By vendor

Google vulnerabilities

Known CVEs affecting Google products, prioritized by severity, with SEC.co remediation and detection guidance.

1195 published vulnerabilities · page 3 of 12

  • CVE-2026-13967HIGH 8.8

    Google Chrome contains a heap buffer overflow vulnerability in its V8 JavaScript engine that could allow attackers to run malicious code within Chrome's sandbox by sending users a crafted webpage. The vulnerability requires user interaction—specifically visiting a malicious site—but once triggered, grants an attacker the ability to execute arbitrary code with the privileges of the Chrome process. This is a serious flaw because while Chrome's sandbox provides some containment, code execution within it can still lead to data theft or further system compromise.

  • CVE-2026-14005HIGH 8.8

    A use-after-free memory vulnerability exists in Google Chrome's address bar (Omnibox) on Android devices. An attacker can craft a malicious webpage that, when a user interacts with it in specific ways, causes Chrome to access memory that has already been freed. This can lead to heap corruption and potential code execution. The vulnerability requires user interaction and affects Chrome versions prior to 150.0.7871.47.

  • CVE-2026-14006HIGH 8.8

    A use-after-free vulnerability in Google Chrome's navigation feature allows attackers to execute arbitrary code on a victim's system by tricking them into visiting a malicious webpage. The flaw affects Chrome versions before 150.0.7871.47. The vulnerability requires user interaction (visiting a crafted page) but poses a significant risk because successful exploitation grants an attacker full control over the affected system.

  • CVE-2026-14009HIGH 8.8

    Google Chrome versions before 150.0.7871.47 contain a flaw in how the browser handles password-related operations that can allow an attacker to corrupt the application's memory. An attacker who crafts a malicious webpage and tricks a user into visiting it could potentially execute arbitrary code or crash the browser. This is not a remote code execution vulnerability that requires no user interaction; the attack requires a user to actually visit a malicious page.

  • CVE-2026-14024HIGH 8.8

    A use-after-free flaw in Chrome's Ozone display server component on Linux allows attackers to corrupt memory and potentially execute code if a user is tricked into performing specific UI interactions on a malicious webpage. The vulnerability affects Chrome versions before 150.0.7871.47 and requires user interaction to exploit, but once triggered can lead to full system compromise.

  • CVE-2026-14025HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's Views component on macOS. If a user visits a malicious webpage and interacts with the page in a specific way—such as clicking certain elements or performing gestures—an attacker could trigger memory corruption that may lead to a complete compromise of the browser process. The vulnerability requires user interaction and affects Chrome versions prior to 150.0.7871.47 on macOS.

  • CVE-2026-14027HIGH 8.8

    A use-after-free vulnerability in Google Chrome's sign-in functionality allows attackers to corrupt memory and potentially execute arbitrary code on a victim's machine. The attack requires convincing a user to perform specific gestures during the sign-in process on a malicious webpage. While Chromium rates this as low severity from a feature perspective, the underlying memory corruption can lead to complete system compromise if successfully exploited.

  • CVE-2026-14036HIGH 8.8

    Google Chrome versions prior to 150.0.7871.47 contain a vulnerability in Bluetooth policy enforcement that allows attackers to escalate privileges on affected systems. By crafting a malicious HTML page, a remote attacker can trick users into visiting the page and gain elevated system permissions. The vulnerability requires user interaction (clicking or viewing a link) but does not require the victim to be authenticated or for the attacker to be on the same network.

  • CVE-2026-14040HIGH 8.8

    Google Chrome versions prior to 150.0.7871.47 contain a use-after-free vulnerability in the BrowserTag component that could allow attackers to corrupt heap memory. The attack requires an attacker to first convince a user to install a malicious Chrome extension. While Chromium classifies this as low severity internally, the CVSS 3.1 score of 8.8 reflects the potential for complete system compromise if successfully exploited. Users who install untrusted extensions remain at risk until they update to the patched version.

  • CVE-2026-14041HIGH 8.8

    A security flaw in Google Chrome's Serial API component allows attackers to bypass security restrictions through a specially crafted webpage. When a user visits a malicious site, the attacker can escalate their privileges on the user's system without requiring any special permissions beforehand. The vulnerability affects Chrome versions prior to 150.0.7871.47 and requires user interaction (clicking or viewing the page) to be exploited.

  • CVE-2026-14067HIGH 8.8

    A use-after-free flaw in Chrome for iOS allows attackers to execute arbitrary code on affected iPhones when a user visits a maliciously crafted webpage. The vulnerability exists in memory management within Chrome's iOS implementation—specifically, the browser can attempt to access data that has already been freed, enabling code execution. While Chromium's internal severity rating is Low, the CVSS score of 8.8 reflects the practical risk: remote, unauthenticated exploitation via a simple link click, with full impact to confidentiality, integrity, and availability. This affects all Chrome users on iOS running versions prior to 150.0.7871.47.

  • CVE-2026-14078HIGH 8.8

    A weakness in how Google Chrome handles WebRTC (real-time communication) components fails to properly validate user-supplied input, allowing attackers to trick users into visiting a malicious webpage that could escalate their privileges on the system. The attacker needs the user to click through to a crafted page, but requires no special access or authentication to launch the attack.

