By vendor
Google vulnerabilities
Known CVEs affecting Google products, prioritized by severity, with SEC.co remediation and detection guidance.
1195 published vulnerabilities · page 2 of 12
- CVE-2026-11124HIGH 8.8
A memory handling flaw in Chrome's Skia graphics library allows attackers to trigger heap corruption by serving a specially crafted webpage. The vulnerability requires user interaction (visiting a malicious page) but needs no special privileges and works across all major operating systems where Chrome runs. An attacker could achieve code execution with full system access—reading files, modifying data, installing malware, or pivoting to other systems.
- CVE-2026-11125HIGH 8.8
A use-after-free memory flaw in Google Chrome's compositing system allows attackers to run arbitrary code within Chrome's sandbox by tricking users into visiting a malicious webpage. The vulnerability affects Chrome versions before 149.0.7827.53 across Windows, macOS, and Linux. While contained by the sandbox, successful exploitation could grant an attacker the same privileges as the Chrome process, potentially compromising sensitive browser data and operations.
- CVE-2026-11130HIGH 8.8
A use-after-free vulnerability in Google Chrome's media handling allows attackers to run malicious code within Chrome's sandbox by tricking users into visiting a specially crafted website. While the underlying Chromium project rates this as Medium severity, the CVSS score of 8.8 reflects the practical risk: it requires user interaction (clicking a link or visiting a site), but once triggered, it can lead to full compromise of the Chrome process, potentially exposing sensitive data or enabling further attacks on the underlying system.
- CVE-2026-11136HIGH 8.8
Google Chrome versions prior to 149.0.7827.53 contain a use-after-free vulnerability in the Canvas component that allows attackers to execute arbitrary code within the browser sandbox. An attacker can exploit this flaw by crafting a malicious HTML page that, when visited by a user, triggers memory corruption and leads to code execution. The vulnerability requires user interaction (visiting a webpage) but needs no special privileges to trigger.
- CVE-2026-11144HIGH 8.8
A use-after-free memory flaw in Google Chrome's media handling allows an attacker to execute malicious code within Chrome's sandbox by tricking a user into opening a specially crafted video file. While sandboxed, successful exploitation could still grant an attacker significant control over the affected browser process and potentially access to sensitive user data.
- CVE-2026-11147HIGH 8.8
A use-after-free vulnerability exists in Chrome's WebML (Web Machine Learning) component on Windows. An attacker can craft a malicious HTML page that, when visited by a user, triggers code execution within Chrome's sandbox. Although the sandbox contains the damage, the vulnerability allows an attacker to breach browser process isolation and execute arbitrary code with the privileges of the Chrome renderer process.
- CVE-2026-11164HIGH 8.8
A use-after-free vulnerability exists in Blink, Google Chrome's rendering engine, affecting versions prior to 149.0.7827.53. An attacker can craft a malicious HTML page that, when visited by a user, exploits this memory safety flaw to execute arbitrary code within the Chrome sandbox. While sandboxed, successful exploitation grants an attacker code execution capabilities on the victim's machine, potentially enabling further compromise.
- CVE-2026-11171HIGH 8.8
A flaw in Blink, the rendering engine behind Google Chrome, allows attackers to trigger an integer overflow by sending a specially crafted web page. If a user visits a malicious site, the attacker can run malicious code within Chrome's sandbox. While the sandbox limits damage, this vulnerability bypasses a critical security boundary and is rated HIGH severity.
- CVE-2026-11172HIGH 8.8
A UI spoofing flaw in Chrome's Contact Picker on Android allows attackers to trick users via specially crafted web pages. When a user attempts to select a contact, a malicious site can mask its true identity or intentions by manipulating the security UI elements that normally help users understand what app or service is asking for contact information. This deceives users into granting access to their contacts under false pretenses.
- CVE-2026-11173HIGH 8.8
A memory writing vulnerability in Google Chrome's V8 JavaScript engine (used to execute web code) allows a specially crafted webpage to trigger an out-of-bounds write operation. An attacker who has already compromised the browser's rendering process can exploit this flaw to break out of the sandbox and run arbitrary code with the privileges of the Chrome process. This requires an attacker to first gain control of the renderer, making it a post-compromise escalation vector rather than a direct entry point.
- CVE-2026-11175HIGH 8.8
Google Chrome on Android contains a flaw in how it displays security-related UI elements within the Messages feature. An attacker can craft a malicious webpage that tricks users into thinking they're interacting with legitimate Chrome security dialogs or warnings, when they're actually seeing fake ones controlled by the attacker. This UI spoofing attack requires user interaction—the victim must visit the malicious page—but once they do, the attacker can deceive them into taking actions they wouldn't normally take, such as entering credentials or approving permissions.
- CVE-2026-11177HIGH 8.8
A use-after-free vulnerability exists in Google Chrome's Omnibox (the combined address and search bar). An attacker can craft a malicious HTML page that, when a user performs specific interactions with the Omnibox, triggers memory corruption. Successful exploitation requires user interaction—the attacker cannot silently compromise a machine, but if a targeted user visits a crafted page and engages with the address bar in a particular way, the attacker could potentially execute arbitrary code with the privileges of the Chrome process.
