By vendor

Microsoft vulnerabilities

Known CVEs affecting Microsoft products, prioritized by severity, with SEC.co remediation and detection guidance.

588 published vulnerabilities · page 1 of 6

  • CVE-2026-10002HIGH 8.8

    A use-after-free memory flaw in PDFium, the PDF rendering engine embedded in Google Chrome, allows attackers to corrupt heap memory by tricking users into opening a specially crafted PDF file. The vulnerability affects Chrome versions before 148.0.7778.216 and requires user interaction to trigger. An attacker exploiting this could achieve code execution with the same privileges as the Chrome process.

  • CVE-2026-10007HIGH 8.8

    Google Chrome versions prior to 148.0.7778.216 contain a use-after-free memory safety flaw in SVG rendering that allows attackers to execute arbitrary code within the browser's sandbox by tricking users into visiting a malicious webpage. An attacker needs only to craft a deceptive HTML page and convince a user to open it—no special privileges or complex interaction are required beyond the initial click.

  • CVE-2026-10013HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's WebCodecs component that could allow an attacker to run malicious code within Chrome's sandbox by tricking a user into visiting a specially crafted website. The vulnerability affects Chrome versions before 148.0.7778.216 and requires user interaction (clicking a link or visiting a page) to be exploited. While the code execution occurs within the sandbox, this still represents a significant security risk as sandbox escapes are a known attack progression path.

  • CVE-2026-10015HIGH 8.8

    Google Chrome versions before 148.0.7778.216 contain an integer overflow vulnerability in the WTF (Web Template Framework) component that allows attackers to execute arbitrary code within the browser's sandbox environment. An attacker can exploit this by tricking a user into visiting a specially crafted webpage, leading to potential code execution with the privileges of the browser process.

  • CVE-2026-10016HIGH 8.8

    A use-after-free flaw exists in Google Chrome's DOM implementation that allows an attacker to execute code within the browser's sandbox by tricking a user into visiting a malicious website. The vulnerability affects Chrome versions before 148.0.7778.216 and requires user interaction (clicking a link or opening a page) but does not require any special permissions or account privileges.

  • CVE-2026-10019HIGH 8.8

    A vulnerability in Google Chrome's ANGLE graphics library (versions before 148.0.7778.216) allows attackers to trick users into visiting a malicious webpage that leaks sensitive data from other websites the user is currently viewing. The flaw stems from improper handling of large numbers in memory calculations, which an attacker can exploit to read cross-origin information that should remain isolated. Users on Windows, macOS, and Linux systems running affected Chrome versions are at risk.

  • CVE-2026-10021HIGH 8.8

    Google Chrome versions before 148.0.7778.216 contain a vulnerability in USB input handling that allows attackers to execute arbitrary code on a user's computer by tricking them into visiting a malicious website. The flaw stems from insufficient validation of untrusted data, meaning Chrome doesn't properly check or sanitize input before processing it through the USB subsystem. An attacker would need to craft a deceptive HTML page and convince a user to visit it, but once clicked, the attack requires no special privileges and can fully compromise the affected system.

  • CVE-2026-10882HIGH 8.8

    Google Chrome contains a use-after-free vulnerability in its network handling code that can allow attackers to execute arbitrary code on a user's system. The flaw affects Chrome versions prior to 149.0.7827.53 and is triggered when a victim visits a specially crafted webpage. Because successful exploitation requires user interaction (visiting a malicious site), the attack surface is primarily limited to social engineering scenarios, though the browser's ubiquity makes this a meaningful threat.

  • CVE-2026-10883HIGH 8.8

    A type confusion vulnerability in Google Chrome's ANGLE graphics library allows attackers to corrupt heap memory through specially crafted web pages. The flaw requires user interaction (visiting a malicious site) but can lead to complete system compromise—confidentiality, integrity, and availability are all at risk. Chrome versions before 149.0.7827.53 are affected.

  • CVE-2026-10888HIGH 8.8

    Google Chrome versions before 149.0.7827.53 contain a use-after-free memory vulnerability in the Cast Streaming feature that allows attackers on your local network to run arbitrary code on affected machines. An attacker doesn't need valid credentials or user interaction to exploit this—just the ability to send crafted network traffic to a vulnerable Chrome instance. This is a serious vulnerability because it bridges network access to code execution on systems within the same network segment.

  • CVE-2026-10890HIGH 8.8

    Google Chrome contains a use-after-free vulnerability in its Cast functionality that could allow an attacker on your local network to corrupt the browser's memory and potentially execute malicious code. The flaw affects Chrome versions prior to 149.0.7827.53 and requires no user interaction to trigger—an attacker simply needs to send specially crafted network traffic to exploit it. This is a local network attack vector, meaning the attacker must be on the same network segment as the target system.

  • CVE-2026-10893HIGH 8.8

    A use-after-free memory vulnerability exists in Google Chrome's Chromoting remote desktop feature that could allow an attacker to run malicious code on a victim's computer through specially crafted network traffic. The flaw affects Chrome versions before 149.0.7827.53 and requires user interaction to trigger. The vulnerability has been assigned a CVSS score of 8.8 (High severity).

  • CVE-2026-10895HIGH 8.8

    A use-after-free vulnerability in Chrome's Ozone component allows attackers to run arbitrary code on a user's computer by tricking them into visiting a malicious website. The flaw exists in versions of Chrome before 149.0.7827.53 and requires user interaction (clicking a link, visiting a page) but no special privileges. Once exploited, an attacker gains full control over the affected browser process and potentially the underlying system.

