2026 · High
High-severity vulnerabilities disclosed in 2026
High-rated CVEs published in 2026, with SEC.co remediation and prioritization guidance.
4140 published vulnerabilities · page 11 of 42
- CVE-2026-10905HIGH 8.3
A memory safety flaw in Google Chrome's network code allows an attacker who has already compromised the browser's renderer process to escape the sandbox and gain full system access. The vulnerability requires user interaction (opening a malicious HTML page) but poses significant risk because successful exploitation bypasses Chrome's core security boundary—the sandbox that isolates the browser from the operating system.
- CVE-2026-10908HIGH 8.3
A use-after-free vulnerability exists in Google Chrome's full-screen functionality on Windows systems. An attacker who has already compromised Chrome's rendering engine could exploit a specially crafted web page to escape the browser sandbox and execute arbitrary code with higher privileges. This requires the attacker to have initial renderer process access, but once achieved, the flaw could allow them to run code outside the sandbox protection layer.
- CVE-2026-10909HIGH 8.3
A use-after-free vulnerability in Google Chrome's Dawn graphics engine allows an attacker who has already compromised the browser's renderer process to escape the sandbox through a malicious webpage. This is a high-severity issue because it bridges two separate security boundaries—first gaining control within Chrome's renderer, then breaking out to execute arbitrary code on the underlying operating system.
- CVE-2026-10911HIGH 8.3
CVE-2026-10911 is a sandbox escape vulnerability in Google Chrome that allows a remote attacker to break out of the browser's security sandbox if they have already compromised the renderer process. The attack requires crafted HTML content and user interaction, but once successful, it grants an attacker full system access. This is a chained attack scenario: an attacker must first compromise the renderer (the part of Chrome that displays web content) through a separate vulnerability, then use this flaw to escape the sandbox and gain control of the underlying system.
- CVE-2026-10915HIGH 8.3
A use-after-free memory vulnerability exists in Google Chrome on iOS that allows an attacker who has already compromised the browser's renderer process to break out of the sandbox and gain deeper system access. The vulnerability requires the attacker to serve a specially crafted HTML page and involves a complex attack chain but poses severe risk because successful exploitation can lead to full compromise of the device. Chrome versions prior to 149.0.7827.53 on iOS are affected.
- CVE-2026-10917HIGH 8.3
Google Chrome versions before 149.0.7827.53 contain a media handling flaw that allows an attacker who has already compromised the browser's renderer process to escape the sandbox and gain broader system access. The vulnerability requires user interaction (visiting a specially crafted webpage) but poses a significant risk because renderer compromises are common entry points in real attacks. Once inside the renderer, the flaw gives an attacker a path to elevated privileges on the underlying operating system.
- CVE-2026-10918HIGH 8.3
A use-after-free vulnerability in Google Chrome's Viz component allows an attacker who has already compromised the browser's renderer process to potentially escape the sandbox and gain deeper system access. The attacker would need to trick a user into visiting a malicious webpage, but the actual exploitation requires prior renderer compromise, making this a multi-stage attack. While not currently known to be exploited in the wild, the vulnerability represents a meaningful privilege escalation path for sophisticated threat actors who have achieved initial browser process compromise.
- CVE-2026-10919HIGH 8.3
A use-after-free bug in Chrome's ANGLE graphics library before version 149.0.7827.53 allows an attacker who already controls the browser's rendering process to break out of the sandbox and gain full system access. The attacker must trick a user into visiting a malicious webpage, but once the renderer is compromised, this flaw provides a path to escape Chrome's isolation boundaries.
- CVE-2026-10920HIGH 8.3
A validation flaw in Chrome's WebShare feature on macOS allows an attacker who has already compromised the browser's renderer process to break out of the sandbox through a specially crafted webpage. This is a post-compromise privilege escalation risk—the attacker must first gain code execution within the renderer, but if successful, can gain full system access. Chrome versions before 149.0.7827.53 are affected.
- CVE-2026-10921HIGH 8.3
A flaw in Google Chrome's graphics processing library (Dawn) could allow an attacker to break out of the browser's security sandbox if they've already compromised the rendering engine. The vulnerability stems from an integer overflow—a situation where a number calculation wraps around and produces an incorrect value—that could be triggered by a specially crafted webpage. While the attacker would need to have already gained access to the renderer process, successfully exploiting this could grant them the same privileges as the operating system user running Chrome, potentially leading to full system compromise.
