By severity
High-severity vulnerabilities
CVEs rated High by CVSS, with SEC.co remediation and prioritization guidance.
1343 published vulnerabilities · page 5 of 14
- CVE-2026-10898HIGH 8.3
A stack buffer overflow vulnerability exists in the GPU component of Google Chrome versions prior to 149.0.7827.53. An attacker who has already compromised Chrome's renderer process can exploit this flaw through a malicious HTML page to break out of the browser sandbox and gain system-level code execution. While the attacker must first compromise the renderer—typically through a separate browser vulnerability or social engineering—the sandbox escape itself represents a critical escalation path that transforms a contained compromise into full system compromise.
- CVE-2026-10905HIGH 8.3
A memory safety flaw in Google Chrome's network code allows an attacker who has already compromised the browser's renderer process to escape the sandbox and gain full system access. The vulnerability requires user interaction (opening a malicious HTML page) but poses significant risk because successful exploitation bypasses Chrome's core security boundary—the sandbox that isolates the browser from the operating system.
- CVE-2026-10908HIGH 8.3
A use-after-free vulnerability exists in Google Chrome's full-screen functionality on Windows systems. An attacker who has already compromised Chrome's rendering engine could exploit a specially crafted web page to escape the browser sandbox and execute arbitrary code with higher privileges. This requires the attacker to have initial renderer process access, but once achieved, the flaw could allow them to run code outside the sandbox protection layer.
- CVE-2026-10909HIGH 8.3
A use-after-free vulnerability in Google Chrome's Dawn graphics engine allows an attacker who has already compromised the browser's renderer process to escape the sandbox through a malicious webpage. This is a high-severity issue because it bridges two separate security boundaries—first gaining control within Chrome's renderer, then breaking out to execute arbitrary code on the underlying operating system.
- CVE-2026-10911HIGH 8.3
CVE-2026-10911 is a sandbox escape vulnerability in Google Chrome that allows a remote attacker to break out of the browser's security sandbox if they have already compromised the renderer process. The attack requires crafted HTML content and user interaction, but once successful, it grants an attacker full system access. This is a chained attack scenario: an attacker must first compromise the renderer (the part of Chrome that displays web content) through a separate vulnerability, then use this flaw to escape the sandbox and gain control of the underlying system.
- CVE-2026-10915HIGH 8.3
A use-after-free memory vulnerability exists in Google Chrome on iOS that allows an attacker who has already compromised the browser's renderer process to break out of the sandbox and gain deeper system access. The vulnerability requires the attacker to serve a specially crafted HTML page and involves a complex attack chain but poses severe risk because successful exploitation can lead to full compromise of the device. Chrome versions prior to 149.0.7827.53 on iOS are affected.
- CVE-2026-10917HIGH 8.3
Google Chrome versions before 149.0.7827.53 contain a media handling flaw that allows an attacker who has already compromised the browser's renderer process to escape the sandbox and gain broader system access. The vulnerability requires user interaction (visiting a specially crafted webpage) but poses a significant risk because renderer compromises are common entry points in real attacks. Once inside the renderer, the flaw gives an attacker a path to elevated privileges on the underlying operating system.
- CVE-2026-10918HIGH 8.3
A use-after-free vulnerability in Google Chrome's Viz component allows an attacker who has already compromised the browser's renderer process to potentially escape the sandbox and gain deeper system access. The attacker would need to trick a user into visiting a malicious webpage, but the actual exploitation requires prior renderer compromise, making this a multi-stage attack. While not currently known to be exploited in the wild, the vulnerability represents a meaningful privilege escalation path for sophisticated threat actors who have achieved initial browser process compromise.
- CVE-2026-10919HIGH 8.3
A use-after-free bug in Chrome's ANGLE graphics library before version 149.0.7827.53 allows an attacker who already controls the browser's rendering process to break out of the sandbox and gain full system access. The attacker must trick a user into visiting a malicious webpage, but once the renderer is compromised, this flaw provides a path to escape Chrome's isolation boundaries.
- CVE-2026-10920HIGH 8.3
A validation flaw in Chrome's WebShare feature on macOS allows an attacker who has already compromised the browser's renderer process to break out of the sandbox through a specially crafted webpage. This is a post-compromise privilege escalation risk—the attacker must first gain code execution within the renderer, but if successful, can gain full system access. Chrome versions before 149.0.7827.53 are affected.
- CVE-2026-10921HIGH 8.3
A flaw in Google Chrome's graphics processing library (Dawn) could allow an attacker to break out of the browser's security sandbox if they've already compromised the rendering engine. The vulnerability stems from an integer overflow—a situation where a number calculation wraps around and produces an incorrect value—that could be triggered by a specially crafted webpage. While the attacker would need to have already gained access to the renderer process, successfully exploiting this could grant them the same privileges as the operating system user running Chrome, potentially leading to full system compromise.
- CVE-2026-10924HIGH 8.3
A mathematical error in Chrome's Chromecast component allows an attacker who has already compromised Chrome's rendering engine to break out of the browser sandbox and gain full system access. The attacker needs to trick a user into visiting a malicious webpage while the renderer is already compromised. This is a serious vulnerability because sandbox escape means the attacker moves from limited browser permissions to unrestricted control of the entire device.