  • CVE-2026-10897HIGH 8.8

    Google Chrome versions prior to 149.0.7827.53 contain a flaw in how the GPU rendering engine handles certain HTML constructs. An attacker can craft a malicious web page that, when visited by a user, exploits this flaw to break out of Chrome's security sandbox—the isolation layer that normally prevents malicious code from accessing the underlying operating system. This is a serious issue because sandbox escapes give attackers direct access to your computer's resources, files, and credentials.

  • CVE-2026-10902HIGH 8.8

    A use-after-free memory vulnerability exists in Chrome's Ozone component that allows attackers to execute arbitrary code by tricking users into visiting a specially crafted webpage. The flaw requires user interaction (clicking a link or visiting a site) but poses a critical threat because successful exploitation grants full control over the browser process and potentially the underlying system.

  • CVE-2026-10903HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's WebRTC implementation that allows an attacker to execute arbitrary code within Chrome's sandbox by convincing a user to visit a malicious website. The vulnerability affects Chrome versions prior to 149.0.7827.53 and can lead to complete compromise of the browser process, including reading sensitive data, modifying content, and disrupting availability.

  • CVE-2026-10904HIGH 8.8

    Google Chrome versions prior to 149.0.7827.53 contain a flaw in the V8 JavaScript engine that allows attackers to break out of the browser sandbox and run malicious code with full privileges. An attacker can exploit this by tricking a user into visiting a specially crafted website. Once triggered, the vulnerability bypasses Chrome's security boundary—the sandbox that normally isolates web content from the rest of the system—giving an attacker direct access to execute arbitrary code on the victim's machine.

  • CVE-2026-10907HIGH 8.8

    A memory safety vulnerability in Google Chrome's ANGLE rendering library allows an attacker to craft a malicious webpage that, when visited by a user, could corrupt the browser's memory heap. This out-of-bounds write flaw can lead to code execution with the privileges of the user running Chrome. The vulnerability requires user interaction—someone must visit the compromised or attacker-controlled page—but needs no special browser configuration or user permissions to trigger the exploit.

  • CVE-2026-10910HIGH 8.8

    Google Chrome contains a type confusion vulnerability in its V8 JavaScript engine that allows an attacker to execute arbitrary code within the browser's sandbox by sending a specially crafted HTML page to a user. The vulnerability requires user interaction (clicking a link or visiting a malicious site) but no special privileges. Once exploited, an attacker gains the ability to run code inside the sandbox, potentially leading to data theft, credential capture, or lateral movement to the underlying system.

  • CVE-2026-10913HIGH 8.8

    A use-after-free vulnerability exists in the ANGLE graphics library component of Google Chrome on Windows. An attacker can craft a malicious HTML page that, when visited by a user, triggers memory corruption within Chrome's sandbox environment. While the sandbox limits direct system compromise, successful exploitation allows arbitrary code execution within that sandboxed context, potentially leading to data theft, credential capture, or lateral movement attempts. The vulnerability requires user interaction (visiting a malicious page) but no special privileges.

  • CVE-2026-10914HIGH 8.8

    A use-after-free vulnerability in ANGLE (the graphics abstraction layer used by Chrome on Windows) allows an attacker to execute code within Chrome's sandbox by tricking a user into visiting a malicious website. The vulnerability affects Chrome versions before 149.0.7827.53 and requires user interaction (visiting a crafted HTML page) but does not require any special privileges. Once exploited, the attacker gains the capabilities of the Chrome sandbox process, which is a significant security boundary but still constrains their access compared to the host system.

  • CVE-2026-10922HIGH 8.8

    CVE-2026-10922 is a same-origin policy bypass vulnerability in Google Chrome's Developer Tools that allows an attacker to access data or perform actions they normally shouldn't be able to. The flaw stems from inadequate validation of untrusted input, meaning malicious network traffic can exploit it if a user performs certain interactions with the DevTools interface. While the attack requires user interaction, it carries significant impact—unauthorized access to sensitive information, unauthorized modifications, or disruption of services are all possible. The vulnerability affects Chrome versions prior to 149.0.7827.53 across Windows, macOS, and Linux systems.

  • CVE-2026-10926HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's Cast functionality that allows an attacker positioned on the same local network to execute arbitrary code on an affected system. The flaw requires no user interaction and can be triggered through specially crafted network traffic. This is a local network attack with high impact—an attacker gaining code execution can read sensitive data, modify system files, and disrupt operations.

  • CVE-2026-10928HIGH 8.8

    A script injection vulnerability in Google Chrome's Headless mode allows attackers to execute arbitrary code on a user's system through a malicious HTML page. The flaw requires user interaction—specifically, the victim must open a crafted webpage in an affected Chrome version—but once triggered, an attacker gains the same privileges as the user running the browser, including the ability to read files, modify data, or install malware.

  • CVE-2026-10935HIGH 8.8

    A type confusion vulnerability in Google Chrome's V8 JavaScript engine allows attackers to execute arbitrary code within the browser's sandbox by tricking users into visiting a malicious website. The vulnerability affects Chrome versions prior to 149.0.7827.53 and requires user interaction (clicking a link or visiting a page). While the code executes within the sandbox, successful exploitation could allow attackers to read, modify, or delete user data accessible to the browser.

  • CVE-2026-10936HIGH 8.8

    A type confusion flaw in Chrome's V8 JavaScript engine allows attackers to execute arbitrary code within the browser's sandbox by tricking users into viewing a specially crafted webpage. The vulnerability requires user interaction (clicking a link or visiting a site) but no authentication or special privileges. Successful exploitation could give an attacker the ability to run malicious code with the same permissions as the Chrome process.

