaw affects Chrome versions before 150.0.7871.47 and requires user interaction to exploit, making it a limited but real risk to users who fall for social engineering.

  • CVE-2026-14129MEDIUM 4.2

    Google Chrome on Android contains a flaw in how it displays the preview tab interface that allows an attacker to trick users into thinking they're interacting with legitimate content when they're actually looking at a spoofed version. An attacker would need to craft a malicious webpage and convince a user to perform specific touch gestures (like swiping or tapping in particular ways) to trigger the vulnerability. The impact is limited but real: users could be misled about what content they're viewing or interacting with.

  • CVE-2026-14133MEDIUM 4.2

    A race condition in Google Chrome's history embeddings feature could allow an attacker to trick users into seeing fake browser UI elements through a specially crafted webpage. The vulnerability requires user interaction and is difficult to exploit reliably, but successful exploitation could lead to minor information disclosure or allow the attacker to manipulate what the user sees on screen. Chrome versions before 150.0.7871.47 are affected.

  • CVE-2026-14137MEDIUM 4.2

    A vulnerability in Chrome for iOS allows attackers to trick users into performing specific gestures on a crafted webpage, resulting in fake UI elements appearing to come from Chrome itself. This 'UI spoofing' attack could mislead users about the source or nature of content they're interacting with, though the underlying browser functionality and user data remain protected. The attack requires user interaction and is rated Medium severity.

  • CVE-2026-14138MEDIUM 4.2

    Google Chrome on Windows contains a UI spoofing vulnerability in its WebAppInstalls feature that could allow an attacker to deceive users through a specially crafted webpage. The vulnerability requires user interaction—specifically, deliberate UI gestures—to be exploited. While the underlying implementation flaw is considered low severity by Google, the CVSS scoring reflects the potential for integrity and availability impacts when successfully exploited.

  • CVE-2026-14139MEDIUM 4.2

    Google Chrome versions prior to 150.0.7871.47 contain a UI spoofing vulnerability in the TabStrip component that could allow an attacker to deceive users through a malicious webpage. The attack requires the victim to perform specific user interface gestures—such as particular mouse or keyboard interactions—making it less likely to succeed in practice than attacks that trigger automatically. The vulnerability affects Chrome across Windows, macOS, and Linux systems.

  • CVE-2026-14144MEDIUM 4.2

    Google Chrome versions before 150.0.7871.47 contain a flaw in how the browser renders security-related UI elements in the Views framework. An attacker could craft a malicious webpage that, when viewed by a user who performs certain mouse or keyboard interactions, tricks the user into believing they are interacting with legitimate browser UI (like permission dialogs or address bar elements) when they are actually interacting with attacker-controlled content. This is a UI spoofing vulnerability that relies on convincing users to take specific actions on a specially crafted page.

  • CVE-2026-9986MEDIUM 4.2

    CVE-2026-9986 is a UI spoofing vulnerability in Google Chrome's OptimizationGuide component that could let an attacker deceive users about what they're seeing on a webpage. The vulnerability requires the attacker to have already compromised Chrome's rendering process—the engine that draws web content. While this limits the immediate attack scope, it represents a meaningful escalation risk for adversaries who have achieved code execution in that sandboxed component. The flaw stems from inadequate validation of user-supplied input before it's used to generate on-screen elements.

  • CVE-2026-10998MEDIUM 4.0

    CVE-2026-10998 is a memory safety issue in Google Chrome's media handling code that allows an attacker positioned on the same local network to read data from memory locations they shouldn't have access to. The vulnerability exists in Chrome versions before 149.0.7827.53. An attacker would need to send specially crafted network traffic to trigger an out-of-bounds read, which could potentially expose sensitive information resident in the browser's memory. This is a local-network-only threat, meaning the attacker must be on your network segment to exploit it.

  • CVE-2026-28581MEDIUM 4.0

    A logic error in Android's call processing code allows an application to initiate emergency calls without proper authorization checks. The vulnerability stems from inadequate validation in the CallIntentProcessor when determining the initiating user, potentially enabling an app to trigger emergency dialing functionality that should be restricted. No user interaction is required for exploitation, and the issue affects multiple Android versions.