- CVE-2026-10924HIGH 8.3
A mathematical error in Chrome's Chromecast component allows an attacker who has already compromised Chrome's rendering engine to break out of the browser sandbox and gain full system access. The attacker needs to trick a user into visiting a malicious webpage while the renderer is already compromised. This is a serious vulnerability because sandbox escape means the attacker moves from limited browser permissions to unrestricted control of the entire device.
- CVE-2026-10925HIGH 8.3
A memory corruption flaw exists in the Skia graphics library within Google Chrome on macOS. An attacker who has already compromised Chrome's renderer process can exploit this out-of-bounds write to break out of the browser sandbox and gain system-level access. The attack requires user interaction (visiting a malicious webpage) but bypasses Chrome's primary security boundary once the renderer is under attacker control.
- CVE-2026-10927HIGH 8.3
A memory reading flaw in Google Chrome's graphics component (Dawn) prior to version 149.0.7827.53 allows attackers who have already compromised the browser's renderer process to escape the sandbox through a specially crafted webpage. This is a two-stage attack: first an attacker must find a way into the renderer, then this vulnerability allows them to break out entirely.
- CVE-2026-10929HIGH 8.3
A memory safety flaw in ANGLE (the graphics abstraction layer used by Chrome) allows an attacker who has already compromised Chrome's sandboxed renderer process to escape that sandbox and gain full system access on Android devices. The attacker must trick a user into visiting a malicious webpage. This affects Chrome versions prior to 149.0.7827.53 on Android.
- CVE-2026-10933HIGH 8.3
A use-after-free vulnerability exists in Google Chrome's audio processing component on Windows systems. An attacker who has already compromised Chrome's renderer process could exploit this flaw through a specially crafted web page to escape the browser sandbox and gain higher privileges on the system. This requires an initial renderer compromise, but if successful, could lead to full system takeover.
- CVE-2026-10934HIGH 8.3
Google Chrome on Android contains a use-after-free vulnerability in its Autofill feature that could allow an attacker to escape the browser sandbox. The flaw requires an attacker to first compromise Chrome's renderer process—the component responsible for parsing and displaying web content—and then trick a user into visiting a malicious webpage. If successful, the attacker could break out of Chrome's security sandbox and gain broader access to the device. This vulnerability affects Chrome versions prior to 149.0.7827.53 on Android.
- CVE-2026-10940HIGH 8.3
A race condition vulnerability in Chrome's media codec handling allows an attacker who has already compromised Chrome's renderer process to escape the browser sandbox on Windows systems. The attacker would need to trick a user into visiting a specially crafted website, but once the renderer is compromised, this flaw could give the attacker full system-level access. Chrome versions before 149.0.7827.53 on Windows are affected.
- CVE-2026-10949HIGH 8.3
A heap buffer overflow vulnerability in Google Chrome's video handling component allows an attacker who has already compromised Chrome's renderer process to escape the browser sandbox and gain system-level access. The attacker would need to craft a malicious HTML page to trigger the overflow, but exploitation requires the renderer to be already compromised—making this a post-compromise escape vector rather than a direct attack from an untrusted webpage. Chrome versions before 149.0.7827.53 are vulnerable on Windows, macOS, and Linux systems.
- CVE-2026-10953HIGH 8.3
A use-after-free vulnerability exists in Google Chrome for Android versions prior to 149.0.7827.53. An attacker who has already compromised Chrome's renderer process can exploit this flaw by crafting a malicious HTML page to break out of the browser sandbox and gain system-level access to the Android device. This is a post-compromise escalation risk rather than a direct entry point, but it significantly amplifies the impact of any renderer exploit.
- CVE-2026-10960HIGH 8.3
CVE-2026-10960 is a sandbox escape vulnerability in Google Chrome's video codec handling. An attacker who has already compromised Chrome's renderer process—the sandboxed component responsible for processing web content—can exploit an uninitialized variable in the codec logic to break out of the sandbox and gain full system access. The attack requires a crafted HTML page and user interaction, but once the renderer is compromised, the attacker can leverage this flaw to escalate to native code execution outside Chrome's security boundary.
- CVE-2026-10961HIGH 8.3
Chrome for iOS users running versions prior to 149.0.7827.53 face a critical sandbox escape vulnerability. A malicious website can exploit a use-after-free memory flaw to break out of Chrome's security sandbox if the attacker first compromises the renderer process—the component that handles webpage content. Once the sandbox is escaped, an attacker gains direct access to the device, potentially leading to theft of credentials, personal data, or malware installation. The vulnerability requires user interaction (visiting a crafted page) but is otherwise remotely exploitable.