  • CVE-2026-10939HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's WebRTC component that allows an attacker to execute arbitrary code within Chrome's sandbox by tricking a user into visiting a malicious webpage. The vulnerability affects Chrome versions prior to 149.0.7827.53 across Windows, macOS, and Linux. While the exploit requires user interaction (clicking a link or visiting a site), the impact is severe: an attacker gains code execution within the browser process.

  • CVE-2026-10941HIGH 8.8

    A memory access vulnerability in the Skia graphics engine used by Google Chrome allows attackers to run malicious code within Chrome's sandbox by tricking users into visiting a specially crafted webpage. The attack requires user interaction (clicking a link or visiting a site) but needs no special privileges. While the code runs in a sandbox environment, successful exploitation could compromise data confidentiality, integrity, and availability within that isolated context.

  • CVE-2026-10943HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's WebRTC component that allows attackers to execute arbitrary code within the browser's sandbox. An attacker can exploit this by crafting a malicious HTML page that, when visited by a user, triggers the vulnerability. Although the code execution occurs in a sandbox (limiting direct system access), the vulnerability has a CVSS score of 8.8, indicating it poses a significant risk to confidentiality, integrity, and availability. Chrome versions before 149.0.7827.53 are affected.

  • CVE-2026-10945HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's PDF handling that allows attackers to execute code within Chrome's sandbox if they can trick a user into performing specific UI interactions with a malicious PDF file. The vulnerability affects Chrome versions prior to 149.0.7827.53 across Windows, macOS, and Linux systems.

  • CVE-2026-10947HIGH 8.8

    A use-after-free bug in Google Chrome's WebRTC implementation allows attackers to execute arbitrary code within the browser's sandbox by serving a specially crafted webpage. The vulnerability affects Chrome versions before 149.0.7827.53 and requires user interaction—the victim must visit a malicious page—but once triggered, it grants an attacker near-complete control over the isolated browser process. This is a memory safety issue where freed memory is incorrectly accessed, a common source of high-impact browser exploits.

  • CVE-2026-10948HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's WebRTC implementation that allows attackers to run malicious code within the browser's sandbox by tricking users into visiting a crafted webpage. The attacker needs user interaction (clicking a link or visiting a malicious site) but requires no special privileges or system access to exploit it. Once triggered, the vulnerability grants full read, write, and execution capabilities within the sandboxed Chrome process.

  • CVE-2026-10954HIGH 8.8

    A use-after-free memory safety bug in Google Chrome's Actor component allows attackers to run malicious code within the browser's sandbox by tricking users into visiting a specially crafted web page. The vulnerability affects Chrome versions before 149.0.7827.53 and requires user interaction—specifically clicking a link or visiting a malicious site—but no special privileges. Once triggered, an attacker gains the ability to read, modify, or delete data and potentially escape the sandbox to affect the underlying operating system.

  • CVE-2026-10955HIGH 8.8

    A type confusion vulnerability exists in ANGLE, the graphics abstraction layer used by Google Chrome on Windows. An attacker can craft a malicious web page that, when visited by a user, exploits this flaw to access memory outside intended boundaries. This could lead to information disclosure, data corruption, or system crashes. The vulnerability requires user interaction (visiting a malicious page) but needs no special privileges to trigger.

  • CVE-2026-10956HIGH 8.8

    Google Chrome versions before 149.0.7827.53 contain a use-after-free vulnerability in the MimeHandlerView component that could allow an attacker to run malicious code within Chrome's sandbox. An attacker would need to trick a user into visiting a specially crafted webpage to trigger the flaw. If successful, the attacker could gain code execution inside the sandboxed process, potentially compromising user data or enabling further system compromise depending on sandbox escape possibilities.

  • CVE-2026-10957HIGH 8.8

    A use-after-free flaw in Chrome's Glic component allows attackers to execute malicious code within the browser's sandbox by tricking users into visiting a specially crafted webpage. The vulnerability requires user interaction but needs no special privileges to exploit. An attacker could gain code execution in a sandboxed context, potentially reading sensitive data or further compromising the system depending on sandbox escape capabilities.

  • CVE-2026-10962HIGH 8.8

    A type confusion vulnerability in Google Chrome's media handling allows attackers to execute malicious code within the browser's sandbox through a specially crafted webpage. The vulnerability requires user interaction (visiting a malicious page) but poses significant risk because it bypasses browser security boundaries. Chrome versions prior to 149.0.7827.53 are affected across Windows, macOS, and Linux platforms.

  • CVE-2026-10963HIGH 8.8

    A flaw in Google Chrome's V8 JavaScript engine allows attackers to run malicious code within Chrome's security sandbox by tricking users into visiting a specially crafted webpage. The vulnerability stems from an integer overflow—a mathematical error where a number becomes too large for its storage space—that can be exploited without requiring any special permissions or user complexity beyond clicking a link. While the code executes inside the sandbox rather than directly on the operating system, successful exploitation still enables attackers to potentially steal data, modify information, or degrade browser functionality.

  • CVE-2026-10964HIGH 8.8

    A flaw in Google Chrome's JavaScript engine (V8) can allow an attacker to run malicious code within the browser's sandbox by tricking a user into visiting a specially crafted webpage. The vulnerability stems from an integer overflow—a type of memory handling error—that undermines the sandbox's security boundary. While the code runs in a confined environment, this still represents a significant security risk because it can be chained with other vulnerabilities to escape the sandbox and compromise the underlying system.