  • CVE-2026-0129LOW 3.5

    A missing bounds check in Android's RTCP (Real-time Transport Control Protocol) Bye packet decoder can expose sensitive information to an authenticated attacker. The vulnerability requires user interaction to trigger and affects only confidentiality; no system crash or modification is possible. This is a low-severity information disclosure issue that primarily concerns privacy of real-time communications data.

  • CVE-2026-0130LOW 3.5

    CVE-2026-0130 is a low-severity vulnerability affecting Google Android that allows an attacker to read sensitive data from device memory through a malformed network packet. The flaw exists in the RtcpChunk decoder, which fails to properly validate buffer boundaries before reading data. An attacker must trick a user into accepting or opening a specially crafted media stream or communication session to trigger the vulnerability. Successful exploitation results in disclosure of locally stored information but does not enable device compromise, privilege escalation, or data modification.

  • CVE-2025-48616LOW 3.3

    CVE-2025-48616 is a logic error in Android's KeyguardViewMediator that allows a local attacker with basic user privileges to bypass lockdown mode when screen pinning is active, potentially exposing sensitive information on the device. The vulnerability requires no user interaction and poses a localized risk to data confidentiality on affected Android devices.

  • CVE-2026-0016LOW 3.3

    A permissions validation flaw in Android's credential management system allows a local attacker with limited user privileges to read sensitive information across other user accounts without special permissions or user interaction. The vulnerability resides in how the system handles credential provider updates when services are removed, creating a bypass that exposes data intended to be isolated between users.

  • CVE-2026-0050LOW 3.3

    CVE-2026-0050 is a local information disclosure vulnerability in Android's Bluetooth adapter service. A malicious app with basic user-level permissions can bypass security checks in the handleBondStateChanged function to read sensitive Bluetooth-related information without requiring additional privileges or user interaction. The impact is limited to information disclosure; the attacker cannot modify data or crash the system.

  • CVE-2026-0056LOW 3.3

    CVE-2026-0056 is a memory safety issue in Android's ResourceTypes.cpp component where an incorrect bounds check allows a local process to read data outside intended memory boundaries. This flaw exposes sensitive information resident in adjacent memory to any app with basic local access—no special permissions, elevated privileges, or user interaction required. The vulnerability is classified as low severity due to its limited scope and local-only nature.

  • CVE-2026-0057LOW 3.3

    A permissions enforcement gap in Android's Contacts Provider allows local applications to view incoming call phone numbers and related metadata without explicit authorization. The issue requires local access to the device but no special privileges or user action during exploitation, making it a concern for applications that should be restricted from call monitoring data.

  • CVE-2026-0134LOW 3.3

    A logic error in Android's factory reset process allows sensitive data to persist on the device after a reset completes. An attacker with local access to the device can read this leftover information without needing special privileges or user interaction. While the exposure is limited to local information disclosure, the issue is particularly concerning because factory reset is a key data-wiping mechanism users rely on before selling, donating, or recycling devices.

  • CVE-2026-0142LOW 3.3

    CVE-2026-0142 is a local information disclosure vulnerability in Android's AVB (Android Verified Boot) RSA key parsing code. A local user can trigger an out-of-bounds memory read by supplying malformed key data, potentially exposing sensitive information from adjacent memory. The flaw requires only local access and user-level privileges—no special permissions or user interaction is required to exploit it.

  • CVE-2026-0145LOW 3.3

    CVE-2026-0145 is a permission bypass vulnerability in Android's KeyMint component that allows a local attacker with basic user privileges to read sensitive information without needing to interact with the system or escalate their access level. The flaw stems from a logic error in how permissions are validated, creating an unintended pathway for unauthorized data access.

  • CVE-2026-0158LOW 3.3

    A flaw in Android's Camera application allows a local user to view photos they shouldn't be able to access. The vulnerability stems from missing permission validation when accessing photo data. Since no special privileges or user interaction are required beyond initial device access, any app or user account on the device could potentially read private photos. The actual impact is limited to unauthorized photo disclosure—the vulnerability doesn't enable device compromise or broader system damage.