  • CVE-2026-14084HIGH 8.8

    Google Chrome versions before 150.0.7871.47 contain a vulnerability in its Chromoting remote access feature that fails to properly validate untrusted input from the network. This weakness can allow an attacker to send specially crafted network traffic that corrupts the browser's memory, potentially leading to code execution. The vulnerability requires user interaction—such as establishing or accepting a remote connection—but does not require special privileges to exploit.

  • CVE-2026-14086HIGH 8.8

    Google Chrome versions before 150.0.7871.47 contain a vulnerability in its Human Interface Device (HID) handling that permits remote code execution when a user visits a malicious webpage. An attacker can craft a specially designed HTML page that exploits insufficient policy enforcement in the HID implementation, allowing them to run arbitrary code with the privileges of the Chrome process. User interaction—opening or viewing the crafted page—is required to trigger the vulnerability.

  • CVE-2026-14087HIGH 8.8

    A heap buffer overflow vulnerability exists in the WebNN (Web Neural Network) component of Google Chrome on Windows systems. The flaw allows a remote attacker who has already compromised the Chrome renderer process to trigger heap memory corruption by crafting a malicious HTML page. While Chromium classifies this as low severity, the CVSS 3.1 assessment reflects the potential for significant impact if exploited, including confidentiality, integrity, and availability violations.

  • CVE-2026-14091HIGH 8.8

    A use-after-free memory vulnerability exists in Chrome's DevTools (developer tools) that allows an attacker to execute arbitrary code within the browser's sandbox through a malicious HTML page. The vulnerability affects Chrome versions prior to 150.0.7871.47 and requires user interaction—the victim must view the crafted HTML in their browser. While Chromium rates this as low severity internally, the CVSS 3.1 assessment reflects high risk due to the combination of network delivery, lack of authentication, and potential for complete system compromise.

  • CVE-2026-14099HIGH 8.8

    A use-after-free memory vulnerability exists in Chrome for iOS that could allow an attacker to corrupt heap memory on your device. The attack requires you to visit a specially crafted website and perform specific UI interactions—there's no automatic exploitation. Once triggered, the memory corruption could lead to full device compromise: stealing sensitive data, modifying content, or crashing the browser. This affects Chrome on iOS versions before 150.0.7871.47.

  • CVE-2026-14102HIGH 8.8

    Google Chrome versions prior to 150.0.7871.47 contain a use-after-free vulnerability in the password management system. An attacker can craft a malicious HTML page that, when visited by a user, exploits this memory safety flaw to corrupt heap memory and potentially execute arbitrary code. The vulnerability requires user interaction (visiting a website) but does not require special privileges.

  • CVE-2026-14107HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's scheduling system that allows attackers to execute code within the Chrome sandbox by tricking users into visiting a malicious webpage. The vulnerability affects Chrome versions prior to 150.0.7871.47. While the Chromium project classified this as low severity, the CVSS score of 8.8 reflects the high-impact nature of the issue due to the combination of network accessibility, low complexity, and the requirement for user interaction.

  • CVE-2026-14108HIGH 8.8

    A use-after-free vulnerability in PDFium, the PDF rendering engine embedded in Google Chrome, allows attackers to execute arbitrary code within Chrome's sandboxed environment by crafting a malicious PDF file. The vulnerability requires user interaction—a victim must open the malicious PDF—but once triggered, it can bypass Chrome's sandbox protections. This affects Chrome versions prior to 150.0.7871.47 across Windows, macOS, and Linux systems.

  • CVE-2026-14149HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's audio processing component on Linux systems. An attacker can craft a malicious HTML page that, when visited by a user, exploits this memory safety flaw to execute arbitrary code on the victim's machine. The vulnerability requires user interaction (visiting a webpage) but needs no special privileges to trigger. Chrome versions before 150.0.7871.47 on Linux are affected.

  • CVE-2026-14383HIGH 8.8

    A flaw in Chrome's V8 JavaScript engine allows attackers to break out of the sandbox and run malicious code on a victim's computer by tricking them into visiting a specially crafted webpage. The vulnerability affects Chrome versions before 150.0.7871.46 and requires user interaction (clicking a link or visiting a site), but once exploited, gives an attacker full control over the browser process and potentially the underlying system.

  • CVE-2026-14385HIGH 8.8

    A heap buffer overflow vulnerability exists in the ANGLE graphics rendering component within Google Chrome on macOS. An attacker can exploit this by hosting a malicious HTML page—when a user visits the page, Chrome's rendering engine writes data beyond allocated memory boundaries, potentially compromising the confidentiality, integrity, and availability of the browser process. This is a remote attack requiring no special privileges, though it does require user interaction (visiting a crafted page).

  • CVE-2026-14393HIGH 8.8

    A use-after-free vulnerability in Google Chrome's V8 JavaScript engine (prior to version 150.0.7871.46) allows attackers to execute arbitrary code within the browser's sandbox by tricking users into visiting a malicious webpage. While the Chromium team rated this as medium severity internally, the CVSS score of 8.8 reflects the practical risk: an attacker needs only to craft a deceptive HTML page and convince a user to visit it—no special privileges or complex conditions required. The attack lands inside the sandbox, limiting but not eliminating post-exploitation impact.

  • CVE-2026-14394HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's V8 JavaScript engine that could allow an attacker to corrupt heap memory by tricking a user into visiting a malicious webpage. The flaw affects Chrome versions before 150.0.7871.46 and requires user interaction (clicking or viewing the page) to trigger. While Chromium rates the severity as Low, the CVSS 3.1 score of 8.8 reflects the potential for complete system compromise through memory corruption.