  • CVE-2026-10965HIGH 8.8

    A vulnerability in Google Chrome's DevTools allows attackers to execute malicious code within Chrome's sandbox by tricking users into visiting a specially crafted webpage. The flaw stems from an integer overflow—a coding error where a number exceeds its maximum value—that can be exploited without requiring special browser settings or elevated permissions. Chrome versions before 149.0.7827.53 are affected.

  • CVE-2026-10975HIGH 8.8

    A use-after-free vulnerability in Google Chrome's WebRTC component allows an attacker to execute arbitrary code within the Chrome sandbox by tricking a user into visiting a specially crafted website. The vulnerability affects Chrome versions prior to 149.0.7827.53 and requires user interaction—specifically clicking a link or visiting a malicious page—but does not require any special privileges. Once exploited, an attacker gains the ability to run code with the same permissions as the Chrome process, potentially compromising sensitive data or escalating further.

  • CVE-2026-10978HIGH 8.8

    A use-after-free vulnerability in Google Chrome's Chromoting component allows attackers to execute arbitrary code on Windows systems. An attacker can trigger the flaw by sending specially crafted network traffic to a target who is using Chrome's remote desktop or remote assistance feature. Successful exploitation grants the attacker the same privileges as the Chrome process, potentially leading to complete system compromise. The vulnerability requires user interaction (for example, accepting a remote connection or visiting a malicious site that initiates Chromoting), but otherwise presents a direct path to code execution without requiring special system privileges or authentication.

  • CVE-2026-10982HIGH 8.8

    A use-after-free flaw in Google Chrome's WebXR implementation allows attackers to run malicious code within the browser's sandbox by tricking users into visiting a specially crafted webpage. The vulnerability affects Chrome versions before 149.0.7827.53 on Windows, macOS, and Linux. While sandboxed, successful exploitation could compromise user data and enable further attacks. User interaction (clicking a link or visiting a site) is required to trigger the vulnerability.

  • CVE-2026-10986HIGH 8.8

    A flaw in how Google Chrome processes media files can allow an attacker to execute code within Chrome's sandbox by tricking a user into opening a malicious file. The vulnerability stems from improper handling of numeric values in media processing, creating a window for code execution. While sandboxed, successful exploitation could grant an attacker access to sensitive data or control within the browser process.

  • CVE-2026-10987HIGH 8.8

    Google Chrome versions before 149.0.7827.53 contain an integer overflow flaw in the V8 JavaScript engine that allows attackers to run malicious code within Chrome's sandbox using a specially crafted webpage. An attacker would need to trick a user into visiting a malicious site, but requires no special privileges or browser plugins. The vulnerability is rated High severity.

  • CVE-2026-10991HIGH 8.8

    Google Chrome contains a use-after-free memory vulnerability in its V8 JavaScript engine that can allow an attacker to run malicious code within Chrome's sandbox. The flaw requires user interaction—specifically, the victim must perform certain UI gestures (like clicking or interacting with specific page elements) while viewing a specially crafted webpage. Once triggered, the vulnerability could allow code execution with the privileges of the Chrome process, potentially compromising the user's browsing session and data. This affects Chrome versions prior to 149.0.7827.53 across Windows, macOS, and Linux systems.

  • CVE-2026-11003HIGH 8.8

    Google Chrome versions before 149.0.7827.53 contain a use-after-free vulnerability in its WebRTC component that could allow an attacker to run arbitrary code within Chrome's sandbox by tricking a user into visiting a malicious web page. While the underlying flaw is rated Medium severity by Chromium, the CVSS score reflects the practical impact: network delivery with minimal user friction and full compromise of confidentiality, integrity, and availability within the sandboxed process.

  • CVE-2026-11024HIGH 8.8

    A stack buffer overflow vulnerability exists in the Skia graphics library, which is used by Google Chrome. An attacker could craft a malicious HTML page that, when viewed by a user, potentially corrupts stack memory and compromises the browser process. The vulnerability requires user interaction (visiting a malicious webpage) but presents significant risk because it can lead to code execution with the privileges of the Chrome process. Google Chrome versions prior to 149.0.7827.53 are affected.

  • CVE-2026-11030HIGH 8.8

    Google Chrome versions prior to 149.0.7827.53 contain a use-after-free vulnerability in the Network component that can be triggered by malicious network traffic. An attacker who crafts and delivers hostile network packets to a user's browser could potentially corrupt the heap memory, leading to code execution with the privileges of the browser process. User interaction (such as visiting a malicious website or receiving crafted network data) is required for exploitation.

  • CVE-2026-11041HIGH 8.8

    A vulnerability in Google Chrome's media handling on Windows systems allows an attacker who has already compromised Chrome's renderer process to break out of the browser's security sandbox through a specially crafted web page. This sandbox escape is the critical concern: while the attacker must first gain control of the renderer, doing so grants them access to the underlying Windows system with the privileges of the Chrome user. The vulnerability affects Chrome versions before 149.0.7827.53.

  • CVE-2026-11042HIGH 8.8

    Google Chrome versions before 149.0.7827.53 contain a use-after-free flaw in its Views component that can allow attackers to corrupt browser memory. An attacker must convince a user to perform specific interactions with a malicious webpage to trigger the vulnerability, potentially leading to code execution or data theft. While Chromium rates this as medium severity, the CVSS score of 8.8 reflects the high impact if successfully exploited.