- CVE-2026-11179HIGH 8.8
Google Chrome versions before 149.0.7827.53 contain a flaw in the Object Request Broker (ORB) feature that allows attackers to bypass site isolation—a critical Chrome security boundary that prevents websites from accessing each other's data. An attacker can exploit this by hosting a malicious HTML page that, when visited by a user, breaks through site isolation and gains unauthorized access to sensitive information from other open tabs or windows. The vulnerability requires user interaction (visiting the crafted page) but demands no special privileges, making it a practical concern for any Chrome user.
- CVE-2026-11188HIGH 8.8
A use-after-free vulnerability in Chrome's USB handling on Android devices allows an attacker to escape the browser's security sandbox by tricking a user into visiting a specially crafted webpage. Once the sandbox is bypassed, the attacker could gain elevated privileges on the device. The vulnerability affects Chrome versions prior to 149.0.7827.53 on Android.
- CVE-2026-11191HIGH 8.8
A memory safety flaw in Chrome's ANGLE graphics library allows attackers to access memory beyond intended boundaries when a user visits a malicious webpage. An attacker can craft HTML that exploits this out-of-bounds read or write to leak sensitive data, crash the browser, or execute code with the privileges of the Chrome process. The vulnerability affects Chrome versions prior to 149.0.7827.53 across Windows, macOS, and Linux.
- CVE-2026-11201HIGH 8.8
Google Chrome versions prior to 149.0.7827.53 contain a use-after-free vulnerability in the ServiceWorker component that allows arbitrary code execution. The vulnerability requires an attacker to convince a user to install a malicious Chrome extension, after which the attacker can exploit memory handling flaws to run code with the privileges of the browser. This is not a vulnerability in the browser itself that users encounter passively—it requires social engineering to trick a user into voluntarily installing a compromised extension.
- CVE-2026-11202HIGH 8.8
Google Chrome on iOS versions before 149.0.7827.53 contain a sandbox escape vulnerability triggered by viewing a malicious webpage. An attacker can craft a specially designed HTML page that, when opened in Chrome on an iPhone, could break out of the browser's security sandbox and gain access to the underlying operating system. This means an attacker could potentially read files, install malware, or take control of the device without requiring any special user permissions beyond clicking a link or visiting a website.
- CVE-2026-11211HIGH 8.8
A flaw in Google Chrome's V8 JavaScript engine allows attackers to run malicious code with limited privileges inside Chrome's sandbox by tricking users into visiting a specially crafted website. While the malicious code runs in a restricted environment, the sandbox breach itself represents a significant security boundary violation that could be chained with other exploits to gain fuller system control.
- CVE-2026-11230HIGH 8.8
Google Chrome versions prior to 149.0.7827.53 contain a use-after-free vulnerability in the Extensions subsystem that could allow an attacker to execute arbitrary code within Chrome's sandbox. An attacker would need to trick a user into visiting a malicious HTML page. While Chromium initially categorized this as low severity, the CVSS score reflects the real-world impact: complete compromise of confidentiality, integrity, and availability within the sandboxed context.
- CVE-2026-11235HIGH 8.8
Google Chrome versions prior to 149.0.7827.53 contain a sandbox escape vulnerability in the compositing system. An attacker who successfully compromises Chrome's renderer process (the sandboxed component responsible for rendering web content) can exploit insufficient policy enforcement to execute arbitrary code with elevated privileges, bypassing the sandbox entirely. The attack requires a crafted HTML page and user interaction, making it a post-compromise threat rather than a direct entry point. While Chromium rated this Low severity, the CVSS score of 8.8 reflects the critical nature of sandbox escapes, which transform a contained renderer compromise into full system code execution.
- CVE-2026-11248HIGH 8.8
CVE-2026-11248 is a bypass vulnerability in Google Lens, a feature within Chrome that allows users to perform visual searches. An attacker can craft a malicious webpage that, when visited by a user, circumvents Chrome's navigation security controls. This means a user could be redirected to an unintended destination or prevented from safely navigating away. The vulnerability requires user interaction—the user must visit the attacker's page—but once there, the attack happens automatically. Google has patched this in Chrome 149.0.7827.53 and later.
- CVE-2026-11262HIGH 8.8
A use-after-free vulnerability exists in Google Chrome's TabStrip component that allows attackers to execute arbitrary code on a victim's machine. The flaw requires user interaction—specifically, visiting a malicious webpage—but once triggered, grants full code execution privileges. Chrome versions prior to 149.0.7827.53 are affected. Despite Chromium's internal severity rating of 'Low', the CVSS 3.1 score reflects the real-world impact: remote code execution with no authentication needed, complete compromise of confidentiality, integrity, and availability.
- CVE-2026-11272HIGH 8.8
A flaw in Google Chrome's Reading List feature on iOS allows attackers to trick users into performing specific actions (like tapping or swiping) that trigger a privilege escalation attack. An attacker would need to craft a malicious webpage and convince the user to interact with it in a particular way. Once exploited, the attacker gains elevated permissions on the device, potentially compromising sensitive data or device functionality.
- CVE-2026-11279HIGH 8.8
Google Chrome versions prior to 149.0.7827.53 contain an out-of-bounds read vulnerability in the DevTools component that allows an attacker to execute arbitrary code within the Chrome sandbox. An attacker would need to trick a user into visiting a crafted HTML page, but would not need any special privileges or system access. While Chromium's internal severity assessment is Low, the CVSS 3.1 score of 8.8 reflects the high severity due to the potential for code execution within a restricted sandbox environment.