  • CVE-2026-14395HIGH 8.8

    Google Chrome versions before 150.0.7871.46 contain an out-of-bounds write vulnerability in the V8 JavaScript engine that allows attackers to run malicious code within the browser's sandbox. An attacker can exploit this by crafting a malicious HTML page and tricking a user into visiting it. Once triggered, the vulnerability permits arbitrary code execution inside the sandboxed environment. While the sandbox provides a containment boundary, successful exploitation still represents a serious security risk.

  • CVE-2026-14403HIGH 8.8

    A use-after-free memory vulnerability exists in Google Chrome's V8 JavaScript engine that could allow an attacker to run malicious code within the browser's sandbox by tricking a user into visiting a specially crafted webpage. While the Chromium team rated this internally as low severity, the CVSS assessment reflects high risk due to the combination of remote exploitability, low attack complexity, and potential for code execution.

  • CVE-2026-14407HIGH 8.8

    A flaw in Google Chrome's V8 JavaScript engine allows attackers to run malicious code inside the browser's sandbox by tricking users into visiting a specially crafted webpage. The vulnerability requires user interaction (clicking a link or visiting a site) but does not require any special privileges. Once exploited, an attacker gains the ability to read sensitive data, modify information, or disrupt browser functionality from within the sandboxed environment.

  • CVE-2026-14415HIGH 8.8

    A flaw in Google Chrome's V8 JavaScript engine allows heap memory corruption when a user interacts with a malicious webpage through specific UI gestures. An attacker crafts an HTML page that, when visited and engaged with in particular ways, corrupts the heap—a critical memory region—potentially leading to code execution or application crash. Chrome versions before 150.0.7871.46 are vulnerable. The attack requires user interaction, not silent exploitation.

  • CVE-2026-14422HIGH 8.8

    A memory safety vulnerability exists in Chrome's Tint rendering component that allows attackers to read and write beyond allocated memory boundaries. When a user visits a malicious website, the attacker can craft HTML that triggers out-of-bounds memory access, potentially compromising confidentiality, integrity, and availability. The vulnerability requires user interaction (visiting a malicious page) but no special privileges, making it a significant risk for typical browsing scenarios.

  • CVE-2026-14430HIGH 8.8

    A flaw in Google Chrome's V8 JavaScript engine allows attackers to crash the browser or run malicious code within Chrome's sandbox by sending a specially crafted webpage. The vulnerability affects Chrome versions before 150.0.7871.46 and requires only that a user visit a malicious site—no special privileges needed. While the code runs inside Chrome's sandbox (limiting system-wide damage), the sandbox can sometimes be bypassed, making this a serious threat to anyone browsing the web.

  • CVE-2026-14431HIGH 8.8

    A type confusion flaw in Chrome's V8 JavaScript engine allows attackers to run malicious code within the browser's sandbox by serving a specially crafted webpage. The vulnerability requires user interaction (visiting a malicious site) but carries high risk because it bypasses the sandbox's isolation protections and can lead to full browser compromise.

  • CVE-2026-14432HIGH 8.8

    Google Chrome contains a use-after-free vulnerability in its V8 JavaScript engine that can allow attackers to run malicious code within Chrome's sandbox by tricking users into visiting a specially crafted website. The flaw affects Chrome versions before 150.0.7871.46 and requires user interaction (clicking a link or visiting a site) but no special privileges. While sandboxing limits direct system access, a successful exploit could still compromise browser data and potentially serve as a stepping stone for further attacks.

  • CVE-2026-15107HIGH 8.8

    Google Chrome contains a use-after-free vulnerability in its IndexedDB implementation that allows attackers to execute arbitrary code within the Chrome sandbox by convincing users to visit a malicious website. The flaw affects Chrome versions prior to 150.0.7871.115 and requires user interaction (clicking a link or visiting a page) to trigger. While the vulnerability is sandboxed, successful exploitation could allow an attacker to read sensitive data, modify browser state, or crash the application.

  • CVE-2026-15110HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's extension handling mechanism. An attacker could craft a malicious Chrome extension that, when installed by a user, triggers memory corruption on the victim's system. This flaw affects Chrome versions prior to 150.0.7871.115 and requires user interaction (convincing someone to install the extension), but once exploited could compromise the confidentiality, integrity, and availability of the affected system.

  • CVE-2026-15112HIGH 8.8

    Google Chrome versions before 150.0.7871.115 contain a use-after-free memory defect in the Ozone component that an attacker can trigger by hosting a malicious web page. If a user visits such a page, the flaw can corrupt the browser's heap memory, potentially allowing the attacker to read sensitive data, modify running processes, or crash the browser. This is a network-based attack requiring only that a user click a link or visit a compromised site—no special user privileges or system access needed.

  • CVE-2026-15114HIGH 8.8

    A memory safety vulnerability in Google Chrome's video codec processing allows attackers to corrupt heap memory by tricking users into opening a specially crafted video file. The flaw combines an out-of-bounds read with an out-of-bounds write, potentially enabling arbitrary code execution on affected systems. Users must update to Chrome 150.0.7871.115 or later to patch the issue.