  • CVE-2026-11046HIGH 8.8

    A flaw in Google Chrome's media handling allows an attacker who has already compromised the browser's renderer process to break out of the sandbox and run arbitrary code with full system privileges. The vulnerability stems from insufficient validation of untrusted input when processing media files, and requires user interaction (such as opening a crafted HTML page) to trigger. Chrome versions prior to 149.0.7827.53 are affected across Windows, macOS, and Linux systems.

  • CVE-2026-11049HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's Password Manager that could allow an attacker to run malicious code within Chrome's sandbox by tricking a user into visiting a specially crafted website. The flaw affects Chrome versions before 149.0.7827.53 across Windows, macOS, and Linux. While the Chromium project rates this as medium severity, the CVSS score of 8.8 reflects the combination of network accessibility, lack of authentication requirements, and potential for high-impact code execution.

  • CVE-2026-11050HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's V8 JavaScript engine that allows attackers to execute arbitrary code within the browser's sandbox by tricking users into visiting a malicious webpage. The flaw requires user interaction (clicking a link or visiting a site) but needs no special privileges to exploit. While Chromium's security team rated this as medium severity internally, the CVSS score of 8.8 reflects the high impact if successfully exploited—attackers could steal data, modify content, or crash the browser.

  • CVE-2026-11054HIGH 8.8

    A use-after-free memory flaw in Chrome's WebRTC component allows an attacker to execute arbitrary code within the browser's sandbox by tricking a user into visiting a malicious webpage. The vulnerability affects Chrome versions prior to 149.0.7827.53 and impacts multiple operating systems including Windows, macOS, and Linux. Successful exploitation requires user interaction (clicking a link or visiting a site) but can lead to complete compromise of the affected browser process.

  • CVE-2026-11055HIGH 8.8

    A use-after-free vulnerability in ANGLE (Google's graphics library) affects Chrome on Windows systems prior to version 149.0.7827.53. An attacker can craft a malicious webpage that, when visited, executes arbitrary code within Chrome's sandbox environment. While the Chromium team rated this as medium severity internally, the CVSS score of 8.8 reflects the practical impact: any user visiting a hostile site is at risk, no user interaction beyond clicking a link is required, and successful exploitation grants code execution.

  • CVE-2026-11059HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's Blink rendering engine that allows attackers to execute arbitrary code within the browser's sandbox by tricking users into visiting a malicious website. The flaw affects Chrome versions prior to 149.0.7827.53 and requires user interaction (clicking a link or visiting a page) but poses significant risk because successful exploitation grants an attacker the ability to run code with the privileges of the Chrome process.

  • CVE-2026-11060HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's media handling on Windows systems. An attacker can craft a malicious HTML page that, when visited by a user, exploits this flaw to execute arbitrary code within Chrome's sandbox. While the sandbox provides a layer of isolation, successful exploitation would still allow the attacker to run code with the privileges of the Chrome process, potentially leading to data theft, credential capture, or lateral movement to the system itself.

  • CVE-2026-11068HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's WebSocket implementation that could allow an attacker to execute arbitrary code within the browser's sandbox by tricking a user into visiting a malicious webpage. The flaw affects Chrome versions before 149.0.7827.53 and impacts Windows, macOS, and Linux systems. While the underlying code defect is classified as Medium severity by the Chromium project, the CVSS score of 8.8 reflects the practical risk: an attacker needs only to convince a user to visit a crafted page, requires no special privileges, and can achieve full code execution within the sandbox boundary.

  • CVE-2026-11076HIGH 8.8

    A type confusion vulnerability in Google Chrome's CSS handling allows attackers to execute malicious code within the browser's sandbox by tricking users into visiting a specially crafted webpage. The vulnerability affects Chrome versions prior to 149.0.7827.53 and requires user interaction (clicking a link or visiting a site), but once triggered, grants the attacker code execution capabilities despite the sandbox protections that normally isolate the browser from the rest of the system.

  • CVE-2026-11077HIGH 8.8

    A flaw in the Dawn graphics component of Google Chrome allows attackers to run malicious code within the browser's sandbox by tricking users into visiting a specially crafted website. The vulnerability requires user interaction (clicking a link or visiting a page) but doesn't require any special privileges. Once exploited, an attacker gains the same permissions as the Chrome process, potentially allowing them to steal data or compromise the system.

  • CVE-2026-11079HIGH 8.8

    Google Chrome contains a vulnerability in its video codec handling that allows attackers to write data outside the intended memory boundaries. An attacker can exploit this by crafting a malicious video file and tricking a user into opening it, potentially allowing the attacker to execute arbitrary code, steal sensitive information, or crash the browser. This affects Chrome versions prior to 149.0.7827.53 across Windows, macOS, and Linux systems.

  • CVE-2026-11086HIGH 8.8

    A vulnerability in Google Chrome's Dawn graphics component allows an attacker who has already compromised the browser's renderer process to break out of the sandbox and execute arbitrary code with full system privileges. The attack requires user interaction (opening a malicious HTML page), but once triggered, it completely undermines Chrome's security architecture. Chrome versions prior to 149.0.7827.53 are affected on Windows, macOS, and Linux systems.

  • CVE-2026-11091HIGH 8.8

    A flaw in Google Chrome's graphics rendering engine (Dawn) allows attackers to trick users into visiting malicious web pages that can read sensitive data, modify files, or crash the browser. The vulnerability requires user interaction—specifically clicking a link or visiting a crafted website—but once triggered, it bypasses Chrome's memory protections. This affects Chrome versions before 149.0.7827.53 across Windows, macOS, and Linux.