- CVE-2026-10967HIGH 8.3
A use-after-free flaw exists in Chrome's SurfaceCapture feature on Android that allows an attacker to escape the browser sandbox. The vulnerability requires the attacker to first compromise Chrome's renderer process and then trick a user into visiting a malicious webpage. If successful, the attacker could break out of Chrome's security sandbox and gain elevated privileges on the device. This affects Chrome versions before 149.0.7827.53 on Android.
- CVE-2026-10970HIGH 8.3
Google Chrome versions prior to 149.0.7827.53 contain a vulnerability in how the browser validates input data related to Interest Groups—a feature used for targeted advertising. An attacker who has already compromised Chrome's renderer process (the part that executes web content) can exploit insufficient input validation to break out of the browser's sandbox—the security boundary designed to isolate web content from the rest of your system. This requires the attacker to first gain renderer access and trick a user into visiting a crafted webpage, but if successful, allows full control over the victim's machine.
- CVE-2026-11010HIGH 8.3
A use-after-free memory safety bug in Chrome's WebShare feature on Android allows an attacker who has already compromised the browser's renderer process to escape the sandbox and gain elevated system privileges by tricking a user into visiting a malicious webpage. While the initial compromise requires the renderer to already be under attacker control, the sandbox escape represents a critical escalation path.
- CVE-2026-11012HIGH 8.3
A use-after-free vulnerability exists in Google Chrome's Serial API on Android devices running versions before 149.0.7827.53. An attacker who has already compromised Chrome's renderer process can exploit this flaw by serving a specially crafted HTML page to achieve a sandbox escape—breaking out of Chrome's security isolation layer. While the underlying Chromium issue is rated Medium severity by Google, the CVSS 3.1 score of 8.3 reflects the HIGH impact potential when combined with renderer compromise.
- CVE-2026-11040HIGH 8.3
A use-after-free flaw in Chrome's ANGLE graphics library allows attackers who have already compromised your browser's renderer process to escape the sandbox and gain full system access via a specially crafted webpage. Chrome versions before 149.0.7827.53 are vulnerable. The attack requires the renderer to be compromised first, but if successful, can completely undermine Chrome's security isolation.
- CVE-2026-11236HIGH 8.3
Google Chrome versions before 149.0.7827.53 contain a flaw in how it enforces security policies for Web Bluetooth functionality. If an attacker has already compromised Chrome's rendering process (the part that runs web content), they could exploit this weakness to break out of Chrome's sandbox—the security boundary that isolates the browser from the rest of your system. An attacker would need to trick a user into visiting a specially crafted webpage while the renderer is already compromised. This is a chaining risk: the vulnerability itself requires a prior compromise, but once chained together, it enables full system access.
- CVE-2026-11237HIGH 8.3
Google Chrome versions before 149.0.7827.53 contain a vulnerability that allows an attacker who has already compromised Chrome's renderer process to trick users through fake or misleading interface elements displayed on a web page. While the underlying flaw is rated 'Low' severity by Chromium, the impact assessment reflects the potential for convincing visual deception attacks that could mislead users into taking harmful actions.
- CVE-2026-11256HIGH 8.3
CVE-2026-11256 is a sandbox escape vulnerability in Google Chrome's GPU processing that affects versions prior to 149.0.7827.53. An attacker who has already compromised Chrome's renderer process can exploit an integer overflow in GPU code to break out of the browser sandbox and execute arbitrary code with higher privileges. The attack requires user interaction (visiting a malicious HTML page) and successful prior compromise of the renderer, making it a post-compromise escalation vector rather than a direct remote code execution path.
- CVE-2026-11340HIGH 8.3
HAVELSAN Inc.'s Liman MYS contains a missing authorization vulnerability that allows authenticated users to access functionality they should not have permission to reach. An attacker with valid login credentials can bypass access control lists (ACLs) to perform unauthorized actions, including modifying system data or disrupting availability. The vulnerability exists in versions prior to release.Master.1107.
- CVE-2026-11631HIGH 8.3
Google Chrome on Windows contains a use-after-free vulnerability in its Aura rendering subsystem that could allow an attacker to break out of the browser's sandbox. The flaw requires an attacker to first compromise the renderer process—typically through a separate vulnerability or exploit—and then use a malicious webpage to trigger memory corruption that escapes the sandbox. This is a post-exploitation technique rather than a direct entry point, but the consequence is severe: attackers could gain system-level access beyond Chrome's normal security boundaries.