  • CVE-2026-15116HIGH 8.8

    Google Chrome contains a use-after-free vulnerability in its Actor component that could allow attackers to run malicious code within Chrome's sandbox by tricking users into visiting a specially crafted webpage. The flaw affects Chrome versions before 150.0.7871.115 and requires user interaction (clicking a link or visiting a malicious site) but no special privileges to exploit.

  • CVE-2026-15118HIGH 8.8

    Google Chrome versions before 150.0.7871.115 contain a use-after-free flaw in the Input component that can be exploited by a remote attacker. An attacker can craft a malicious HTML page that, when visited by a user, triggers the vulnerability and executes arbitrary code within Chrome's sandbox environment. This is a memory safety issue where the browser attempts to access input data after it has already been freed, allowing code injection with high impact to confidentiality, integrity, and availability.

  • CVE-2026-15121HIGH 8.8

    A use-after-free vulnerability in Google Chrome's WebRTC implementation allows attackers to run malicious code within the browser's sandbox by tricking users into visiting a crafted website. The vulnerability affects Chrome versions before 150.0.7871.115. While the code executes in a sandbox (limiting direct system impact), successful exploitation could lead to data theft, credential capture, or lateral movement to other browser contexts.

  • CVE-2026-15123HIGH 8.8

    Google Chrome versions before 150.0.7871.115 contain a flaw in how the browser handles the Document Object Model (DOM) that could allow attackers to corrupt memory on your system. An attacker could craft a malicious web page that, when visited, exploits this vulnerability to gain control over sensitive data, modify web content, or crash your browser. The vulnerability requires user interaction—you must visit the malicious page—but no special user privileges are needed, and the attacker doesn't need network access beyond hosting the page.

  • CVE-2026-15125HIGH 8.8

    Google Chrome versions before 150.0.7871.115 contain a vulnerability in the Forms implementation that allows attackers to execute arbitrary code within Chrome's sandbox through a malicious HTML page. An attacker would need to trick a user into visiting or interacting with a crafted webpage, but once clicked or loaded, the vulnerability could allow code execution with the privileges of the browser process.

  • CVE-2026-15126HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's Forms component that allows an attacker to execute arbitrary code within Chrome's sandbox environment. An attacker would need to trick a user into visiting a specially crafted webpage. If successful, the attacker gains code execution inside the sandbox, which provides some isolation but can still lead to data theft, credential harvesting, or lateral movement depending on the victim's system configuration. Google has assigned this a High severity rating. The vulnerability affects Chrome versions prior to 150.0.7871.115.

  • CVE-2026-15129HIGH 8.8

    A use-after-free flaw in Google Chrome's Views component could allow an attacker to corrupt browser memory and take control of your system when you visit a malicious website. The vulnerability affects Chrome versions before 150.0.7871.115. No user interaction beyond visiting a crafted page is required to trigger the flaw, making it a serious risk for any organization relying on Chrome.

  • CVE-2026-15132HIGH 8.8

    A vulnerability in Google Chrome's V8 JavaScript engine allows attackers to execute malicious code within the browser's sandbox by tricking users into visiting a specially crafted webpage. The flaw stems from improper handling of uninitialized variables, creating a memory safety issue that can be exploited without requiring special user permissions or authentication. This is a remote code execution (RCE) vulnerability that affects Chrome versions prior to 150.0.7871.115.

  • CVE-2026-15133HIGH 8.8

    Google Chrome versions before 150.0.7871.115 contain a use-after-free vulnerability in the InterestGroups feature. An attacker can craft a malicious HTML page that, when opened in an affected browser, triggers the flaw to execute arbitrary code within the Chrome sandbox. The vulnerability requires user interaction (visiting a malicious page) but poses a high risk due to the ease of exploitation and the potential for sandbox escape or data theft.

  • CVE-2026-9873HIGH 8.8

    A use-after-free memory defect in Google Chrome's Network component allows attackers to run malicious code within the browser sandbox by sending a specially crafted HTML page. The vulnerability requires user interaction—the victim must visit or be directed to the malicious page—but no special browser configuration or privileges are needed to exploit it. Google has rated this as Critical severity due to code execution capabilities, though the CVSS 3.1 score of 8.8 reflects the HIGH severity classification.

  • CVE-2026-9878HIGH 8.8

    A use-after-free vulnerability exists in the ANGLE graphics library component of Google Chrome versions before 148.0.7778.216. An attacker can craft a malicious webpage that, when visited, exploits this flaw to execute arbitrary code within Chrome's sandbox environment. The vulnerability requires user interaction (clicking a link or visiting a site) but does not require any special privileges. While the code runs in a sandbox, successful exploitation could allow attackers to steal sensitive data or cause denial of service.

  • CVE-2026-9879HIGH 8.8

    A memory safety bug in Chrome's graphics rendering engine (ANGLE) allows attackers to write data outside of allocated memory boundaries. An attacker can craft a malicious HTML page that, when opened in vulnerable versions of Chrome, triggers this out-of-bounds write to execute arbitrary code on the user's system. The vulnerability requires user interaction—specifically, the victim must visit or be directed to the malicious webpage—but no special privileges are needed and the attack works over the network.

  • CVE-2026-9883HIGH 8.8

    Google Chrome contains a use-after-free memory safety flaw in its Base component that allows attackers to execute arbitrary code on a user's system when they visit a malicious webpage. The vulnerability requires user interaction (viewing the crafted HTML) but no special privileges, and the attacker can read sensitive data, modify files, or crash the browser. Chrome versions prior to 148.0.7778.216 are affected across Windows, macOS, and Linux platforms.