  • CVE-2026-11092HIGH 8.8

    A flaw in Google Chrome's developer tools (DevTools) fails to properly enforce security policies, allowing an attacker to escalate privileges if they can trick a user into installing a malicious browser extension. The vulnerability affects Chrome versions before 149.0.7827.53 across Windows, macOS, and Linux. While the attacker needs user interaction (installing the extension), the resulting privilege escalation grants them high-impact access to the browser process and potentially sensitive data.

  • CVE-2026-11116HIGH 8.8

    Google Chrome contains a use-after-free memory vulnerability in its Chromoting remote desktop feature that can be triggered by malicious network traffic. An attacker can send specially crafted packets to a targeted user, leading to arbitrary code execution on the victim's machine. The vulnerability requires user interaction—specifically, the user must be engaged in an active Chromoting session—but once triggered, it grants the attacker the same privileges as the Chrome process.

  • CVE-2026-11117HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's Views component on Windows systems. An attacker can exploit this flaw by crafting a malicious HTML page that, when visited by a user, allows remote code execution on the victim's machine. The vulnerability affects Chrome versions prior to 149.0.7827.53 and requires user interaction (visiting a malicious site), but once triggered, grants the attacker full system compromise capabilities.

  • CVE-2026-11118HIGH 8.8

    A memory safety vulnerability exists in Google Chrome's WebRTC implementation that could allow attackers to run malicious code within the browser's sandbox. The flaw stems from a use-after-free condition—where the browser continues using memory that has already been freed—which can be triggered by visiting a specially crafted webpage. No special permissions or user interaction beyond clicking a link or viewing a page are required, making this a significant remote code execution risk despite being contained within the sandbox.

  • CVE-2026-11124HIGH 8.8

    A memory handling flaw in Chrome's Skia graphics library allows attackers to trigger heap corruption by serving a specially crafted webpage. The vulnerability requires user interaction (visiting a malicious page) but needs no special privileges and works across all major operating systems where Chrome runs. An attacker could achieve code execution with full system access—reading files, modifying data, installing malware, or pivoting to other systems.

  • CVE-2026-11125HIGH 8.8

    A use-after-free memory flaw in Google Chrome's compositing system allows attackers to run arbitrary code within Chrome's sandbox by tricking users into visiting a malicious webpage. The vulnerability affects Chrome versions before 149.0.7827.53 across Windows, macOS, and Linux. While contained by the sandbox, successful exploitation could grant an attacker the same privileges as the Chrome process, potentially compromising sensitive browser data and operations.

  • CVE-2026-11130HIGH 8.8

    A use-after-free vulnerability in Google Chrome's media handling allows attackers to run malicious code within Chrome's sandbox by tricking users into visiting a specially crafted website. While the underlying Chromium project rates this as Medium severity, the CVSS score of 8.8 reflects the practical risk: it requires user interaction (clicking a link or visiting a site), but once triggered, it can lead to full compromise of the Chrome process, potentially exposing sensitive data or enabling further attacks on the underlying system.

  • CVE-2026-11136HIGH 8.8

    Google Chrome versions prior to 149.0.7827.53 contain a use-after-free vulnerability in the Canvas component that allows attackers to execute arbitrary code within the browser sandbox. An attacker can exploit this flaw by crafting a malicious HTML page that, when visited by a user, triggers memory corruption and leads to code execution. The vulnerability requires user interaction (visiting a webpage) but needs no special privileges to trigger.

  • CVE-2026-11144HIGH 8.8

    A use-after-free memory flaw in Google Chrome's media handling allows an attacker to execute malicious code within Chrome's sandbox by tricking a user into opening a specially crafted video file. While sandboxed, successful exploitation could still grant an attacker significant control over the affected browser process and potentially access to sensitive user data.

  • CVE-2026-11147HIGH 8.8

    A use-after-free vulnerability exists in Chrome's WebML (Web Machine Learning) component on Windows. An attacker can craft a malicious HTML page that, when visited by a user, triggers code execution within Chrome's sandbox. Although the sandbox contains the damage, the vulnerability allows an attacker to breach browser process isolation and execute arbitrary code with the privileges of the Chrome renderer process.

  • CVE-2026-11164HIGH 8.8

    A use-after-free vulnerability exists in Blink, Google Chrome's rendering engine, affecting versions prior to 149.0.7827.53. An attacker can craft a malicious HTML page that, when visited by a user, exploits this memory safety flaw to execute arbitrary code within the Chrome sandbox. While sandboxed, successful exploitation grants an attacker code execution capabilities on the victim's machine, potentially enabling further compromise.

  • CVE-2026-11171HIGH 8.8

    A flaw in Blink, the rendering engine behind Google Chrome, allows attackers to trigger an integer overflow by sending a specially crafted web page. If a user visits a malicious site, the attacker can run malicious code within Chrome's sandbox. While the sandbox limits damage, this vulnerability bypasses a critical security boundary and is rated HIGH severity.

  • CVE-2026-11173HIGH 8.8

    A memory writing vulnerability in Google Chrome's V8 JavaScript engine (used to execute web code) allows a specially crafted webpage to trigger an out-of-bounds write operation. An attacker who has already compromised the browser's rendering process can exploit this flaw to break out of the sandbox and run arbitrary code with the privileges of the Chrome process. This requires an attacker to first gain control of the renderer, making it a post-compromise escalation vector rather than a direct entry point.