- CVE-2026-11635HIGH 8.3
A use-after-free memory vulnerability exists in the Bluetooth component of Google Chrome on macOS. An attacker who already compromises a website's renderer process can exploit this flaw through a specially crafted HTML page to escape the browser sandbox and run code at system level. This is a chained attack—the initial compromise of the renderer process is prerequisite, but once achieved, the vulnerability enables full sandbox bypass with high impact.
- CVE-2026-11640HIGH 8.3
A mathematical error in Google Chrome's image processing library (libyuv) can be exploited by attackers who have already compromised the browser's sandbox. By crafting a malicious HTML page, they can trigger an integer overflow that potentially breaks out of Chrome's security sandbox entirely, gaining full system access. This requires the attacker to have already penetrated the renderer process first, making it a second-stage attack rather than a direct entry point.
- CVE-2026-11642HIGH 8.3
Google Chrome prior to version 149.0.7827.103 contains a use-after-free vulnerability in its web application handling that could allow a remote attacker to escape the browser's sandbox. The attack requires the attacker to first compromise the renderer process—a separate security boundary within Chrome—and then trick a user into visiting a malicious website. If successful, the attacker could potentially gain system-level access, though the vulnerability itself is triggered through browser interaction rather than automatic exploitation.
- CVE-2026-11647HIGH 8.3
A use-after-free memory vulnerability in Chrome's printing functionality on Android allows an attacker who has already compromised a renderer process to escape the sandbox and gain higher privileges. The attacker would need to trick a user into viewing a malicious HTML page, but the actual exploitation requires pre-existing renderer compromise, making this a high-severity but technically constrained attack chain.
- CVE-2026-11652HIGH 8.3
Google Chrome versions before 149.0.7827.103 contain a use-after-free vulnerability in its extension handling code that could allow an attacker to escape the browser sandbox. An attacker who has already compromised the Chrome renderer process—the isolated process that runs website code—could exploit this flaw by crafting a malicious HTML page to gain code execution outside the sandbox, potentially compromising the entire system. The vulnerability requires user interaction (such as visiting a malicious site) and a prior renderer compromise, making it a secondary exploitation vector rather than a direct entry point.
- CVE-2026-11655HIGH 8.3
A mathematical error in how Google Chrome handles media files on macOS allows an attacker to escape the browser's sandbox if they've already compromised Chrome's rendering engine. The vulnerability exists in versions before 149.0.7827.103 and requires a specially crafted webpage to trigger. Once exploited, an attacker could move from the restricted sandbox environment to full system access.
- CVE-2026-11656HIGH 8.3
A use-after-free vulnerability exists in Google Chrome's ServiceWorker component that could allow attackers to escape the browser sandbox if they can trick a user into installing a malicious Chrome extension. The vulnerability affects Chrome versions before 149.0.7827.103 and requires user interaction to install the extension, but successful exploitation would grant an attacker access to the underlying system beyond Chrome's normal security boundaries.
- CVE-2026-11660HIGH 8.3
A vulnerability in Google Chrome's New Tab Page feature allows an attacker who has already compromised Chrome's renderer process to escape the browser sandbox using a specially crafted HTML page. This is a critical privilege escalation risk because sandbox escapes can lead to full system compromise. The vulnerability affects Chrome versions before 149.0.7827.103 across Windows, macOS, and Linux.
- CVE-2026-11661HIGH 8.3
A use-after-free flaw in Google Chrome's Views component on Windows allows a remote attacker to escape the browser's sandbox if the renderer process has already been compromised. The attacker would need to craft a malicious HTML page to trigger the vulnerability. This is a post-compromise escalation risk: while initial renderer compromise is required, successful exploitation grants code execution outside the sandbox, elevating the threat from contained to system-wide.
- CVE-2026-11663HIGH 8.3
A use-after-free memory flaw exists in Google Chrome's Skia rendering engine. If an attacker first compromises Chrome's renderer process—the sandboxed component responsible for drawing web content—they can craft a malicious HTML page to trigger the vulnerability and break out of the sandbox, gaining full system access. This is a post-compromise attack chain: the renderer must already be compromised, but once it is, the attacker bypasses Chrome's key security boundary.
- CVE-2026-11672HIGH 8.3
A heap buffer overflow vulnerability exists in the GPU component of Google Chrome on Android versions prior to 149.0.7827.103. An attacker who has already compromised Chrome's renderer process can exploit this flaw through a specially crafted HTML page to escape the browser sandbox and gain higher privileges on the device. This is a post-compromise escalation vector that requires the renderer to be compromised first.