  • CVE-2026-13942LOW 3.3

    A vulnerability in Google Chrome's video capture implementation on ChromeOS allows a local attacker to create fake UI elements through a specially crafted web page. The attacker must already have local access to the device and the user must interact with the malicious page, but the attack only affects the visual presentation of the interface—it cannot steal data or crash the system.

  • CVE-2026-13955LOW 3.3

    Google Chrome on Android contains a UI spoofing vulnerability in its CustomTabs feature that could allow a local attacker to deceive users by manipulating the app's visual appearance. The vulnerability stems from insufficient validation when processing untrusted input from malicious files. An attacker would need local access to the device and user interaction (such as opening a file) to exploit it. The attack surface is limited because it requires both proximity and user action, and the impact is restricted to visual deception rather than data theft or system compromise.

  • CVE-2026-15115LOW 3.3

    A vulnerability in Google Chrome on Android allows a local attacker to bypass the same-origin policy—a core browser security feature that prevents websites from accessing data from other origins—through a specially crafted HTML page. The issue stems from insufficient validation of user-supplied input in the WebAppInstalls component. An attacker with local access to the device would need to trick a user into visiting a malicious webpage to exploit this. The vulnerability was patched in Chrome version 150.0.7871.115.

  • CVE-2026-21034LOW 3.3

    Samsung Auto versions prior to 3.1.2.61 (Android 15) and 3.2.0.38 (Android 16) contain a flaw that improperly exposes application components. A local attacker with user-level access can exploit this exposure to modify audio settings without user consent. The vulnerability is rated LOW severity and does not affect confidentiality or system availability, only the integrity of audio configuration.

  • CVE-2026-28586LOW 3.3

    CVE-2026-28586 is a local information disclosure vulnerability in Android's AppOpsService that allows an already-authenticated user to bypass permission checks and read sensitive data they shouldn't have access to. The flaw requires the attacker to already have a local account on the device; there's no way to exploit it remotely. The exposure is classified as low-severity because the data leaked is limited and no system functions are disrupted.

  • CVE-2026-10011LOW 3.1

    A flaw in Chrome's Skia graphics library could allow an attacker who has already compromised Chrome's renderer process to extract sensitive data from websites you visit. The attacker would need to serve you a specially crafted web page to perform the attack. While the underlying issue received a High severity rating from Chromium, the overall exploitability is limited because it requires both renderer compromise and user interaction, making it a low-risk vulnerability in practical terms.

  • CVE-2026-11240LOW 3.1

    CVE-2026-11240 is a low-severity input validation flaw in Google Chrome's Loader component that allows a remote attacker to bypass the browser's site isolation security feature, but only if they have already compromised the renderer process. Site isolation is Chrome's defense mechanism that runs each website in a separate process to prevent one compromised site from accessing data from another. An attacker would need to deliver a specially crafted HTML page to exploit this, making it a post-compromise risk rather than a direct remote code execution vector. The vulnerability affects Chrome versions prior to 149.0.7827.53.

  • CVE-2026-11244LOW 3.1

    CVE-2026-11244 is a low-severity flaw in Google Chrome's WebAuthentication feature that allows inadequate validation of user-supplied input. An attacker with prior access to Chrome's renderer process—the component responsible for displaying web pages—could craft a malicious HTML page to circumvent the browser's same-origin policy, a fundamental security boundary that prevents scripts from one website accessing data from another. This is not a direct remote code execution and requires both renderer process compromise and user interaction to succeed.

  • CVE-2026-11247LOW 3.1

    A flaw in Google Chrome's CustomTabs feature on Android allows an attacker to leak data across website boundaries through a specially crafted webpage. The vulnerability requires user interaction and is difficult to exploit, affecting Android devices running Chrome versions before 149.0.7827.53. While the risk is low, it represents a potential privacy leak in a widely used mobile browser component.