  • CVE-2026-11177HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's Omnibox (the combined address and search bar). An attacker can craft a malicious HTML page that, when a user performs specific interactions with the Omnibox, triggers memory corruption. Successful exploitation requires user interaction—the attacker cannot silently compromise a machine, but if a targeted user visits a crafted page and engages with the address bar in a particular way, the attacker could potentially execute arbitrary code with the privileges of the Chrome process.

  • CVE-2026-11179HIGH 8.8

    Google Chrome versions before 149.0.7827.53 contain a flaw in the Object Request Broker (ORB) feature that allows attackers to bypass site isolation—a critical Chrome security boundary that prevents websites from accessing each other's data. An attacker can exploit this by hosting a malicious HTML page that, when visited by a user, breaks through site isolation and gains unauthorized access to sensitive information from other open tabs or windows. The vulnerability requires user interaction (visiting the crafted page) but demands no special privileges, making it a practical concern for any Chrome user.

  • CVE-2026-11191HIGH 8.8

    A memory safety flaw in Chrome's ANGLE graphics library allows attackers to access memory beyond intended boundaries when a user visits a malicious webpage. An attacker can craft HTML that exploits this out-of-bounds read or write to leak sensitive data, crash the browser, or execute code with the privileges of the Chrome process. The vulnerability affects Chrome versions prior to 149.0.7827.53 across Windows, macOS, and Linux.

  • CVE-2026-11201HIGH 8.8

    Google Chrome versions prior to 149.0.7827.53 contain a use-after-free vulnerability in the ServiceWorker component that allows arbitrary code execution. The vulnerability requires an attacker to convince a user to install a malicious Chrome extension, after which the attacker can exploit memory handling flaws to run code with the privileges of the browser. This is not a vulnerability in the browser itself that users encounter passively—it requires social engineering to trick a user into voluntarily installing a compromised extension.

  • CVE-2026-11211HIGH 8.8

    A flaw in Google Chrome's V8 JavaScript engine allows attackers to run malicious code with limited privileges inside Chrome's sandbox by tricking users into visiting a specially crafted website. While the malicious code runs in a restricted environment, the sandbox breach itself represents a significant security boundary violation that could be chained with other exploits to gain fuller system control.

  • CVE-2026-11230HIGH 8.8

    Google Chrome versions prior to 149.0.7827.53 contain a use-after-free vulnerability in the Extensions subsystem that could allow an attacker to execute arbitrary code within Chrome's sandbox. An attacker would need to trick a user into visiting a malicious HTML page. While Chromium initially categorized this as low severity, the CVSS score reflects the real-world impact: complete compromise of confidentiality, integrity, and availability within the sandboxed context.

  • CVE-2026-11235HIGH 8.8

    Google Chrome versions prior to 149.0.7827.53 contain a sandbox escape vulnerability in the compositing system. An attacker who successfully compromises Chrome's renderer process (the sandboxed component responsible for rendering web content) can exploit insufficient policy enforcement to execute arbitrary code with elevated privileges, bypassing the sandbox entirely. The attack requires a crafted HTML page and user interaction, making it a post-compromise threat rather than a direct entry point. While Chromium rated this Low severity, the CVSS score of 8.8 reflects the critical nature of sandbox escapes, which transform a contained renderer compromise into full system code execution.

  • CVE-2026-11248HIGH 8.8

    CVE-2026-11248 is a bypass vulnerability in Google Lens, a feature within Chrome that allows users to perform visual searches. An attacker can craft a malicious webpage that, when visited by a user, circumvents Chrome's navigation security controls. This means a user could be redirected to an unintended destination or prevented from safely navigating away. The vulnerability requires user interaction—the user must visit the attacker's page—but once there, the attack happens automatically. Google has patched this in Chrome 149.0.7827.53 and later.

  • CVE-2026-11262HIGH 8.8

    A use-after-free vulnerability exists in Google Chrome's TabStrip component that allows attackers to execute arbitrary code on a victim's machine. The flaw requires user interaction—specifically, visiting a malicious webpage—but once triggered, grants full code execution privileges. Chrome versions prior to 149.0.7827.53 are affected. Despite Chromium's internal severity rating of 'Low', the CVSS 3.1 score reflects the real-world impact: remote code execution with no authentication needed, complete compromise of confidentiality, integrity, and availability.

  • CVE-2026-11279HIGH 8.8

    Google Chrome versions prior to 149.0.7827.53 contain an out-of-bounds read vulnerability in the DevTools component that allows an attacker to execute arbitrary code within the Chrome sandbox. An attacker would need to trick a user into visiting a crafted HTML page, but would not need any special privileges or system access. While Chromium's internal severity assessment is Low, the CVSS 3.1 score of 8.8 reflects the high severity due to the potential for code execution within a restricted sandbox environment.

  • CVE-2026-11301HIGH 8.8

    A vulnerability in Google Chrome's LiveCaption feature allows attackers to access memory outside safe boundaries by sending specially crafted network traffic. While Chrome assigned this a low severity rating internally, the vulnerability can lead to information disclosure, data corruption, or system crashes depending on what memory region is accessed. The attack requires user interaction—the user must be running a vulnerable Chrome version and receive the malicious traffic—but no special privileges are needed from the attacker's perspective.