- CVE-2026-10925HIGH 8.3
A memory corruption flaw exists in the Skia graphics library within Google Chrome on macOS. An attacker who has already compromised Chrome's renderer process can exploit this out-of-bounds write to break out of the browser sandbox and gain system-level access. The attack requires user interaction (visiting a malicious webpage) but bypasses Chrome's primary security boundary once the renderer is under attacker control.
- CVE-2026-10927HIGH 8.3
A memory reading flaw in Google Chrome's graphics component (Dawn) prior to version 149.0.7827.53 allows attackers who have already compromised the browser's renderer process to escape the sandbox through a specially crafted webpage. This is a two-stage attack: first an attacker must find a way into the renderer, then this vulnerability allows them to break out entirely.
- CVE-2026-10929HIGH 8.3
A memory safety flaw in ANGLE (the graphics abstraction layer used by Chrome) allows an attacker who has already compromised Chrome's sandboxed renderer process to escape that sandbox and gain full system access on Android devices. The attacker must trick a user into visiting a malicious webpage. This affects Chrome versions prior to 149.0.7827.53 on Android.
- CVE-2026-10933HIGH 8.3
A use-after-free vulnerability exists in Google Chrome's audio processing component on Windows systems. An attacker who has already compromised Chrome's renderer process could exploit this flaw through a specially crafted web page to escape the browser sandbox and gain higher privileges on the system. This requires an initial renderer compromise, but if successful, could lead to full system takeover.
- CVE-2026-10934HIGH 8.3
Google Chrome on Android contains a use-after-free vulnerability in its Autofill feature that could allow an attacker to escape the browser sandbox. The flaw requires an attacker to first compromise Chrome's renderer process—the component responsible for parsing and displaying web content—and then trick a user into visiting a malicious webpage. If successful, the attacker could break out of Chrome's security sandbox and gain broader access to the device. This vulnerability affects Chrome versions prior to 149.0.7827.53 on Android.
- CVE-2026-10940HIGH 8.3
A race condition vulnerability in Chrome's media codec handling allows an attacker who has already compromised Chrome's renderer process to escape the browser sandbox on Windows systems. The attacker would need to trick a user into visiting a specially crafted website, but once the renderer is compromised, this flaw could give the attacker full system-level access. Chrome versions before 149.0.7827.53 on Windows are affected.
- CVE-2026-10949HIGH 8.3
A heap buffer overflow vulnerability in Google Chrome's video handling component allows an attacker who has already compromised Chrome's renderer process to escape the browser sandbox and gain system-level access. The attacker would need to craft a malicious HTML page to trigger the overflow, but exploitation requires the renderer to be already compromised—making this a post-compromise escape vector rather than a direct attack from an untrusted webpage. Chrome versions before 149.0.7827.53 are vulnerable on Windows, macOS, and Linux systems.
- CVE-2026-10953HIGH 8.3
A use-after-free vulnerability exists in Google Chrome for Android versions prior to 149.0.7827.53. An attacker who has already compromised Chrome's renderer process can exploit this flaw by crafting a malicious HTML page to break out of the browser sandbox and gain system-level access to the Android device. This is a post-compromise escalation risk rather than a direct entry point, but it significantly amplifies the impact of any renderer exploit.
- CVE-2026-10960HIGH 8.3
CVE-2026-10960 is a sandbox escape vulnerability in Google Chrome's video codec handling. An attacker who has already compromised Chrome's renderer process—the sandboxed component responsible for processing web content—can exploit an uninitialized variable in the codec logic to break out of the sandbox and gain full system access. The attack requires a crafted HTML page and user interaction, but once the renderer is compromised, the attacker can leverage this flaw to escalate to native code execution outside Chrome's security boundary.
- CVE-2026-10961HIGH 8.3
Chrome for iOS users running versions prior to 149.0.7827.53 face a critical sandbox escape vulnerability. A malicious website can exploit a use-after-free memory flaw to break out of Chrome's security sandbox if the attacker first compromises the renderer process—the component that handles webpage content. Once the sandbox is escaped, an attacker gains direct access to the device, potentially leading to theft of credentials, personal data, or malware installation. The vulnerability requires user interaction (visiting a crafted page) but is otherwise remotely exploitable.
- CVE-2026-10967HIGH 8.3
A use-after-free flaw exists in Chrome's SurfaceCapture feature on Android that allows an attacker to escape the browser sandbox. The vulnerability requires the attacker to first compromise Chrome's renderer process and then trick a user into visiting a malicious webpage. If successful, the attacker could break out of Chrome's security sandbox and gain elevated privileges on the device. This affects Chrome versions before 149.0.7827.53 on Android.
- CVE-2026-10970HIGH 8.3
Google Chrome versions prior to 149.0.7827.53 contain a vulnerability in how the browser validates input data related to Interest Groups—a feature used for targeted advertising. An attacker who has already compromised Chrome's renderer process (the part that executes web content) can exploit insufficient input validation to break out of the browser's sandbox—the security boundary designed to isolate web content from the rest of your system. This requires the attacker to first gain renderer access and trick a user into visiting a crafted webpage, but if successful, allows full control over the victim's machine.