- CVE-2026-11676HIGH 8.3
A weakness in how Google Chrome's graphics engine (Dawn) validates user-supplied input can allow an attacker who has already compromised the browser's renderer process to escape the sandbox and gain full system access. The vulnerability exists in Chrome on Linux and ChromeOS versions before 149.0.7827.103, and requires the attacker to trick a user into visiting a malicious webpage. Once the renderer is compromised—typically through a separate browser vulnerability—this flaw becomes a path to break out of Chrome's security isolation and potentially execute arbitrary code with system privileges.
- CVE-2026-11677HIGH 8.3
A race condition vulnerability in Google Chrome's network process on macOS allows an attacker who has already compromised the browser's network process to escape the sandbox and potentially gain system-level access. The vulnerability requires the attacker to craft a malicious HTML page and trick a user into viewing it, but the underlying network process compromise is the critical prerequisite. This is a privilege escalation vector rather than a primary infection method.
- CVE-2026-11679HIGH 8.3
A use-after-free memory vulnerability exists in Google Chrome's codec handling on Windows systems. An attacker who has already compromised Chrome's renderer process—the sandboxed component that handles web content—could exploit this flaw via a malicious HTML page to break out of the sandbox and gain full system access. This requires the attacker to have already achieved renderer process compromise, making it a critical second-stage attack in a multi-stage exploitation chain.
- CVE-2026-11682HIGH 8.3
A vulnerability in Google Chrome's Views implementation on Linux allows an attacker who has already compromised Chrome's renderer process to break out of the browser sandbox and gain system-level access. The attacker would need to trick a user into visiting a malicious webpage, but the actual exploit requires prior control of Chrome's rendering engine—making this a dangerous second-stage attack vector rather than a direct browser vulnerability. Chrome versions before 149.0.7827.103 on Linux are affected.
- CVE-2026-11692HIGH 8.3
A use-after-free vulnerability in Chrome's Read Anything feature allows an attacker who has already compromised the browser's renderer process to escape the sandbox and gain elevated system privileges. The attacker needs a user to open a malicious HTML page, but once triggered, the flaw breaks Chrome's security isolation and can lead to full system compromise. Google Chrome versions prior to 149.0.7827.103 are affected across Windows, macOS, and Linux.
- CVE-2026-11700HIGH 8.3
A use-after-free flaw in Chrome's tracing component allows an attacker who has already compromised the renderer process to escape the browser sandbox through a specially crafted HTML page. While the attack requires the renderer to be compromised first, successful exploitation could give an attacker full system access beyond the browser's security boundaries.
- CVE-2026-12008HIGH 8.3
A use-after-free vulnerability in Google Chrome's DigitalCredentials component allows attackers who have already compromised a browser's renderer process to potentially break out of Chrome's sandbox and gain system-level access. The flaw affects Chrome versions before 149.0.7827.115 and requires an attacker to serve a specially crafted webpage to trigger it. While the initial compromise of the renderer is a necessary prerequisite, successfully exploiting this vulnerability could give an attacker the ability to execute arbitrary code outside the browser's security boundaries.
- CVE-2026-12009HIGH 8.3
Google Chrome on macOS contains a vulnerability in its Accessibility feature that could allow an attacker to escape the browser's sandbox—a critical security boundary—if they first compromised Chrome's rendering engine. The flaw stems from insufficient validation of untrusted input. An attacker would need to trick a user into visiting a specially crafted webpage while having already compromised the renderer process, making this a two-stage attack. Versions prior to 149.0.7827.115 are affected.
- CVE-2026-12010HIGH 8.3
A heap buffer overflow vulnerability exists in the GPU rendering component of Google Chrome on Android versions before 149.0.7827.115. The vulnerability requires an attacker to first compromise the browser's renderer process and then serve a specially crafted web page to trigger the overflow. If successfully exploited, the attacker could potentially break out of Chrome's sandbox and gain broader system access. This is a high-severity issue with a CVSS score of 8.3.
- CVE-2026-12011HIGH 8.3
A use-after-free flaw in Chrome's WebMIDI implementation allows attackers who have already broken into Chrome's rendering process to escape the browser sandbox and gain deeper system access on Windows. An attacker would need to trick a user into visiting a malicious webpage while having already compromised the renderer—a two-stage attack, but one that could lead to full system compromise if successful.