- CVE-2026-11295HIGH 8.8
A vulnerability in Google Chrome's WebView on Android allows attackers to escalate their privileges by tricking users into visiting a specially crafted webpage. WebView is the component that renders web content within Android apps, so this affects not just Chrome but any app built on this framework. An attacker needs user interaction (clicking or viewing the malicious page), but once triggered, the vulnerability grants them elevated system permissions—a significant breach of the Android security model.
- CVE-2026-11301HIGH 8.8
A vulnerability in Google Chrome's LiveCaption feature allows attackers to access memory outside safe boundaries by sending specially crafted network traffic. While Chrome assigned this a low severity rating internally, the vulnerability can lead to information disclosure, data corruption, or system crashes depending on what memory region is accessed. The attack requires user interaction—the user must be running a vulnerable Chrome version and receive the malicious traffic—but no special privileges are needed from the attacker's perspective.
- CVE-2026-11303HIGH 8.8
A use-after-free vulnerability in PDFium, the PDF rendering engine embedded in Google Chrome, allows attackers to execute arbitrary code within Chrome's sandbox by tricking users into opening a specially crafted PDF file. While the vulnerability requires user interaction (opening a malicious PDF), the impact is severe: an attacker gains code execution inside the sandboxed Chrome process, potentially leading to data theft, system compromise, or further exploitation. The vulnerability affects Chrome versions prior to 149.0.7827.53 across Windows, macOS, and Linux platforms.
- CVE-2026-11304HIGH 8.8
A use-after-free flaw in PDFium, the PDF rendering engine used by Google Chrome, allows attackers to corrupt heap memory when a user opens a specially crafted PDF file. An attacker could exploit this to potentially execute arbitrary code or crash the browser. The vulnerability requires user interaction (opening a malicious PDF) but is otherwise straightforward to exploit remotely.
- CVE-2026-11305HIGH 8.8
A use-after-free flaw in PDFium, the PDF rendering engine embedded in Google Chrome, allows attackers to execute arbitrary code within Chrome's sandbox by tricking users into opening a malicious PDF file. The vulnerability affects Chrome versions prior to 149.0.7827.53 across Windows, macOS, and Linux. While Chromium assigned this a Low security severity rating, the CVSS score of 8.8 reflects the practical risk: a remote attacker needs only a crafted PDF and user interaction to achieve code execution with high impact on confidentiality, integrity, and availability.
- CVE-2026-11306HIGH 8.8
A memory safety bug in Google Chrome's PDF rendering engine (PDFium) allows attackers to run malicious code within Chrome's sandbox by sending a victim a specially crafted PDF file. The attacker needs the user to open the PDF—there's no way to trigger this remotely without interaction. While the Chromium team rated the issue as Low severity internally, the actual impact is significant: an attacker gains arbitrary code execution within the browser sandbox, potentially stealing data or performing other malicious actions. This affects Chrome on Windows, macOS, and Linux.
- CVE-2026-11307HIGH 8.8
A use-after-free memory bug in PDFium—the PDF rendering library bundled with Google Chrome—allows attackers to run arbitrary code within Chrome's sandbox by sending a malicious PDF file. The vulnerability requires user interaction (opening the PDF) but can fully compromise a victim's browser process, stealing data or installing malware. While Google rated this as low severity internally, the CVSS score of 8.8 reflects the serious consequences: an attacker gains code execution with high impact to confidentiality, integrity, and availability.
- CVE-2026-11629HIGH 8.8
A use-after-free vulnerability in Google Chrome's Ozone component allows attackers to crash the browser or corrupt its memory by tricking users into visiting a specially crafted webpage. The attacker needs the victim to click a link or visit a malicious site—no special privileges are required. Chrome versions before 149.0.7827.103 are affected.
- CVE-2026-11630HIGH 8.8
Google Chrome versions prior to 149.0.7827.103 contain a use-after-free vulnerability in its file input handling. An attacker can craft a malicious HTML page that, when visited by a user, triggers improper memory management in Chrome's file handling code. This allows the attacker to corrupt memory on the victim's computer, potentially leading to arbitrary code execution. The vulnerability requires user interaction (visiting a malicious webpage) but affects users across Windows, macOS, and Linux systems.
- CVE-2026-11633HIGH 8.8
Google Chrome on macOS contains a use-after-free vulnerability in its Bluetooth handling code. This flaw allows a remote attacker to execute arbitrary code on a victim's machine if that person connects to or interacts with a malicious Bluetooth peripheral while using an unpatched version of Chrome. The vulnerability affects Chrome versions prior to 149.0.7827.103 on Mac systems.
- CVE-2026-11637HIGH 8.8
A use-after-free vulnerability exists in Google Chrome's Views component on macOS that allows attackers to execute arbitrary code on a victim's machine. The flaw is triggered when a user visits a specially crafted webpage, requiring no special privileges or complex setup. Google has classified this as a critical severity issue in the underlying Chromium project. This vulnerability affects Chrome versions prior to 149.0.7827.103 on macOS systems.
- CVE-2026-11646HIGH 8.8
A use-after-free flaw in Google Chrome's ViewTransitions feature allows attackers to run arbitrary code within Chrome's sandbox by tricking users into visiting a malicious website. The vulnerability exists in Chrome versions before 149.0.7827.103 and requires user interaction—specifically clicking or otherwise engaging with a crafted HTML page. While the code runs in a sandboxed environment (limiting direct system access), it still represents a significant threat because sandbox escapes are a known attack progression.