  • CVE-2026-9884HIGH 8.8

    A use-after-free vulnerability in Google Chrome on macOS allows an attacker to run malicious code on a victim's computer by tricking them into visiting a specially crafted website. The vulnerability affects Chrome versions before 148.0.7778.216 on Mac and requires user interaction (clicking a link or viewing a page) but no special privileges to exploit. Google has classified this as a critical security issue in the Chromium project.

  • CVE-2026-9887HIGH 8.8

    A memory safety bug in Google Chrome's proxy handling system allows an attacker to craft a malicious Proxy Auto-Config (PAC) script that, when processed by the browser, causes the application to reference memory that has already been freed. This use-after-free condition can be leveraged to execute arbitrary code on a user's system. The vulnerability requires user interaction—specifically, the victim must visit a website or be directed to load a PAC script—but no special privileges are needed from the attacker's perspective. Chrome versions prior to 148.0.7778.216 are affected.

  • CVE-2026-9896HIGH 8.8

    A flaw in Google Chrome's V8 JavaScript engine allows attackers to write data outside intended memory boundaries. By crafting a malicious HTML page, an attacker can trigger arbitrary code execution within Chrome's sandbox. The vulnerability requires user interaction—the victim must visit or be directed to a malicious website—but no special privileges are needed. Chrome versions prior to 148.0.7778.216 are affected across Windows, macOS, and Linux platforms.

  • CVE-2026-9897HIGH 8.8

    Google Chrome versions prior to 148.0.7778.216 contain a use-after-free vulnerability in the DOM (Document Object Model) that allows attackers to execute arbitrary code within the browser sandbox by tricking users into visiting a crafted webpage. This vulnerability requires user interaction but poses a high risk because successful exploitation grants code execution capabilities inside the sandboxed browser process.

  • CVE-2026-9910HIGH 8.8

    A memory safety bug in Google Chrome's graphics engine (ANGLE) allows an attacker to run malicious code within Chrome's sandbox by sending a specially crafted web page to a victim. The vulnerability requires user interaction—specifically visiting a malicious webpage—but no special privileges. Once triggered, an attacker could read sensitive data, modify browser state, or crash the application. This affects Chrome on Windows, macOS, and Linux.

  • CVE-2026-9923HIGH 8.8

    A use-after-free vulnerability exists in Skia, the graphics library used by Google Chrome. An attacker can exploit this flaw by hosting a specially crafted HTML page. If a user visits that page while running a vulnerable version of Chrome, the attacker may corrupt memory on the user's system, potentially leading to data theft, system compromise, or browser crashes. The vulnerability requires user interaction (visiting a malicious page) but no special privileges.

  • CVE-2026-9927HIGH 8.8

    A use-after-free vulnerability in ANGLE (the graphics translation layer used by Chrome) allows attackers to run malicious code within Chrome's sandbox by tricking users into visiting a specially crafted webpage. The vulnerability exists in Google Chrome versions prior to 148.0.7778.216 and affects Windows, macOS, and Linux systems. While sandboxed, successful exploitation could grant an attacker local execution capabilities on the victim's machine.

  • CVE-2026-9928HIGH 8.8

    A memory safety flaw in Google Chrome's ANGLE graphics library allows attackers to read data outside intended memory boundaries. When a user visits a specially crafted webpage, this out-of-bounds read can be weaponized to execute arbitrary code on the affected Windows system. The vulnerability affects Chrome versions prior to 148.0.7778.216 and is rated High severity by Chromium's security team.

  • CVE-2026-9938HIGH 8.8

    A flaw in Google Chrome's V8 JavaScript engine allows attackers to execute arbitrary code within the browser's sandbox by tricking users into visiting a malicious webpage. The vulnerability affects Chrome versions before 148.0.7778.216 and requires user interaction (clicking a link or visiting a crafted site). While the code runs in a sandboxed environment, successful exploitation could allow an attacker to break out of Chrome's security boundaries and potentially access system resources or steal sensitive data.

  • CVE-2026-9939HIGH 8.8

    A heap buffer overflow vulnerability in Chrome's WebCodecs component allows attackers to execute arbitrary code within Chrome's sandbox by tricking users into visiting a malicious webpage. The vulnerability affects Chrome versions prior to 148.0.7778.216 across Windows, macOS, and Linux platforms. Because it requires user interaction (clicking a link or visiting a site) but can bypass Chrome's sandbox protections, it represents a significant remote code execution risk for Chrome users.

  • CVE-2026-9940HIGH 8.8

    A heap buffer overflow vulnerability exists in the ANGLE graphics library used by Google Chrome versions before 148.0.7778.216. An attacker can craft a malicious HTML page that, when visited by a user, corrupts heap memory in the browser process. This memory corruption could allow the attacker to execute arbitrary code or crash the browser. The vulnerability requires user interaction (visiting a malicious website) but does not require any special privileges or complex attack setup.

  • CVE-2026-9941HIGH 8.8

    A use-after-free flaw in Chrome's ANGLE graphics library allows attackers to run arbitrary code within Chrome's sandbox by serving a malicious HTML page. An attacker would need to trick a user into visiting a crafted website; no special privileges or system access are required. Chrome versions before 148.0.7778.216 are vulnerable.