  • CVE-2026-11251LOW 3.1

    A flaw in Chrome's password manager allows a sophisticated attacker to read stored password information if they can first compromise Chrome's renderer process through a malicious web page. The vulnerability requires multiple conditions to exploit: the attacker must already control the rendering engine, the user must interact with the page, and the attack surface is limited to sensitive credential disclosure. Chrome versions before 149.0.7827.53 are affected. This is not a zero-click issue and does not allow code execution or system-level access.

  • CVE-2026-11675LOW 3.1

    Google Chrome contained a memory reading vulnerability in its Skia graphics library that could allow an attacker to steal sensitive data from other websites. The attacker would first need to compromise Chrome's renderer process—the sandboxed component that handles web page rendering—and then trick a user into visiting a specially crafted webpage. If successful, the flaw could leak cross-origin data, meaning information from a different website than the one the user thought they were visiting. This vulnerability affects Chrome versions prior to 149.0.7827.103 across Windows, macOS, and Linux systems.

  • CVE-2026-11684LOW 3.1

    A policy enforcement gap in Google Chrome's Network component allowed attackers who had already compromised Chrome's utility process to steal cross-origin data by serving a specially crafted HTML page. This is a post-compromise attack where the attacker has already gained some level of access to the browser process itself, then exploits this weakness to read data that should be isolated between different websites.

  • CVE-2026-11686LOW 3.1

    A flaw in Google Chrome's Dawn graphics library on macOS allows an attacker who has already compromised the browser's renderer process to trick the system into leaking data from other websites. The vulnerability requires the attacker to already have control over the renderer and the user to interact with a malicious webpage, making it a limited but real risk in scenarios where renderer escapes are already being exploited.

  • CVE-2026-11691LOW 3.1

    Google Chrome contained a flaw in its New Tab Page that could allow attackers who had already compromised Chrome's renderer process to steal data from websites across different origins. The vulnerability required an attacker to have already broken into the renderer—the sandboxed component that runs web content—and then trick a user into visiting a malicious HTML page. While the Chromium security team rated this High severity internally, the calculated CVSS score is Low (3.1) because the attack requires both prior renderer compromise and user interaction.

  • CVE-2026-12017LOW 3.1

    Google Chrome versions before 149.0.7827.115 contain a flaw in how browser extensions are implemented that could allow an attacker who has already compromised Chrome's rendering engine to escape site isolation—the security boundary that prevents malicious websites from accessing data belonging to other websites. The attacker would need to trick a user into viewing a specially crafted webpage, but the core vulnerability requires prior control of the renderer process, which significantly limits real-world attack scope.

  • CVE-2026-12032LOW 3.1

    Google Chrome on Android versions prior to 149.0.7827.115 contain a flaw in how the browser handles password-related features that could allow an attacker to bypass site isolation protections. Site isolation is a critical Chrome security feature that prevents malicious websites from accessing data from other sites. To exploit this issue, an attacker would first need to compromise Chrome's rendering engine through another vulnerability, then use a specially crafted webpage to break site isolation. While this requires multiple attack prerequisites, the underlying flaw affects password handling and could expose cross-site data to compromised processes.

  • CVE-2026-12458LOW 3.1

    Google Chrome versions before 149.0.7827.155 contain a flaw in how the browser handles password-related features that could allow an attacker to extract sensitive data from websites the user has visited. The vulnerability requires an attacker to trick a user into performing specific interactions—such as clicking or gesturing—on a malicious webpage. When exploited, it may leak information that should remain isolated between different websites, but only within the user's current browsing session. The severity is considered low because it demands active user participation and the exposed data scope is limited.

  • CVE-2026-13939LOW 3.1

    A flaw in Google Chrome's WebShare feature on Android devices could allow an attacker who has already compromised the browser's rendering engine to trick users into thinking they are interacting with legitimate interface elements when they are actually seeing forged content. The vulnerability requires the attacker to have significant pre-existing access to the browser process and relies on user interaction, making it a limited-impact issue in practice.

  • CVE-2026-13944LOW 3.1

    Google Chrome on macOS contains a flaw in how it handles data transfers that could allow an attacker to trick users into exposing information across website boundaries. The vulnerability requires the attacker to convince the user to perform specific interactions with a malicious webpage. This is a low-severity issue affecting Chrome versions before 150.0.7871.47 on Mac systems.