- CVE-2026-11648HIGH 8.8
A use-after-free memory flaw exists in Google Chrome's full-screen functionality on Windows. An attacker can craft a malicious web page that, when visited, exploits this flaw to corrupt the browser's memory heap. This could allow the attacker to execute arbitrary code on the victim's machine with the same privileges as the user running Chrome. The vulnerability requires user interaction (clicking or navigating to the malicious page) but no special privileges or complex setup.
- CVE-2026-11649HIGH 8.8
Google Chrome versions before 149.0.7827.103 contain a use-after-free vulnerability in the V8 JavaScript engine that allows attackers to execute arbitrary code within the Chrome sandbox by serving a malicious HTML page. The flaw requires user interaction (clicking a link or visiting a site) but does not require special privileges. While the sandbox limits the immediate blast radius, successful exploitation could grant an attacker control over the browser process and access to user data like credentials, session tokens, and browsing history.
- CVE-2026-11650HIGH 8.8
A use-after-free flaw in Google Chrome's V8 JavaScript engine allows attackers to execute arbitrary code within the browser's sandbox by tricking users into visiting a malicious website. The vulnerability affects Chrome versions before 149.0.7827.103 and requires user interaction (clicking a link or visiting a page). While the code runs in a sandboxed environment, successful exploitation could allow attackers to break out of the sandbox or pivot to other browser features, making this a serious but not trivial attack vector.
- CVE-2026-11657HIGH 8.8
Google Chrome on macOS contains a use-after-free memory flaw in its Payments feature that allows an attacker to run malicious code on a user's machine. The vulnerability is triggered when a user visits a specially crafted website, making it relatively easy to exploit in the wild. Chrome versions before 149.0.7827.103 on macOS are affected. This is a remote code execution risk that requires user interaction (clicking a link or visiting a site) but no special privileges.
- CVE-2026-11662HIGH 8.8
A type confusion vulnerability in Google Chrome's bindings mechanism allows attackers to execute arbitrary code within the Chrome sandbox by serving a specially crafted HTML page. The flaw affects Chrome versions before 149.0.7827.103 and requires user interaction (visiting a malicious page) to trigger. While sandboxed, successful exploitation could lead to complete compromise of the affected Chrome process, including data theft and system-level attacks if combined with additional vulnerabilities.
- CVE-2026-11664HIGH 8.8
A use-after-free vulnerability exists in Google Chrome's Payments component that could allow an attacker to corrupt browser memory and potentially execute arbitrary code. An attacker would need to trick a user into visiting a malicious website to trigger the flaw. The issue affects Chrome versions prior to 149.0.7827.103 and is considered high-severity by Google's security team.
- CVE-2026-11670HIGH 8.8
A use-after-free vulnerability in Google Chrome's PDF renderer allows attackers to run malicious code within the browser's sandbox by crafting a specially designed PDF file. The attack requires user interaction—specifically, opening a malicious PDF—but once triggered, it can lead to complete compromise of the affected browser process. This affects Chrome versions prior to 149.0.7827.103 across Windows, macOS, and Linux systems.
- CVE-2026-11673HIGH 8.8
A use-after-free vulnerability in Google Chrome's InterestGroups feature allows attackers to execute arbitrary code within the browser's sandbox by tricking users into visiting a malicious webpage. The vulnerability affects Chrome versions prior to 149.0.7827.103 and can be exploited without requiring user privileges beyond normal web browsing.
- CVE-2026-11674HIGH 8.8
A use-after-free flaw in Google Chrome's Guest View feature allows attackers to run malicious code within the browser sandbox by tricking users into visiting a specially crafted webpage. While the exploit runs in a sandboxed environment, a successful attack could still compromise sensitive data or enable further system compromise. The vulnerability affects Chrome versions before 149.0.7827.103 and requires user interaction to trigger.
- CVE-2026-11680HIGH 8.8
Google Chrome contains a use-after-free vulnerability in its Media component that could allow an attacker to run malicious code within Chrome's sandbox by tricking a user into visiting a specially crafted website. The flaw affects Windows systems running Chrome versions prior to 149.0.7827.103. While the exploit requires user interaction (clicking a link or visiting a site), the potential impact is severe: an attacker could steal sensitive data, modify files, or cause denial of service, all while operating within Chrome's restricted sandbox environment.
- CVE-2026-11681HIGH 8.8
A use-after-free vulnerability exists in the Ozone display layer of Google Chrome on Linux systems. An attacker can craft a malicious HTML page that, when visited by a user, triggers improper memory management and causes heap corruption. This can lead to a crash or arbitrary code execution on the victim's machine. The vulnerability requires user interaction (clicking a link or visiting a site) but does not require any special browser configuration or elevated privileges.
- CVE-2026-11683HIGH 8.8
Google Chrome contains a use-after-free vulnerability in its WebCodecs component that allows remote attackers to execute arbitrary code within the browser sandbox. An attacker would need to trick a user into visiting a specially crafted webpage to trigger the flaw. Once exploited, the attacker gains code execution privileges within Chrome's sandbox environment, which limits but does not eliminate the potential for system compromise depending on sandbox escape possibilities.