- CVE-2026-11010HIGH 8.3
A use-after-free memory safety bug in Chrome's WebShare feature on Android allows an attacker who has already compromised the browser's renderer process to escape the sandbox and gain elevated system privileges by tricking a user into visiting a malicious webpage. While the initial compromise requires the renderer to already be under attacker control, the sandbox escape represents a critical escalation path.
- CVE-2026-11012HIGH 8.3
A use-after-free vulnerability exists in Google Chrome's Serial API on Android devices running versions before 149.0.7827.53. An attacker who has already compromised Chrome's renderer process can exploit this flaw by serving a specially crafted HTML page to achieve a sandbox escape—breaking out of Chrome's security isolation layer. While the underlying Chromium issue is rated Medium severity by Google, the CVSS 3.1 score of 8.3 reflects the HIGH impact potential when combined with renderer compromise.
- CVE-2026-11040HIGH 8.3
A use-after-free flaw in Chrome's ANGLE graphics library allows attackers who have already compromised your browser's renderer process to escape the sandbox and gain full system access via a specially crafted webpage. Chrome versions before 149.0.7827.53 are vulnerable. The attack requires the renderer to be compromised first, but if successful, can completely undermine Chrome's security isolation.
- CVE-2026-11236HIGH 8.3
Google Chrome versions before 149.0.7827.53 contain a flaw in how it enforces security policies for Web Bluetooth functionality. If an attacker has already compromised Chrome's rendering process (the part that runs web content), they could exploit this weakness to break out of Chrome's sandbox—the security boundary that isolates the browser from the rest of your system. An attacker would need to trick a user into visiting a specially crafted webpage while the renderer is already compromised. This is a chaining risk: the vulnerability itself requires a prior compromise, but once chained together, it enables full system access.
- CVE-2026-11237HIGH 8.3
Google Chrome versions before 149.0.7827.53 contain a vulnerability that allows an attacker who has already compromised Chrome's renderer process to trick users through fake or misleading interface elements displayed on a web page. While the underlying flaw is rated 'Low' severity by Chromium, the impact assessment reflects the potential for convincing visual deception attacks that could mislead users into taking harmful actions.
- CVE-2026-11256HIGH 8.3
CVE-2026-11256 is a sandbox escape vulnerability in Google Chrome's GPU processing that affects versions prior to 149.0.7827.53. An attacker who has already compromised Chrome's renderer process can exploit an integer overflow in GPU code to break out of the browser sandbox and execute arbitrary code with higher privileges. The attack requires user interaction (visiting a malicious HTML page) and successful prior compromise of the renderer, making it a post-compromise escalation vector rather than a direct remote code execution path.
- CVE-2026-11631HIGH 8.3
Google Chrome on Windows contains a use-after-free vulnerability in its Aura rendering subsystem that could allow an attacker to break out of the browser's sandbox. The flaw requires an attacker to first compromise the renderer process—typically through a separate vulnerability or exploit—and then use a malicious webpage to trigger memory corruption that escapes the sandbox. This is a post-exploitation technique rather than a direct entry point, but the consequence is severe: attackers could gain system-level access beyond Chrome's normal security boundaries.
- CVE-2026-11635HIGH 8.3
A use-after-free memory vulnerability exists in the Bluetooth component of Google Chrome on macOS. An attacker who already compromises a website's renderer process can exploit this flaw through a specially crafted HTML page to escape the browser sandbox and run code at system level. This is a chained attack—the initial compromise of the renderer process is prerequisite, but once achieved, the vulnerability enables full sandbox bypass with high impact.
- CVE-2026-11640HIGH 8.3
A mathematical error in Google Chrome's image processing library (libyuv) can be exploited by attackers who have already compromised the browser's sandbox. By crafting a malicious HTML page, they can trigger an integer overflow that potentially breaks out of Chrome's security sandbox entirely, gaining full system access. This requires the attacker to have already penetrated the renderer process first, making it a second-stage attack rather than a direct entry point.
- CVE-2026-11642HIGH 8.3
Google Chrome prior to version 149.0.7827.103 contains a use-after-free vulnerability in its web application handling that could allow a remote attacker to escape the browser's sandbox. The attack requires the attacker to first compromise the renderer process—a separate security boundary within Chrome—and then trick a user into visiting a malicious website. If successful, the attacker could potentially gain system-level access, though the vulnerability itself is triggered through browser interaction rather than automatic exploitation.
- CVE-2026-11647HIGH 8.3
A use-after-free memory vulnerability in Chrome's printing functionality on Android allows an attacker who has already compromised a renderer process to escape the sandbox and gain higher privileges. The attacker would need to trick a user into viewing a malicious HTML page, but the actual exploitation requires pre-existing renderer compromise, making this a high-severity but technically constrained attack chain.
- CVE-2026-11652HIGH 8.3
Google Chrome versions before 149.0.7827.103 contain a use-after-free vulnerability in its extension handling code that could allow an attacker to escape the browser sandbox. An attacker who has already compromised the Chrome renderer process—the isolated process that runs website code—could exploit this flaw by crafting a malicious HTML page to gain code execution outside the sandbox, potentially compromising the entire system. The vulnerability requires user interaction (such as visiting a malicious site) and a prior renderer compromise, making it a secondary exploitation vector rather than a direct entry point.