  • CVE-2026-9945HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's media handling code on Windows systems. An attacker can craft a malicious HTML page that, when visited by a user, triggers the vulnerability to execute arbitrary code within Chrome's sandboxed environment. This requires user interaction (visiting a link or webpage) but no special privileges, making it a practical attack vector for compromised websites or phishing campaigns.

  • CVE-2026-9947HIGH 8.8

    A use-after-free memory vulnerability exists in Google Chrome's XML processing engine that allows an attacker to execute arbitrary code within Chrome's sandbox. An attacker can trigger this vulnerability by crafting a malicious HTML page and convincing a user to visit it. While the sandbox limits damage, successful exploitation could allow the attacker to steal sensitive data or escalate privileges. The vulnerability affects Chrome versions prior to 148.0.7778.216 on Windows, macOS, and Linux systems.

  • CVE-2026-9952HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's WebAudio component that allows attackers to execute arbitrary code within the Chrome sandbox by tricking users into visiting a malicious website. The vulnerability affects Chrome versions prior to 148.0.7778.216 and requires user interaction (clicking a link or visiting a page). While sandboxed, successful exploitation could allow an attacker to run code with the privileges of the Chrome process, potentially leading to data theft or system compromise.

  • CVE-2026-9957HIGH 8.8

    Google Chrome's PDF renderer contains a use-after-free vulnerability that allows attackers to run malicious code within Chrome's sandboxed PDF handling process. An attacker can exploit this by sending a specially crafted PDF file to a victim. If the victim opens the PDF in Chrome, the vulnerability triggers, potentially allowing the attacker to escape the sandbox and execute arbitrary code on the system. The vulnerability affects Chrome versions prior to 148.0.7778.216 and impacts users on Windows, macOS, and Linux.

  • CVE-2026-9958HIGH 8.8

    A use-after-free vulnerability in PDFium, the PDF rendering engine embedded in Google Chrome, allows attackers to corrupt heap memory when a victim opens a maliciously crafted PDF file. An attacker can trigger this flaw remotely simply by getting someone to view a rigged PDF—no special browser settings or plugins required. This can lead to information disclosure, data corruption, or arbitrary code execution depending on how an attacker chains the memory corruption with other techniques.

  • CVE-2026-9961HIGH 8.8

    A use-after-free memory vulnerability exists in Google Chrome's SurfaceCapture component that allows attackers to corrupt heap memory. An attacker can craft a malicious HTML page that, when visited by a user, triggers the flaw to potentially execute arbitrary code with the privileges of the Chrome process. The vulnerability requires user interaction (visiting a malicious site) but has high impact once triggered.

  • CVE-2026-9962HIGH 8.8

    A use-after-free memory vulnerability in Google Chrome's WebRTC component allows an attacker to execute arbitrary code within the browser's sandbox by tricking a user into visiting a specially crafted webpage. The attacker gains the ability to read sensitive data, modify information, or crash the browser without needing special privileges or authentication.

  • CVE-2026-9965HIGH 8.8

    A memory vulnerability in Google Chrome's ANGLE graphics library allows attackers to corrupt heap memory through a specially crafted webpage. When a user visits a malicious site, the attacker can trigger an out-of-bounds write operation that overwrites data beyond intended memory boundaries. This could lead to arbitrary code execution with the privileges of the browser process. The vulnerability requires user interaction (visiting a malicious page) but is otherwise trivial to deliver via normal web browsing.

  • CVE-2026-9968HIGH 8.8

    Google Chrome versions before 148.0.7778.216 contain a flaw in the V8 JavaScript engine that can be triggered by opening a malicious webpage. An attacker can exploit this to run malicious code within Chrome's sandbox—a security boundary meant to isolate the browser from the rest of your system. While the sandbox limits what an attacker can directly access, breaking out of it is a known follow-up risk. The vulnerability requires user interaction (visiting a malicious site) but poses a serious threat because it affects millions of Chrome users across Windows, macOS, and Linux.

  • CVE-2026-9969HIGH 8.8

    A vulnerability in Google Chrome's ANGLE graphics library (the translation layer that converts graphics commands to platform-specific formats) fails to properly check user-supplied input before processing it. An attacker can exploit this by hosting a specially crafted webpage; when a user visits that page in a vulnerable version of Chrome, the attacker gains the ability to run arbitrary code on the victim's machine with the same privileges as the Chrome process. The attack requires user interaction—specifically, the victim must visit the malicious page—but no special browser settings or additional permissions are needed.

  • CVE-2026-9973HIGH 8.8

    CVE-2026-9973 is a memory corruption vulnerability in Google Chrome's V8 JavaScript engine that allows attackers to run malicious code within the browser's sandbox by hosting a specially crafted HTML page. An attacker would need to trick a user into visiting the malicious site, but once there, the flaw provides a direct path to arbitrary code execution. Chrome versions before 148.0.7778.216 are vulnerable.

  • CVE-2026-9976HIGH 8.8

    Google Chrome versions before 148.0.7778.216 contain a flaw in how the browser handles USB device interactions. An attacker can craft a malicious HTML page that, when visited by a user, exploits this flaw to run arbitrary code on the victim's computer with the same privileges as the Chrome process. The vulnerability requires user interaction (visiting the page) but does not require the attacker to have special privileges or be on the same network—it can be delivered remotely via the internet.