- CVE-2026-11687HIGH 8.8
A memory safety flaw in Google Chrome's graphics rendering engine (Dawn) on macOS allows attackers to corrupt memory on a victim's computer by tricking them into visiting a malicious website. The vulnerability exists in Chrome versions before 149.0.7827.103 and can lead to complete compromise of the affected system.
- CVE-2026-11688HIGH 8.8
Google Chrome versions prior to 149.0.7827.103 contain a flaw in how the browser handles SVG (Scalable Vector Graphics) content. An attacker can craft a malicious HTML page that, when visited by a user, executes arbitrary code within Chrome's sandbox environment. While the sandbox is designed to limit damage, this vulnerability allows an attacker to breach that boundary, potentially compromising user data and system integrity.
- CVE-2026-11698HIGH 8.8
Google Chrome on macOS contains a use-after-free vulnerability in its Bluetooth handling code that allows attackers to corrupt heap memory when a victim visits a malicious website. The vulnerability affects Chrome versions before 149.0.7827.103 and requires user interaction (clicking a link or visiting a site) but does not require special privileges. Successful exploitation can lead to data theft, system compromise, or application crash.
- CVE-2026-11699HIGH 8.8
A use-after-free vulnerability exists in the Bluetooth component of Google Chrome on macOS. An attacker can craft a malicious webpage that, when visited by a user, exploits this flaw to corrupt the browser's memory and potentially execute arbitrary code. The vulnerability requires user interaction (visiting a link or webpage) but does not require the victim to have any special privileges. Google has assigned it high severity and has released a patch in Chrome version 149.0.7827.103.
- CVE-2026-12007HIGH 8.8
A use-after-free vulnerability in Google Chrome's core rendering engine on Windows allows attackers to execute arbitrary code by tricking users into visiting a malicious webpage. The flaw exists in memory management logic—when Chrome processes certain HTML constructs, it may attempt to access memory that has already been freed, enabling an attacker to overwrite that freed memory with malicious code. No special user privileges or system access are required; the attack succeeds if a user simply visits a crafted page in a vulnerable Chrome version.
- CVE-2026-12018HIGH 8.8
A flaw in Chrome's Mojo implementation on Windows allows a local attacker to gain system-level control by tricking a user into opening a malicious file. The vulnerability affects Chrome versions before 149.0.7827.115 and has been rated High severity by Google's security team.
- CVE-2026-12020HIGH 8.8
A use-after-free vulnerability exists in Google Chrome's Autofill feature on macOS. When a user visits a malicious website, an attacker can craft HTML that triggers heap memory corruption. The flaw allows potential arbitrary code execution with the same privileges as the Chrome browser process. All macOS users running Chrome versions prior to 149.0.7827.115 are at risk.
- CVE-2026-12035HIGH 8.8
Google Chrome on Windows contains a use-after-free vulnerability in its Views component that could allow an attacker to corrupt memory on a victim's computer. The flaw requires user interaction—clicking or interacting with a malicious webpage—but once triggered, an attacker could potentially execute arbitrary code with the privileges of the Chrome process. This is a remote attack that does not require the victim to install software or bypass authentication.
- CVE-2026-12439HIGH 8.8
Google Chrome contains a use-after-free vulnerability in its Digital Credentials component that could allow an attacker to corrupt heap memory and potentially execute arbitrary code. The flaw requires user interaction—specifically, visiting a specially crafted webpage—but poses a critical risk because it affects a widely deployed browser across multiple operating systems. Users running Chrome versions prior to 149.0.7827.155 are at risk.
- CVE-2026-12441HIGH 8.8
A use-after-free vulnerability exists in Google Chrome's file input handling on Linux systems. An attacker can craft a malicious HTML page that, when visited by a user, exploits this memory safety flaw to corrupt the browser's heap and potentially execute arbitrary code. The vulnerability affects Chrome versions prior to 149.0.7827.155 and requires user interaction (clicking or interacting with the page).
- CVE-2026-12442HIGH 8.8
A use-after-free flaw in Google Chrome's password handling on Android allows remote attackers to run malicious code on a victim's device. An attacker could craft a deceptive HTML page that, when visited by an Android user, exploits freed memory in Chrome's password system to gain arbitrary code execution. This is a critical-severity bug that requires user interaction—the victim must visit the malicious page—but once triggered, can fully compromise the device.
- CVE-2026-12443HIGH 8.8
A use-after-free vulnerability in Google Chrome's Web Authentication subsystem allows attackers to execute arbitrary code by tricking users into visiting a malicious website. The flaw affects Chrome versions before 149.0.7827.155 across Windows, macOS, and Linux. An attacker would need to craft a deceptive HTML page and convince a user to visit it; successful exploitation grants the attacker the same privileges as the compromised browser process.
- CVE-2026-12447HIGH 8.8
A vulnerability in Google Chrome's WebRTC component allows attackers to crash the browser or run malicious code within Chrome's sandbox protection by tricking users into visiting a specially crafted website. The attack requires user interaction—specifically, a user must open or be redirected to the malicious page—but no special privileges are needed on the target system. While the code execution is limited to the Chrome sandbox environment, successful exploitation could still enable data theft or further system compromise.