- CVE-2026-11655HIGH 8.3
A mathematical error in how Google Chrome handles media files on macOS allows an attacker to escape the browser's sandbox if they've already compromised Chrome's rendering engine. The vulnerability exists in versions before 149.0.7827.103 and requires a specially crafted webpage to trigger. Once exploited, an attacker could move from the restricted sandbox environment to full system access.
- CVE-2026-11656HIGH 8.3
A use-after-free vulnerability exists in Google Chrome's ServiceWorker component that could allow attackers to escape the browser sandbox if they can trick a user into installing a malicious Chrome extension. The vulnerability affects Chrome versions before 149.0.7827.103 and requires user interaction to install the extension, but successful exploitation would grant an attacker access to the underlying system beyond Chrome's normal security boundaries.
- CVE-2026-11660HIGH 8.3
A vulnerability in Google Chrome's New Tab Page feature allows an attacker who has already compromised Chrome's renderer process to escape the browser sandbox using a specially crafted HTML page. This is a critical privilege escalation risk because sandbox escapes can lead to full system compromise. The vulnerability affects Chrome versions before 149.0.7827.103 across Windows, macOS, and Linux.
- CVE-2026-11661HIGH 8.3
A use-after-free flaw in Google Chrome's Views component on Windows allows a remote attacker to escape the browser's sandbox if the renderer process has already been compromised. The attacker would need to craft a malicious HTML page to trigger the vulnerability. This is a post-compromise escalation risk: while initial renderer compromise is required, successful exploitation grants code execution outside the sandbox, elevating the threat from contained to system-wide.
- CVE-2026-11663HIGH 8.3
A use-after-free memory flaw exists in Google Chrome's Skia rendering engine. If an attacker first compromises Chrome's renderer process—the sandboxed component responsible for drawing web content—they can craft a malicious HTML page to trigger the vulnerability and break out of the sandbox, gaining full system access. This is a post-compromise attack chain: the renderer must already be compromised, but once it is, the attacker bypasses Chrome's key security boundary.
- CVE-2026-11672HIGH 8.3
A heap buffer overflow vulnerability exists in the GPU component of Google Chrome on Android versions prior to 149.0.7827.103. An attacker who has already compromised Chrome's renderer process can exploit this flaw through a specially crafted HTML page to escape the browser sandbox and gain higher privileges on the device. This is a post-compromise escalation vector that requires the renderer to be compromised first.
- CVE-2026-11676HIGH 8.3
A weakness in how Google Chrome's graphics engine (Dawn) validates user-supplied input can allow an attacker who has already compromised the browser's renderer process to escape the sandbox and gain full system access. The vulnerability exists in Chrome on Linux and ChromeOS versions before 149.0.7827.103, and requires the attacker to trick a user into visiting a malicious webpage. Once the renderer is compromised—typically through a separate browser vulnerability—this flaw becomes a path to break out of Chrome's security isolation and potentially execute arbitrary code with system privileges.
- CVE-2026-11677HIGH 8.3
A race condition vulnerability in Google Chrome's network process on macOS allows an attacker who has already compromised the browser's network process to escape the sandbox and potentially gain system-level access. The vulnerability requires the attacker to craft a malicious HTML page and trick a user into viewing it, but the underlying network process compromise is the critical prerequisite. This is a privilege escalation vector rather than a primary infection method.
- CVE-2026-11679HIGH 8.3
A use-after-free memory vulnerability exists in Google Chrome's codec handling on Windows systems. An attacker who has already compromised Chrome's renderer process—the sandboxed component that handles web content—could exploit this flaw via a malicious HTML page to break out of the sandbox and gain full system access. This requires the attacker to have already achieved renderer process compromise, making it a critical second-stage attack in a multi-stage exploitation chain.
- CVE-2026-11682HIGH 8.3
A vulnerability in Google Chrome's Views implementation on Linux allows an attacker who has already compromised Chrome's renderer process to break out of the browser sandbox and gain system-level access. The attacker would need to trick a user into visiting a malicious webpage, but the actual exploit requires prior control of Chrome's rendering engine—making this a dangerous second-stage attack vector rather than a direct browser vulnerability. Chrome versions before 149.0.7827.103 on Linux are affected.
- CVE-2026-11692HIGH 8.3
A use-after-free vulnerability in Chrome's Read Anything feature allows an attacker who has already compromised the browser's renderer process to escape the sandbox and gain elevated system privileges. The attacker needs a user to open a malicious HTML page, but once triggered, the flaw breaks Chrome's security isolation and can lead to full system compromise. Google Chrome versions prior to 149.0.7827.103 are affected across Windows, macOS, and Linux.
- CVE-2026-11700HIGH 8.3
A use-after-free flaw in Chrome's tracing component allows an attacker who has already compromised the renderer process to escape the browser sandbox through a specially crafted HTML page. While the attack requires the renderer to be compromised first, successful exploitation could give an attacker full system access beyond the browser's security boundaries.
- CVE-2026-32905HIGH 8.3
OpenClaw versions before 2026.5.4 contain a flaw that lets users with basic chat access create device enrollment codes they shouldn't be able to generate. An attacker with legitimate chat permissions can issue bootstrap codes that add new devices with full operator and node-level capabilities to the system. Once enrolled, these devices retain administrative credentials indefinitely until an administrator manually removes them, creating a persistent backdoor.