  • CVE-2026-9978HIGH 8.8

    A use-after-free flaw in Google Chrome's Glic component allows attackers to run arbitrary code within the browser's sandbox by tricking users into visiting a malicious webpage. The vulnerability affects Chrome versions prior to 148.0.7778.216 across Windows, macOS, and Linux. While the code execution is confined to the sandbox, successful exploitation could lead to data theft, credential compromise, or lateral movement depending on the attacker's objectives and the system's security posture.

  • CVE-2026-9983HIGH 8.8

    A type confusion vulnerability in Chrome's Skia graphics engine allows attackers to execute arbitrary code within Chrome's sandbox by tricking users into visiting a malicious website. The attacker needs no special privileges—just the ability to craft a deceptive HTML page. Once code runs in the sandbox, it gains significant capabilities including reading sensitive data, modifying content, and disrupting the browser. Chrome version 148.0.7778.216 and later patch this flaw.

  • CVE-2026-9984HIGH 8.8

    Google Chrome on Windows contains a use-after-free memory vulnerability in its UI layer that allows attackers to execute arbitrary code on affected systems. The flaw can be triggered by tricking a user into visiting a specially crafted webpage; no special privileges or system access is required from the attacker. This is a remote code execution risk that affects Chrome versions prior to 148.0.7778.216.

  • CVE-2026-9992HIGH 8.8

    Google Chrome versions prior to 148.0.7778.216 contain a use-after-free vulnerability in its Network component that allows attackers to execute arbitrary code within the browser's sandbox by tricking users into visiting a malicious website. The vulnerability requires user interaction (clicking a link or visiting a page) but no special privileges, making it a practical attack vector for widespread exploitation.

  • CVE-2026-9995HIGH 8.8

    Google Chrome contains a use-after-free memory vulnerability in its WebXR implementation that allows attackers to execute arbitrary code within the browser's sandbox. An attacker can craft a malicious HTML page that, when visited by a user, triggers this flaw to break out of memory protections and run code. This affects Chrome versions prior to 148.0.7778.216 on Windows, macOS, and Linux systems.

  • CVE-2026-9999HIGH 8.8

    A flaw in ANGLE, the graphics rendering component within Google Chrome on macOS, allows attackers to break out of the sandbox and run arbitrary code on an affected system. An attacker only needs to trick a user into visiting a malicious webpage—no special permissions or complex attack chains required. The vulnerability has a High severity rating and affects Chrome versions prior to 148.0.7778.216 on Mac systems.

  • CVE-2026-11158HIGH 8.6

    A vulnerability in Google Chrome's download handling on macOS allows a local attacker to potentially escape Chrome's sandbox protection using a specially crafted AppleScript command. The issue stems from insufficient validation of user-supplied input. An attacker with local access to an affected Mac could exploit this to break out of the browser sandbox and gain elevated system privileges, though user interaction (such as clicking on a malicious download link or AppleScript trigger) is required.

  • CVE-2026-13849HIGH 8.6

    Google Chrome on Windows contains a flaw in its Chromoting component (the remote desktop feature) that fails to properly validate certain user inputs. An attacker with local access to a machine can exploit this by tricking a user into opening a malicious file, potentially breaking out of Chrome's security sandbox and gaining broader system access. The vulnerability affects Chrome versions prior to 150.0.7871.47 on Windows.

  • CVE-2026-10000HIGH 8.3

    A use-after-free memory vulnerability exists in Google Chrome's password management system on Windows. An attacker who has already compromised Chrome's renderer process (the sandboxed component that displays web pages) could exploit this flaw through a malicious HTML page to escape the sandbox and gain system-level access. This is a multi-stage attack: the attacker must first achieve renderer compromise, then leverage this vulnerability to break out of Chrome's security boundary.

  • CVE-2026-10001HIGH 8.3

    A use-after-free flaw in Chrome's PerformanceManager could let an attacker escape the browser sandbox if they've already compromised the rendering engine. The attack requires a specially crafted web page and user interaction, but success could grant full system access. This affects Chrome versions before 148.0.7778.216.

  • CVE-2026-10012HIGH 8.3

    A use-after-free flaw in Chrome's Skia graphics library allows an attacker who controls the browser's renderer process to escape the sandbox and execute arbitrary code on the underlying system. The attack requires a malicious HTML page and user interaction, but once the renderer is compromised, the vulnerability enables full system compromise. This is particularly dangerous because renderer exploits are common entry points; this flaw raises the stakes by providing a bridge from that compromised renderer to the host OS.

  • CVE-2026-10014HIGH 8.3

    A use-after-free memory flaw in Chrome's WebMIDI implementation on Android allows an attacker who has already compromised Chrome's renderer process to escape the sandbox through a specially crafted web page. This is a privilege escalation attack: the attacker must first breach the renderer sandbox, then exploit this vulnerability to break out and gain full device access.

  • CVE-2026-10017HIGH 8.3

    A memory read vulnerability exists in Google Chrome's Headless mode that could allow an attacker to escape the browser's security sandbox. If an attacker first compromises the renderer process—the part of Chrome that interprets web pages—they could craft a malicious HTML page to trigger an out-of-bounds read, potentially breaking out of the sandbox and gaining broader system access. This vulnerability requires the renderer to already be compromised, which is a significant precondition, but the consequence of successful exploitation is severe.