- CVE-2026-12448HIGH 8.8
A weakness in Google Chrome's WebView component on Android devices allows attackers to trick users into visiting a specially crafted webpage that can escape the security boundaries of the browser and gain elevated privileges on the device. This is a remote attack that requires user interaction—the victim must click a link or visit a malicious site—but once triggered, it bypasses normal Android permission models. The vulnerability affects Chrome versions prior to 149.0.7827.155.
- CVE-2026-12452HIGH 8.8
A use-after-free memory flaw in Google Chrome's Downloads feature on Android devices allows an attacker to corrupt heap memory and potentially take control of your browser by getting you to visit a malicious website. No special user permissions or browser configuration is required—the vulnerability triggers automatically when you land on a crafted page. The issue is confirmed fixed in Chrome version 149.0.7827.155 and later.
- CVE-2026-12466HIGH 8.8
A memory safety flaw in Chrome's WebRTC component allows attackers to run malicious code on Windows machines. An attacker can craft a deceptive webpage that, when visited by an unaware user, exploits the heap buffer overflow to gain control of the browser process. This is a remote attack requiring only that a user click or visit a malicious link—no special permissions or prior system compromise needed.
- CVE-2026-13026HIGH 8.8
A use-after-free flaw in Chrome's Digital Credentials feature on macOS could let an attacker trick a user into visiting a malicious webpage, potentially corrupting Chrome's memory and achieving arbitrary code execution. The vulnerability affects Chrome versions before 149.0.7827.197 on Apple's macOS platform.
- CVE-2026-13027HIGH 8.8
A use-after-free vulnerability in Google Chrome's FileSystem component allows attackers to corrupt memory and potentially execute arbitrary code when a user visits a malicious website. The flaw affects Chrome versions before 149.0.7827.197 across Windows, macOS, and Linux systems. Exploitation requires user interaction—specifically visiting a crafted HTML page—but once triggered, the vulnerability can lead to complete system compromise.
- CVE-2026-13031HIGH 8.8
A use-after-free memory vulnerability exists in Chrome's Blink rendering engine that could allow an attacker to run malicious code within Chrome's sandbox by tricking a user into visiting a specially crafted website. The flaw affects Chrome versions before 149.0.7827.197 and impacts users across Windows, macOS, and Linux systems.
- CVE-2026-13033HIGH 8.8
A memory safety vulnerability in Google Chrome's interest groups feature allows attackers to read and write data outside intended memory boundaries. An attacker can craft a malicious HTML page that, when visited by a user, triggers the flaw to execute arbitrary code on the victim's machine. The vulnerability affects Chrome versions before 149.0.7827.197 and is classified as critical by Chrome's security team.
- CVE-2026-13035HIGH 8.8
A use-after-free vulnerability in Chrome's Bluetooth implementation on macOS allows an attacker to execute arbitrary code on a victim's computer. The flaw requires user interaction—specifically, a user must connect to or interact with a malicious Bluetooth peripheral—but once triggered, it grants the attacker full control over the affected system. This is a remote code execution (RCE) risk that bypasses Chrome's sandbox protections.
- CVE-2026-13036HIGH 8.8
A use-after-free memory vulnerability exists in Google Chrome's Blink rendering engine that allows remote attackers to execute arbitrary code within the browser's sandbox. The flaw requires user interaction—specifically opening a malicious HTML page—but poses a direct threat to confidentiality, integrity, and availability once triggered. Attackers can escape the sandbox's execution context and potentially gain control over the affected system.
- CVE-2026-13038HIGH 8.8
Google Chrome on Windows contains a use-after-free memory vulnerability in its Autofill feature that allows attackers to execute arbitrary code on a user's system. An attacker can craft a malicious HTML page that, when visited by a Chrome user, triggers memory corruption in the Autofill subsystem. Because the vulnerability requires only user interaction (visiting a webpage) and no special privileges, it presents a high bar for exploitation chains and a significant risk to Chrome users. The vulnerability affects Chrome versions prior to 149.0.7827.197 on Windows.
- CVE-2026-13777HIGH 8.8
Google Chrome on iOS contains a vulnerability that allows attackers to trigger heap memory corruption by tricking users into visiting a malicious webpage. The flaw stems from Chrome's iOSWeb component failing to properly validate user-supplied input before processing it. An attacker would need to craft a specially designed HTML page and convince a user to visit it; the user's device would then be at risk of compromise. Chrome versions before 150.0.7871.47 are vulnerable on iOS.
- CVE-2026-13783HIGH 8.8
A use-after-free memory vulnerability exists in Google Chrome's Views component that could allow an attacker to corrupt the heap memory of an affected system. The vulnerability requires a user to visit a malicious website and perform specific UI interactions, such as clicking or gesturing within the page. If exploited successfully, an attacker could read sensitive data, modify system behavior, or crash the application. This is a memory safety issue—a category of bugs that remains a persistent challenge in browser security.
- CVE-2026-13784HIGH 8.8
A use-after-free vulnerability exists in Google Chrome's Views component that could allow an attacker to corrupt browser memory. The flaw requires user interaction—specifically, the victim must perform certain UI gestures (like clicking, dragging, or other interface actions) while visiting a malicious webpage. If successfully exploited, this could lead to a complete compromise of the user's browser, potentially affecting data confidentiality, integrity, and availability. Chrome versions prior to 150.0.7871.47 are affected.