- CVE-2026-42941HIGH 8.3
Danelec MacGregor's Voyage Data Recorder (VDR) devices ship with hardcoded default credentials that cannot be forced to change, allowing unauthenticated network attackers to gain administrative access. This is a straightforward but high-impact authentication bypass on a maritime safety-critical system.
- CVE-2026-44698HIGH 8.3
Home Assistant Companion apps for iOS and Android contain a vulnerability that allows malicious websites viewed in the app to steal a user's access token and run code as if they were logged into Home Assistant. The flaw stems from improper protection of a JavaScript bridge that connects web content to native app functionality. An attacker can craft a webpage with hidden content that tricks the bridge into executing arbitrary commands with the victim's credentials, effectively compromising their Home Assistant account.
- CVE-2026-46307HIGH 8.3
CVE-2026-46307 is a memory safety bug in the Linux kernel's ath5k WiFi driver. The driver incorrectly writes data beyond the bounds of an array when handling wireless transmission status updates. While the out-of-bounds write itself is narrow in scope—it only affects an adjacent memory field used for signal strength reporting—the vulnerability demonstrates a real flaw that could be triggered during normal WiFi operations. An attacker with network proximity could potentially exploit this to corrupt driver state or trigger unexpected behavior.
- CVE-2026-46481HIGH 8.3
OpenMetadata users without admin privileges can exploit a workflow testing feature to extract sensitive credentials and authentication tokens. When a non-admin SSO user tests a database connection through the platform's automation interface, the response inadvertently exposes the plaintext database password and a privileged authentication token belonging to the ingestion bot. An attacker with these credentials can then impersonate the bot to access APIs and data that should be restricted to service accounts, effectively escalating their access within the metadata platform. This flaw affects all OpenMetadata versions prior to 1.12.4.
- CVE-2026-49203HIGH 8.3
CVE-2026-49203 is a critical authorization flaw in Acer Connect M6E 5G cellular management APIs. The vulnerability allows an attacker with network access to remotely rewrite or delete eSIM profiles without authentication. Because the affected endpoints lack proper caller verification, an unauthenticated adversary on the same network can manipulate cellular configurations, potentially disconnecting devices or provisioning unauthorized SIM profiles. The flaw exposes organizations relying on these devices for cellular connectivity to profile tampering and service disruption.
- CVE-2026-9877HIGH 8.3
A use-after-free memory vulnerability in the ANGLE graphics library affects Google Chrome versions before 148.0.7778.216. An attacker who has already compromised Chrome's renderer process can exploit this flaw through a specially crafted HTML page to escape the browser sandbox and gain unauthorized system access. While the attack requires an existing foothold in the renderer, the critical severity designation reflects the severe consequences of a successful sandbox escape.
- CVE-2026-9880HIGH 8.3
Google Chrome versions before 148.0.7778.216 contain a flaw in WebGL input validation that allows an attacker who has already compromised the browser's renderer process to escape the browser sandbox and gain full system access. The vulnerability requires user interaction (clicking or otherwise engaging with a malicious page) but poses a critical risk once that initial renderer compromise occurs.
- CVE-2026-9885HIGH 8.3
A flaw in how Google Chrome validates user interface input on macOS versions prior to 148.0.7778.216 could allow an attacker who has already compromised the browser's rendering engine to break out of Chrome's sandbox. The attacker would need to trick a user into visiting a specially crafted webpage, but once the renderer is compromised, this vulnerability provides a pathway to execute code outside the sandbox with full system privileges.
- CVE-2026-9888HIGH 8.3
A use-after-free vulnerability in Chrome's WebView component on Android allows an attacker with access to the renderer process to potentially escape the sandbox through a specially crafted web page. This is a serious flaw because the renderer is typically isolated for security; if that isolation fails, an attacker could gain deeper system access. The vulnerability affects Chrome versions prior to 148.0.7778.216.
- CVE-2026-9889HIGH 8.3
A memory safety vulnerability in Google Chrome's graphics rendering engine (Dawn) on Android devices allows an attacker to read and write memory outside intended boundaries. By crafting a malicious HTML page, a remote attacker could potentially escape the Chrome sandbox and gain elevated system privileges. This requires user interaction—the victim must visit the malicious page—but poses a critical threat to Android users.
- CVE-2026-9890HIGH 8.3
A use-after-free memory flaw exists in Google Chrome's Extended Reality (XR) implementation on Windows. An attacker who has already compromised Chrome's renderer process can exploit this defect through a malicious webpage to break out of the browser sandbox and gain system-level access. This is a privilege escalation attack that requires the renderer to be compromised first, making it part of a multi-stage exploitation chain.
- CVE-2026-9892HIGH 8.3
A vulnerability in Google Chrome's Skia graphics library on Android could allow an attacker who has already gained control of Chrome's renderer process to break out of the browser sandbox and execute arbitrary code with elevated privileges. An attacker would need to trick a user into visiting a specially crafted website while the renderer has been compromised—a two-step attack requiring both initial compromise and user interaction.
- CVE-2026-9893HIGH 8.3
A use-after-free vulnerability exists in Google Chrome's Skia graphics library (versions before 148.0.7778.216). An attacker who has already compromised Chrome's renderer process can exploit this flaw through a specially crafted HTML page to escape the browser sandbox—potentially gaining full system access. While the attack requires an initial compromise of the renderer, the sandbox escape risk elevates this to a critical concern for organizations where Chrome is prevalent.