  • CVE-2026-10020HIGH 8.3

    A flaw in Chrome's Skia graphics library on Android allows an attacker who has already compromised Chrome's renderer process to escape the security sandbox and gain full device access. The vulnerability requires the user to visit a specially crafted webpage, but the heavy lifting—compromising the renderer first—means this is a two-stage attack. Chrome versions before 148.0.7778.216 on Android are affected.

  • CVE-2026-10884HIGH 8.3

    A use-after-free memory vulnerability exists in Google Chrome's Chromecast component that could allow an attacker to escape the browser's sandbox if the attacker has already compromised the renderer process. The vulnerability requires user interaction and specific browser conditions, but successful exploitation could grant an attacker unauthorized access to the host system. Google has assigned this a Critical severity rating within Chromium's threat model.

  • CVE-2026-10889HIGH 8.3

    A memory reading flaw in Chrome's ANGLE graphics library can let an attacker who has already gained control of the browser's rendering process break out of the Chrome sandbox and access the underlying system. The attack requires a specially crafted web page and user interaction, but once the renderer is compromised, this vulnerability opens a direct path to full system compromise. Chrome versions before 149.0.7827.53 are affected.

  • CVE-2026-10894HIGH 8.3

    A use-after-free flaw in Chrome's printing subsystem on Linux could allow an attacker who already controls the browser's renderer process to break out of Chrome's sandbox protections and gain full system access. The vulnerability is triggered by a specially crafted web page and affects Chrome versions before 149.0.7827.53. While this requires initial compromise of the renderer process, it represents a critical escalation path from web content to system privileges.

  • CVE-2026-10898HIGH 8.3

    A stack buffer overflow vulnerability exists in the GPU component of Google Chrome versions prior to 149.0.7827.53. An attacker who has already compromised Chrome's renderer process can exploit this flaw through a malicious HTML page to break out of the browser sandbox and gain system-level code execution. While the attacker must first compromise the renderer—typically through a separate browser vulnerability or social engineering—the sandbox escape itself represents a critical escalation path that transforms a contained compromise into full system compromise.

  • CVE-2026-10905HIGH 8.3

    A memory safety flaw in Google Chrome's network code allows an attacker who has already compromised the browser's renderer process to escape the sandbox and gain full system access. The vulnerability requires user interaction (opening a malicious HTML page) but poses significant risk because successful exploitation bypasses Chrome's core security boundary—the sandbox that isolates the browser from the operating system.

  • CVE-2026-10908HIGH 8.3

    A use-after-free vulnerability exists in Google Chrome's full-screen functionality on Windows systems. An attacker who has already compromised Chrome's rendering engine could exploit a specially crafted web page to escape the browser sandbox and execute arbitrary code with higher privileges. This requires the attacker to have initial renderer process access, but once achieved, the flaw could allow them to run code outside the sandbox protection layer.

  • CVE-2026-10909HIGH 8.3

    A use-after-free vulnerability in Google Chrome's Dawn graphics engine allows an attacker who has already compromised the browser's renderer process to escape the sandbox through a malicious webpage. This is a high-severity issue because it bridges two separate security boundaries—first gaining control within Chrome's renderer, then breaking out to execute arbitrary code on the underlying operating system.

  • CVE-2026-10911HIGH 8.3

    CVE-2026-10911 is a sandbox escape vulnerability in Google Chrome that allows a remote attacker to break out of the browser's security sandbox if they have already compromised the renderer process. The attack requires crafted HTML content and user interaction, but once successful, it grants an attacker full system access. This is a chained attack scenario: an attacker must first compromise the renderer (the part of Chrome that displays web content) through a separate vulnerability, then use this flaw to escape the sandbox and gain control of the underlying system.

  • CVE-2026-10915HIGH 8.3

    A use-after-free memory vulnerability exists in Google Chrome on iOS that allows an attacker who has already compromised the browser's renderer process to break out of the sandbox and gain deeper system access. The vulnerability requires the attacker to serve a specially crafted HTML page and involves a complex attack chain but poses severe risk because successful exploitation can lead to full compromise of the device. Chrome versions prior to 149.0.7827.53 on iOS are affected.

  • CVE-2026-10917HIGH 8.3

    Google Chrome versions before 149.0.7827.53 contain a media handling flaw that allows an attacker who has already compromised the browser's renderer process to escape the sandbox and gain broader system access. The vulnerability requires user interaction (visiting a specially crafted webpage) but poses a significant risk because renderer compromises are common entry points in real attacks. Once inside the renderer, the flaw gives an attacker a path to elevated privileges on the underlying operating system.

  • CVE-2026-10918HIGH 8.3

    A use-after-free vulnerability in Google Chrome's Viz component allows an attacker who has already compromised the browser's renderer process to potentially escape the sandbox and gain deeper system access. The attacker would need to trick a user into visiting a malicious webpage, but the actual exploitation requires prior renderer compromise, making this a multi-stage attack. While not currently known to be exploited in the wild, the vulnerability represents a meaningful privilege escalation path for sophisticated threat actors who have achieved initial browser process compromise.

  • CVE-2026-10919HIGH 8.3

    A use-after-free bug in Chrome's ANGLE graphics library before version 149.0.7827.53 allows an attacker who already controls the browser's rendering process to break out of the sandbox and gain full system access. The attacker must trick a user into visiting a malicious webpage, but once the renderer is compromised, this flaw provides a path to escape Chrome's isolation boundaries.