- CVE-2026-13786HIGH 8.8
A memory safety flaw in Google Chrome's Ozone subsystem allows attackers to execute arbitrary code on a victim's computer by hosting a malicious website. When a user visits the compromised site, the browser processes a specially crafted HTML page that triggers a use-after-free condition—essentially allowing code to operate on memory that has already been freed. This results in complete system compromise. The vulnerability requires user interaction (visiting a malicious page) but no special privileges, and affects Chrome versions prior to 150.0.7871.47.
- CVE-2026-13788HIGH 8.8
A use-after-free memory flaw in Google Chrome's fullscreen feature on Android allows attackers to run arbitrary code by tricking users into visiting a malicious webpage. This is a memory safety issue where the browser attempts to access memory that has already been freed, creating an opening for code execution. The flaw affects Android devices running Chrome versions prior to 150.0.7871.47.
- CVE-2026-13805HIGH 8.8
A use-after-free vulnerability exists in Google Chrome's graphics rendering engine (GFX) on macOS. An attacker can exploit this by hosting a malicious website; when a user visits the page, Chrome crashes in a way that allows the attacker to run arbitrary code with the privileges of the Chrome process. This affects Chrome versions prior to 150.0.7871.47 on Mac systems.
- CVE-2026-13811HIGH 8.8
Google Chrome versions before 150.0.7871.47 contain a use-after-free vulnerability in the Input Method Editor (IME) component that can be exploited when a user visits a malicious webpage. An attacker could leverage this flaw to execute arbitrary code within Chrome's sandbox environment, potentially leading to system compromise. The vulnerability requires user interaction (visiting a crafted page) but does not require elevated privileges to trigger.
- CVE-2026-13815HIGH 8.8
A use-after-free vulnerability exists in Google Chrome's Blink rendering engine that allows attackers to execute arbitrary code within the browser sandbox by tricking users into viewing a malicious webpage. No special privileges or complex user interaction beyond opening a link are required for exploitation.
- CVE-2026-13817HIGH 8.8
A flaw in Chrome's Glic component fails to properly validate user-supplied input before processing it. This weakness allows an attacker to craft a malicious HTML page that, when visited, could break out of Chrome's sandbox—the security boundary that isolates the browser from the underlying operating system. If successful, an attacker gains the ability to execute arbitrary code with the same privileges as the user running Chrome, potentially compromising the entire system.
- CVE-2026-13821HIGH 8.8
A use-after-free memory bug in Google Chrome's Canvas rendering engine allows attackers to run malicious code within the browser's sandbox by tricking users into visiting a specially crafted webpage. No special privileges are required—any user viewing a malicious site can be compromised. The vulnerability affects Chrome versions before 150.0.7871.47 across Windows, macOS, and Linux systems.
- CVE-2026-13825HIGH 8.8
Google Chrome contains a flaw where certain memory in the browser's graphics component (Dawn) is not properly initialized before use. An attacker who crafts a malicious HTML page can trigger this condition and potentially corrupt the heap memory that Chrome relies on, leading to crashes or, in the worst case, arbitrary code execution. The vulnerability requires user interaction—the victim must visit the malicious page—but once they do, the attack executes with no additional privileges needed.
- CVE-2026-13830HIGH 8.8
A use-after-free vulnerability in Google Chrome's Chromoting feature on Linux allows an attacker on the same network to remotely execute arbitrary code without user interaction. An attacker would need to send malicious network traffic to trigger the flaw, which resides in memory management of the Chromoting subsystem. This is a particularly dangerous class of vulnerability because it gives an attacker direct code execution capability on an affected system.
- CVE-2026-13835HIGH 8.8
Google Chrome versions prior to 150.0.7871.47 contain a flaw in how the browser processes XML within HTML pages. An attacker can craft a malicious web page that, when visited by a user, exploits this flaw to corrupt the browser's memory heap. This type of corruption can lead to complete compromise of the affected system—including theft of sensitive data, installation of malware, or loss of system control. The vulnerability requires user interaction (visiting a malicious site) but is otherwise straightforward to exploit.
- CVE-2026-13845HIGH 8.8
Google Chrome versions prior to 150.0.7871.47 contain a use-after-free vulnerability in the DOM (Document Object Model) that could allow an attacker to run arbitrary code within the browser's sandbox by tricking a user into visiting a specially crafted webpage. This is a memory safety issue where Chrome continues to reference DOM objects after they have been freed, creating a window for code execution. The vulnerability requires user interaction—specifically visiting a malicious site—but carries high risk once triggered.
- CVE-2026-13848HIGH 8.8
A use-after-free memory flaw in Google Chrome's form handling allows attackers to run malicious code within the browser's sandbox by tricking users into visiting a specially crafted website. The vulnerability affects Chrome versions prior to 150.0.7871.47 across Windows, macOS, and Linux. While the code executes in a sandbox—which limits what an attacker can directly access on the system—the sandbox itself isn't impenetrable, and successful exploitation could lead to full browser compromise or escalation of privileges.
- CVE-2026-13850HIGH 8.8
Google Chrome on iOS versions before 150.0.7871.47 contain a flaw that fails to properly validate user-supplied input when handling files. A local attacker could craft a malicious file that, when opened in Chrome on iOS, would execute arbitrary code within the browser's sandbox. While sandboxing limits the scope of potential damage, successful exploitation could allow an attacker to run malicious code on an affected device.