- CVE-2026-9894HIGH 8.3
Google Chrome versions before 148.0.7778.216 contain a use-after-free vulnerability in the GPU rendering process. An attacker who has already compromised Chrome's renderer process can exploit this flaw via a malicious HTML page to escape the browser's sandbox and gain broader system access. This is a post-compromise escalation risk, not a direct infection vector.
- CVE-2026-9895HIGH 8.3
Google Chrome versions prior to 148.0.7778.216 contain an out-of-bounds read vulnerability in the GPU processing component. An attacker who has already compromised a renderer process can exploit this flaw by serving a specially crafted HTML page, potentially escaping the browser sandbox entirely. This is a critical chaining vulnerability—it requires prior renderer compromise but enables full system access.
- CVE-2026-9898HIGH 8.3
A validation flaw in Google Chrome's GPU handling on Android allows an attacker who has already compromised the browser's renderer process to escape the sandbox through a specially crafted HTML page. This is a post-compromise risk: the attacker must first break into the renderer (via a separate vulnerability or exploit), then leverage this GPU validation gap to break out of Chrome's sandbox and gain full device access.
- CVE-2026-9899HIGH 8.3
A use-after-free memory defect in ANGLE (the graphics abstraction layer used by Chrome) can allow an attacker to escape Chrome's sandbox if they've already compromised the renderer process. The attack requires a specially crafted web page and user interaction, but successful exploitation could give an attacker full system access beyond Chrome's security boundaries.
- CVE-2026-9900HIGH 8.3
A memory safety bug in Chrome's graphics rendering engine (ANGLE) allows attackers to write data outside allocated memory bounds. If an attacker can compromise Chrome's renderer process—the part that displays web content—they can exploit this flaw to break out of Chrome's sandbox and gain full system access. This requires both process compromise and a user to visit a malicious page, but the consequences are severe.
- CVE-2026-9902HIGH 8.3
A use-after-free memory bug in Google Chrome's accessibility features could allow an attacker to escape the browser's sandbox if they first compromise the renderer process. The vulnerability affects Chrome versions before 148.0.7778.216 and requires the attacker to trick a user into visiting a crafted webpage. While the initial compromise of the renderer process is a significant prerequisite, successfully exploiting this flaw could grant an attacker system-level access beyond the browser's normal restrictions.
- CVE-2026-9904HIGH 8.3
A use-after-free memory vulnerability exists in ANGLE, the graphics abstraction layer used by Google Chrome. By delivering a specially crafted HTML page, a remote attacker could exploit this flaw to break out of Chrome's sandbox—the critical security boundary that isolates the browser process from the rest of your system. Successful exploitation allows the attacker to run arbitrary code with the privileges of your user account, potentially compromising your entire machine.
- CVE-2026-9905HIGH 8.3
A use-after-free vulnerability exists in Google Chrome's accessibility features on Windows. An attacker who has already compromised Chrome's renderer process can exploit this flaw through a specially crafted HTML page to break out of Chrome's sandbox and gain system-level access. This is a post-compromise risk: the attacker must first have control of the renderer, but if they do, this vulnerability provides a direct path to escape Chrome's security isolation and potentially take full control of your computer.
- CVE-2026-9906HIGH 8.3
Google Chrome versions prior to 148.0.7778.216 contain a memory safety flaw in GPU processing that could allow an attacker with control of the browser's renderer process to break out of the sandbox and gain system-level access. The attack requires the renderer to already be compromised and the user to visit a malicious webpage, but success would bypass Chrome's primary security boundary.
- CVE-2026-9914HIGH 8.3
An attacker who gains control of Chrome's rendering engine can use this vulnerability to break out of the browser sandbox by crafting a malicious webpage. The flaw stems from inadequate validation of untrusted data within ANGLE, a graphics abstraction layer, allowing an attacker to execute code with privileges beyond the sandbox constraints.
- CVE-2026-9915HIGH 8.3
A heap buffer overflow vulnerability exists in ANGLE, the graphics abstraction layer used by Google Chrome, affecting versions prior to 148.0.7778.216. An attacker who has already compromised Chrome's renderer process can exploit this flaw via a specially crafted HTML page to potentially escape the browser sandbox and gain elevated privileges on the system. This requires the attacker to first compromise the renderer, making it a post-compromise threat rather than a direct entry point.
- CVE-2026-9916HIGH 8.3
A memory safety flaw exists in the ANGLE graphics library component of Google Chrome. An attacker who has already compromised the browser's renderer process could exploit this out-of-bounds write to break out of the browser sandbox and gain system-level access. Exploitation requires the attacker to deliver a crafted HTML page and needs user interaction to trigger. The vulnerability affects Chrome versions before 148.0.7778.216.
- CVE-2026-9924HIGH 8.3
A flaw in the ANGLE graphics library (which Chrome uses to render graphics on Windows) can cause memory corruption when processing specially crafted web content. An attacker who has already compromised Chrome's sandboxed renderer process could exploit this to escape the sandbox and gain full system access. The vulnerability requires user interaction—the victim must open a malicious webpage—but once the renderer is compromised, the attacker has a path to execute code outside the sandbox.