  • CVE-2026-11303HIGH 8.8

    A use-after-free vulnerability in PDFium, the PDF rendering engine embedded in Google Chrome, allows attackers to execute arbitrary code within Chrome's sandbox by tricking users into opening a specially crafted PDF file. While the vulnerability requires user interaction (opening a malicious PDF), the impact is severe: an attacker gains code execution inside the sandboxed Chrome process, potentially leading to data theft, system compromise, or further exploitation. The vulnerability affects Chrome versions prior to 149.0.7827.53 across Windows, macOS, and Linux platforms.

  • CVE-2026-11304HIGH 8.8

    A use-after-free flaw in PDFium, the PDF rendering engine used by Google Chrome, allows attackers to corrupt heap memory when a user opens a specially crafted PDF file. An attacker could exploit this to potentially execute arbitrary code or crash the browser. The vulnerability requires user interaction (opening a malicious PDF) but is otherwise straightforward to exploit remotely.

  • CVE-2026-11305HIGH 8.8

    A use-after-free flaw in PDFium, the PDF rendering engine embedded in Google Chrome, allows attackers to execute arbitrary code within Chrome's sandbox by tricking users into opening a malicious PDF file. The vulnerability affects Chrome versions prior to 149.0.7827.53 across Windows, macOS, and Linux. While Chromium assigned this a Low security severity rating, the CVSS score of 8.8 reflects the practical risk: a remote attacker needs only a crafted PDF and user interaction to achieve code execution with high impact on confidentiality, integrity, and availability.

  • CVE-2026-11306HIGH 8.8

    A memory safety bug in Google Chrome's PDF rendering engine (PDFium) allows attackers to run malicious code within Chrome's sandbox by sending a victim a specially crafted PDF file. The attacker needs the user to open the PDF—there's no way to trigger this remotely without interaction. While the Chromium team rated the issue as Low severity internally, the actual impact is significant: an attacker gains arbitrary code execution within the browser sandbox, potentially stealing data or performing other malicious actions. This affects Chrome on Windows, macOS, and Linux.

  • CVE-2026-11307HIGH 8.8

    A use-after-free memory bug in PDFium—the PDF rendering library bundled with Google Chrome—allows attackers to run arbitrary code within Chrome's sandbox by sending a malicious PDF file. The vulnerability requires user interaction (opening the PDF) but can fully compromise a victim's browser process, stealing data or installing malware. While Google rated this as low severity internally, the CVSS score of 8.8 reflects the serious consequences: an attacker gains code execution with high impact to confidentiality, integrity, and availability.

  • CVE-2026-11629HIGH 8.8

    A use-after-free vulnerability in Google Chrome's Ozone component allows attackers to crash the browser or corrupt its memory by tricking users into visiting a specially crafted webpage. The attacker needs the victim to click a link or visit a malicious site—no special privileges are required. Chrome versions before 149.0.7827.103 are affected.

  • CVE-2026-11630HIGH 8.8

    Google Chrome versions prior to 149.0.7827.103 contain a use-after-free vulnerability in its file input handling. An attacker can craft a malicious HTML page that, when visited by a user, triggers improper memory management in Chrome's file handling code. This allows the attacker to corrupt memory on the victim's computer, potentially leading to arbitrary code execution. The vulnerability requires user interaction (visiting a malicious webpage) but affects users across Windows, macOS, and Linux systems.

  • CVE-2026-11646HIGH 8.8

    A use-after-free flaw in Google Chrome's ViewTransitions feature allows attackers to run arbitrary code within Chrome's sandbox by tricking users into visiting a malicious website. The vulnerability exists in Chrome versions before 149.0.7827.103 and requires user interaction—specifically clicking or otherwise engaging with a crafted HTML page. While the code runs in a sandboxed environment (limiting direct system access), it still represents a significant threat because sandbox escapes are a known attack progression.

  • CVE-2026-11648HIGH 8.8

    A use-after-free memory flaw exists in Google Chrome's full-screen functionality on Windows. An attacker can craft a malicious web page that, when visited, exploits this flaw to corrupt the browser's memory heap. This could allow the attacker to execute arbitrary code on the victim's machine with the same privileges as the user running Chrome. The vulnerability requires user interaction (clicking or navigating to the malicious page) but no special privileges or complex setup.

  • CVE-2026-11649HIGH 8.8

    Google Chrome versions before 149.0.7827.103 contain a use-after-free vulnerability in the V8 JavaScript engine that allows attackers to execute arbitrary code within the Chrome sandbox by serving a malicious HTML page. The flaw requires user interaction (clicking a link or visiting a site) but does not require special privileges. While the sandbox limits the immediate blast radius, successful exploitation could grant an attacker control over the browser process and access to user data like credentials, session tokens, and browsing history.

  • CVE-2026-11650HIGH 8.8

    A use-after-free flaw in Google Chrome's V8 JavaScript engine allows attackers to execute arbitrary code within the browser's sandbox by tricking users into visiting a malicious website. The vulnerability affects Chrome versions before 149.0.7827.103 and requires user interaction (clicking a link or visiting a page). While the code runs in a sandboxed environment, successful exploitation could allow attackers to break out of the sandbox or pivot to other browser features, making this a serious but not trivial attack vector.

  • CVE-2026-11662HIGH 8.8

    A type confusion vulnerability in Google Chrome's bindings mechanism allows attackers to execute arbitrary code within the Chrome sandbox by serving a specially crafted HTML page. The flaw affects Chrome versions before 149.0.7827.103 and requires user interaction (visiting a malicious page) to trigger. While sandboxed, successful exploitation could lead to complete compromise of the affected Chrome process, including data theft and system-level attacks if combined with additional vulnerabilities.