- CVE-2026-13870HIGH 8.8
A use-after-free memory flaw in Chrome's WebView component on Android allows attackers to run malicious code within the browser sandbox by hosting a specially crafted webpage. Any user who visits the malicious page while using an affected Chrome version could be compromised. The vulnerability affects Chrome versions before 150.0.7871.47.
- CVE-2026-13884HIGH 8.8
CVE-2026-13884 is an integer overflow vulnerability in the Chromecast component of Google Chrome. A local attacker on the same network can send malicious network traffic to trigger the overflow and achieve arbitrary code execution with no user interaction required. This is a serious local network attack, not an internet-facing threat.
- CVE-2026-13885HIGH 8.8
A use-after-free vulnerability exists in Skia, Google Chrome's graphics library, affecting Android versions prior to 150.0.7871.47. An attacker can craft a malicious HTML page that, when visited by a user, triggers code execution within Chrome's sandbox. While sandboxed, successful exploitation could allow an attacker to break out of Chrome's security boundary and access the underlying Android system, posing a significant risk to affected devices.
- CVE-2026-13888HIGH 8.8
A use-after-free memory vulnerability exists in Google Chrome's extension handling system. When a user visits a malicious webpage, an attacker can exploit this flaw to run arbitrary code within Chrome's sandboxed extension environment. The vulnerability requires user interaction (visiting a crafted webpage) but carries significant risk because it bypasses Chrome's sandbox protections, which are designed to contain extension-level exploits. All recent versions of Chrome before 150.0.7871.47 are affected across Windows, macOS, and Linux platforms.
- CVE-2026-13897HIGH 8.8
A flaw in how Google Chrome enforces security policies for Chromecast functionality allows attackers to trick users into visiting malicious web pages that escalate their browser privileges. The attacker gains access equivalent to the user's account, posing a direct risk to data and system integrity. This affects Chrome versions before 150.0.7871.47.
- CVE-2026-13898HIGH 8.8
A use-after-free vulnerability in Google Chrome's Cast Receiver component allows attackers to run arbitrary code within the browser's sandbox by tricking users into visiting a malicious webpage. The flaw affects Chrome versions prior to 150.0.7871.47 and requires user interaction (clicking a link or visiting a site). While sandboxed, successful exploitation could give an attacker significant control over the affected user's browsing session and data.
- CVE-2026-13899HIGH 8.8
A use-after-free memory flaw in Google Chrome's HTML rendering engine allows attackers to run arbitrary code within the browser's sandbox by sending a specially crafted web page. An attacker would need to trick a user into visiting a malicious website, but once there, the flaw could allow code execution with the privileges of the browser process.
- CVE-2026-13903HIGH 8.8
Google Chrome versions before 150.0.7871.47 contain a vulnerability in Bluetooth policy enforcement that allows attackers to escalate privileges on a user's system. An attacker can craft a malicious HTML page that, when visited by a user, exploits insufficient controls over Bluetooth permissions to gain elevated access. This is a remote attack requiring only user interaction—no special network conditions or authentication.
- CVE-2026-13915HIGH 8.8
A use-after-free memory flaw in Chrome for iOS allows attackers to corrupt heap memory and potentially take control of your device if you visit a malicious webpage and perform certain UI gestures, such as scrolling or tapping in specific ways. The vulnerability affects Chrome on iPhones running iOS versions prior to 150.0.7871.47. While Google rated this as medium severity internally, the CVSS score of 8.8 reflects the practical risk: no special privileges are required, the attack works over the network, and successful exploitation grants full read, write, and delete access to device memory.
- CVE-2026-13918HIGH 8.8
A use-after-free vulnerability exists in Chrome for iOS that allows attackers to corrupt memory and potentially take control of the affected device through a malicious webpage. The flaw affects Chrome versions before 150.0.7871.47 on iPhone and iPad. An attacker needs only to trick a user into visiting a crafted website—no special access or complex interaction is required beyond basic browsing.
- CVE-2026-13928HIGH 8.8
Google Chrome versions before 150.0.7871.47 contain a vulnerability that allows attackers to gain elevated privileges on a user's system by tricking them into visiting a malicious webpage. The flaw stems from inadequate checking of user-supplied input, and while Google rates the underlying issue as medium severity, the combination of remote exploitability, user interaction requirement, and high impact consequences results in a CVSS score of 8.8 (HIGH). Users who browse to a specially crafted HTML page could see their Chrome process escalate its privileges, potentially compromising the entire browser context.
- CVE-2026-13938HIGH 8.8
Google Chrome versions before 150.0.7871.47 contain an integer overflow vulnerability in the font rendering system that attackers can exploit by sending a crafted HTML page. If a user visits a malicious site, the overflow can corrupt memory in a way that lets the attacker read sensitive data, modify running code, or crash the browser. The vulnerability requires user interaction (clicking a link or visiting a page) but no special privileges.
- CVE-2026-13965HIGH 8.8
Google Chrome versions before 150.0.7871.47 contain a use-after-free vulnerability in Oilpan, Chrome's garbage collection system. An attacker can craft a malicious HTML page that, when visited, triggers unsafe memory access and executes arbitrary code within Chrome's sandbox. While the sandbox contains the impact to the browser process, the flaw still allows complete compromise of that process with full read, write, and execute access. This is a remote attack requiring only that a user visit a hostile website—no special user privileges or configuration changes are needed.