- CVE-2026-9925HIGH 8.3
A use-after-free flaw in ANGLE (the graphics abstraction layer used by Google Chrome) can allow an attacker to escape the browser sandbox if they first compromise the renderer process. The attacker would craft a malicious HTML page to trigger memory corruption that leads to code execution outside the sandbox boundary. This requires two conditions: initial renderer compromise and user interaction with the hostile page.
- CVE-2026-9926HIGH 8.3
A memory error in Chrome's graphics processing component (ANGLE) could allow an attacker who has already compromised the renderer process to break out of the sandbox and access the wider system. The vulnerability requires the attacker to deliver a specially crafted webpage and the user to interact with it, but once triggered, it could lead to full system compromise. The issue affects Chrome versions prior to 148.0.7778.216.
- CVE-2026-9931HIGH 8.3
A use-after-free memory flaw in Chrome's GPU component allows an attacker who has already compromised the browser's renderer process to break out of Chrome's sandbox and gain system-level access. The attacker would need to trick a user into visiting a malicious webpage while the renderer is already under attack. This is a post-compromise privilege escalation path rather than a direct remote attack vector.
- CVE-2026-9932HIGH 8.3
A use-after-free vulnerability exists in the ANGLE graphics library within Google Chrome on Windows. An attacker who has already compromised Chrome's renderer process can exploit this flaw via a specially crafted HTML page to break out of Chrome's sandbox and gain full system access. This is a chained attack: the initial compromise must occur first, but once inside the renderer, the attacker gains significant additional capabilities.
- CVE-2026-9936HIGH 8.3
A use-after-free vulnerability in Google Chrome's graphics rendering engine (GFX) affects Mac systems running versions prior to 148.0.7778.216. The flaw allows an attacker who has already compromised Chrome's renderer process to escape the browser sandbox through a malicious HTML page, potentially gaining access to the underlying operating system. This is a post-compromise attack requiring the renderer to already be under attacker control.
- CVE-2026-9937HIGH 8.3
A use-after-free flaw in Google Chrome's user interface on Windows allows an attacker who has already compromised Chrome's renderer process to escape the browser sandbox and gain system-level access. The attacker would need to craft a malicious HTML page to trigger the vulnerability. This is a critical privilege escalation path because sandbox escapes turn browser compromises into full system compromises.
- CVE-2026-9946HIGH 8.3
A use-after-free vulnerability in Google Chrome's ANGLE graphics library could allow an attacker who has already compromised the browser's renderer process to break out of Chrome's security sandbox and execute code with system-level privileges. The flaw affects Chrome versions before 148.0.7778.216 and requires user interaction—typically visiting a malicious website—to trigger the vulnerability chain.
- CVE-2026-9948HIGH 8.3
Google Chrome on macOS contains a use-after-free vulnerability in its Views component that could allow an attacker to escape the browser's sandbox. The attack requires two conditions: the attacker must first compromise Chrome's renderer process (the sandboxed component that executes web content), and the victim must interact with a specially crafted webpage. If successful, the attacker gains access beyond the sandbox, potentially compromising the entire system. This vulnerability affects Chrome versions prior to 148.0.7778.216 on macOS.
- CVE-2026-9949HIGH 8.3
A use-after-free memory vulnerability exists in Google Chrome's Core component on Windows that could allow an attacker to escape the browser's sandbox. The vulnerability requires the attacker to have already compromised Chrome's renderer process and trick a user into visiting a malicious webpage. If successfully exploited, an attacker could gain the same privileges as the Windows user running Chrome, potentially compromising the entire system.
- CVE-2026-9951HIGH 8.3
Google Chrome before version 148.0.7778.216 contains a use-after-free vulnerability in its user interface rendering engine. This flaw allows an attacker to craft a malicious HTML page that, when visited by a user, can trigger memory corruption. The vulnerability is particularly dangerous because it may enable attackers to break out of Chrome's sandbox—the security boundary that isolates the browser from the underlying operating system—potentially gaining direct access to system resources and user data. Exploitation requires user interaction (clicking or visiting a malicious site) and involves complex attack conditions, but the potential for sandbox escape elevates the risk significantly.
- CVE-2026-9966HIGH 8.3
This vulnerability is an integer overflow flaw in how Google Chrome handles XML content on Windows systems. An attacker who has already compromised Chrome's rendering engine could craft a malicious HTML page to escape Chrome's security sandbox—the isolated environment that prevents malicious code from accessing your system directly. The vulnerability requires the attacker to have control of the renderer process first, and it requires user interaction (visiting a malicious page), but if exploited successfully, it could lead to complete system compromise.
- CVE-2026-9970HIGH 8.3
A use-after-free memory vulnerability exists in Google Chrome's WebGL component that could allow an attacker to escape the browser sandbox. An attacker would first need to compromise Chrome's renderer process—typically through a separate exploit or social engineering—and then could use a specially crafted HTML page to gain unauthorized access outside the browser's security boundaries. This vulnerability affects Chrome versions before 148.0.7778.216 on Windows, macOS, and Linux systems.
- CVE-2026-9972HIGH 8.3
A vulnerability in Google Chrome on macOS could allow an attacker to escape the browser's security sandbox if the attacker has already compromised Chrome's renderer process. The flaw stems from uninitialized memory in the gamepad handling code. An attacker would need to trick a user into visiting a malicious website while Chrome is running, and would require a prior compromise of the renderer—a critical prerequisite that significantly limits real-world exploitation scenarios. Once exploited, the attacker could potentially gain full system access beyond Chrome's normal restrictions.