  • CVE-2026-13945LOW 3.1

    This vulnerability affects Google Chrome on Linux systems and involves insufficient controls over how browser extensions are validated. An attacker could create a malicious extension that, once installed by a user, could perform UI spoofing—essentially creating fake interface elements that trick users into thinking they're interacting with legitimate Chrome features. The vulnerability requires user action (installing the extension) to be exploited, making it a social engineering vector rather than a direct technical flaw. Google has addressed this issue in Chrome version 150.0.7871.47 and later.

  • CVE-2026-13948LOW 3.1

    Google Chrome versions prior to 150.0.7871.47 contain a flaw in how it enforces policies on browser extensions. An attacker could convince a user to install a malicious extension, then use that extension to create fake or spoofed user interface elements—making it appear as though the user is interacting with legitimate Chrome features when they are actually engaging with attacker-controlled content. This is a social engineering attack that relies on initial user action to install the extension.

  • CVE-2026-13963LOW 3.1

    A vulnerability in Google Chrome's developer tools allows an attacker to trick users into revealing sensitive information from other websites through a specially crafted web page. The attack requires the user to perform specific interactions with Chrome's UI, such as clicking or dragging elements in a particular way. While the risk is considered low due to these interaction requirements and the limited scope of data exposure, organizations should still apply the patch to eliminate the attack surface.

  • CVE-2026-13982LOW 3.1

    Google Chrome's password manager UI can be spoofed by attackers who have already compromised the browser's rendering engine. An attacker who gains control of the renderer process—the component responsible for displaying web content—can craft a malicious HTML page that mimics legitimate Chrome password UI elements, potentially deceiving users into revealing credentials or performing unintended actions. This requires prior compromise of the renderer, which is a significant prerequisite but still represents a real escalation risk once initial access is achieved.

  • CVE-2026-9920LOW 3.1

    Google Chrome on Android contains a vulnerability in GPU memory handling that could allow an attacker who has already compromised the browser's renderer process to access sensitive data from websites that should be isolated from each other. The vulnerability stems from uninitialized memory in the GPU code path, which under specific conditions could leak cross-origin data through a malicious webpage. This requires the renderer process to be compromised first, making it a secondary exploitation step rather than a direct entry point.

  • CVE-2026-9944LOW 3.1

    CVE-2026-9944 is a memory safety issue in the ANGLE graphics library used by Google Chrome. An attacker who has already compromised Chrome's renderer process can craft a malicious webpage to leak sensitive data from other websites or origins. The vulnerability requires the renderer to be compromised first, limiting the attack surface, but the data leakage potential is real once that initial foothold exists. Chrome versions before 148.0.7778.216 are vulnerable on Windows, macOS, and Linux.

  • CVE-2026-9950LOW 3.1

    A same-origin policy bypass vulnerability exists in Google Chrome on iOS versions prior to 148.0.7778.216. The flaw stems from insufficient validation of untrusted input that allows an attacker who has already compromised Chrome's renderer process to craft a malicious HTML page that circumvents browser security boundaries. This means an attacker could potentially access data or perform actions from a different website origin than the one a user is visiting, but only if the renderer process has already been compromised through another attack vector.

  • CVE-2026-9959LOW 3.1

    A race condition in WebRTC functionality within Google Chrome on Windows allows an attacker to leak data across origin boundaries. The vulnerability requires user interaction (clicking on a crafted HTML page) and is difficult to exploit reliably due to timing constraints. While the underlying issue is rated High severity by Chromium, the CVSS 3.1 score of 3.1 reflects the practical barriers to exploitation and limited scope—an attacker can extract sensitive information, but cannot modify data or disrupt service.

  • CVE-2026-9991LOW 3.1

    A vulnerability in Google Chrome's media handling on Windows allows an attacker who has already compromised the browser's renderer process to extract sensitive data across security boundaries. The attacker would need to host a malicious webpage and trick a user into visiting it while the renderer is already under their control. The exposure is information disclosure—no system takeover or crashes—and the barrier to exploitation is relatively high because the attacker must first achieve renderer compromise.