- CVE-2026-9974HIGH 8.3
CVE-2026-9974 is a memory safety bug in Google Chrome's GPU rendering component that can allow an attacker to escape the browser's sandbox if they first compromise the renderer process. The vulnerability stems from an out-of-bounds write operation, meaning the code writes data outside its intended memory boundaries. An attacker would need to trick a user into visiting a malicious webpage while already having control of Chrome's renderer, making this a secondary exploit that amplifies damage from other browser compromises.
- CVE-2026-9975HIGH 8.3
A memory safety vulnerability in Google Chrome's ANGLE graphics library allows an attacker who has already compromised the browser's renderer process to break out of Chrome's sandbox and gain full system access. The flaw involves reading and writing memory beyond intended boundaries, creating a bridge from the restricted renderer environment to the host operating system. This requires the attacker to first successfully compromise the renderer (through a separate browser exploit or vulnerability) and then craft a malicious HTML page to trigger the escape.
- CVE-2026-9977HIGH 8.3
A validation flaw in Chrome's WebShare feature on Android allows an attacker who has already compromised Chrome's renderer process to escape the browser sandbox through a specially crafted HTML page. The vulnerability requires the attacker to have gained initial access to the renderer—typically through a separate exploit or compromise—but once inside, the insufficient input checking creates a pathway to break out of the browser's security boundary and potentially gain full device access.
- CVE-2026-9982HIGH 8.3
CVE-2026-9982 is a sandbox escape vulnerability in Google Chrome's ANGLE graphics library. An attacker who has already compromised the browser's renderer process can exploit insufficient input validation to break out of the sandbox and gain system-level access. This requires an attacker to first deliver a malicious webpage that triggers the rendering flaw, making it a chained attack scenario rather than a one-step exploitation path.
- CVE-2026-9988HIGH 8.3
A use-after-free memory flaw in Chrome's WebRTC component on Linux could allow an attacker to escape the browser's security sandbox. By crafting a malicious webpage, an attacker who tricks a user into visiting it could potentially break out of Chrome's isolation protections and execute code with system-level privileges. This affects Chrome versions before 148.0.7778.216 on Linux systems.
- CVE-2026-9993HIGH 8.3
A use-after-free memory vulnerability exists in Google Chrome's rendering engine that allows an attacker to escape the browser's sandbox if they have already compromised the renderer process. The vulnerability is triggered when a user opens a malicious PDF file. This is a critical threat because it could allow an attacker who has gained code execution within the browser to break out of Chrome's security boundaries and gain access to the underlying operating system.
- CVE-2026-9994HIGH 8.3
A use-after-free vulnerability exists in Google Chrome's core rendering engine on Windows systems. An attacker who has already compromised the browser's renderer process can exploit this flaw through a specially crafted HTML page to escape the browser sandbox—breaking out of Chrome's security isolation layer. This means an attacker could potentially gain full system access from within the constrained renderer environment.
- CVE-2026-9997HIGH 8.3
Google Chrome versions prior to 148.0.7778.216 contain a use-after-free vulnerability in the Input component that could allow an attacker to escape the browser's sandbox. The attack requires the attacker to have already compromised Chrome's renderer process and trick a user into visiting a malicious HTML page. If successful, the attacker could break out of the sandbox and gain access to the underlying operating system.
- CVE-2026-9998HIGH 8.3
CVE-2026-9998 is a high-severity integer overflow vulnerability in Google Chrome's Skia graphics library that could allow an attacker to escape the browser's sandbox—a critical security boundary—if they first compromise Chrome's renderer process. The vulnerability requires a specially crafted HTML page and user interaction, making it a significant but not trivial threat. The issue affects Chrome versions before 148.0.7778.216.
- CVE-2016-20062HIGH 8.2
A SQL injection flaw in the Simply Poll WordPress plugin version 1.4.1 allows attackers without login credentials to steal data directly from a site's database. By crafting malicious requests to the plugin's AJAX handler, an attacker can execute arbitrary database queries and extract sensitive information such as user credentials, posts, or custom data. The vulnerability requires no user interaction and can be exploited by anyone with network access to the affected WordPress site.
- CVE-2016-20065HIGH 8.2
The Product Catalog 8 plugin version 1.2 for WordPress contains a critical SQL injection flaw that allows attackers to bypass authentication entirely and directly query the WordPress database. An unauthenticated attacker can craft a specially designed POST request to the admin-ajax.php endpoint, manipulating the selectedCategory parameter to inject arbitrary SQL commands. This enables unauthorized data extraction from sensitive WordPress database tables, potentially exposing user credentials, posts, comments, and configuration data without requiring login credentials or user interaction.
- CVE-2017-20243HIGH 8.2
The WordPress Car Park Booking Plugin version from October 17 contains a SQL injection flaw that allows attackers to directly manipulate the plugin's database queries without authentication. By crafting malicious requests with specially crafted parameters, attackers can extract sensitive information from the WordPress database, such as user credentials, booking details, and other confidential records. The vulnerability is exploited through time-based SQL injection techniques, where attackers observe database response delays to infer data values.