- CVE-2026-12014HIGH 8.3
Google Chrome versions prior to 149.0.7827.115 contain a use-after-free memory vulnerability in the Cast feature that allows an attacker with access to the local network to escape the browser sandbox. The vulnerability requires specific conditions to trigger but, if successfully exploited, could grant an attacker code execution outside the browser's security boundaries. This is a local network attack vector, not a remote internet-wide threat, but poses significant risk in environments where untrusted devices share the same network segment.
- CVE-2026-12016HIGH 8.3
Google Chrome versions before 149.0.7827.115 contain a vulnerability in the DevTools component that allows an attacker to escape the browser's sandbox. The attack requires two preconditions: the attacker must first compromise Chrome's renderer process (the component that executes web content), and the victim must interact with a specially crafted HTML page. Successfully exploiting this flaw could give an attacker full system access, bypassing Chrome's security isolation layer.
- CVE-2026-12019HIGH 8.3
A heap buffer overflow vulnerability exists in Google Chrome's codec handling on Linux and ChromeOS. An attacker who has already compromised Chrome's renderer process—the sandboxed component that processes web content—could exploit this flaw to break out of the sandbox and gain elevated privileges on the system. The vulnerability requires user interaction (visiting a malicious webpage) and is triggered through a specially crafted HTML page. Chrome versions prior to 149.0.7827.115 are affected.
- CVE-2026-12022HIGH 8.3
A race condition in Google Chrome's Safe Browsing feature on macOS allows an attacker who has already compromised the browser's renderer process to escape the sandbox using a specially crafted file. This means an attacker would need to first gain code execution within Chrome itself, then exploit this timing vulnerability to break out of Chrome's security boundary and gain full system access. The vulnerability affects Chrome versions prior to 149.0.7827.115 on Mac.
- CVE-2026-12023HIGH 8.3
A use-after-free memory flaw exists in the GPU processing component of Google Chrome on macOS. An attacker who has already compromised Chrome's renderer process could exploit this defect via a specially crafted HTML page to escape the browser's security sandbox and execute arbitrary code with elevated privileges. This is a post-compromise attack path—it requires the renderer to be under attacker control first, but the sandbox escape amplifies the damage significantly.
- CVE-2026-12028HIGH 8.3
A use-after-free memory vulnerability exists in Google Chrome's GPU component on Android devices. An attacker who has already compromised Chrome's renderer process—the part of the browser that interprets web pages—could exploit this flaw via a specially crafted HTML page to escape the browser sandbox and gain broader system access. This is a serious escalation risk because it requires an initial compromise to be effective, but once achieved, it could allow the attacker to break out of Chrome's security isolation.
- CVE-2026-12029HIGH 8.3
A use-after-free memory vulnerability exists in Google Chrome's video handling component on Windows systems. An attacker who has already compromised Chrome's renderer process—the sandboxed component that runs untrusted web content—could exploit this flaw through a specially crafted webpage to break out of the sandbox and gain full system access. This represents a critical step in a multi-stage attack chain, as the attacker must first compromise the renderer before leveraging this vulnerability for privilege escalation.
- CVE-2026-12030HIGH 8.3
A memory safety flaw in Google Chrome's GPU rendering engine on Android allows a remote attacker to escape the browser sandbox if they first compromise the renderer process. An attacker would need to trick a user into visiting a malicious webpage after achieving initial renderer compromise, potentially leading to full device compromise. This is a high-severity issue because it bridges from the already-isolated renderer to the broader Android system.
- CVE-2026-12031HIGH 8.3
Google Chrome on Windows contains a flaw in how it handles Views that could allow an attacker with a compromised renderer process to escape the browser sandbox. An attacker would need to first compromise Chrome's renderer—typically through a separate browser vulnerability—then serve a specially crafted HTML page to trigger the sandbox escape. This is a serious chaining vulnerability because successful exploitation grants access to the operating system with the privileges of the user running Chrome.
- CVE-2026-12034HIGH 8.3
A flaw in how Google Chrome handles theming files on Linux systems could let an attacker escape the browser's security sandbox if they've already compromised the renderer process. The vulnerability stems from Chrome failing to properly validate untrusted input in its Linux Toolkit Theming component. An attacker would need to trick a user into opening a malicious file to trigger the vulnerability, but successful exploitation could give them full system access beyond the confined browser environment.
- CVE-2026-12437HIGH 8.3
A use-after-free vulnerability exists in Google Chrome's WebShare feature on Windows. If an attacker first compromises Chrome's renderer process (the sandboxed component that displays web content), they could exploit a flaw in how WebShare manages memory to escape the sandbox and gain full system access. This requires the attacker to have already compromised the renderer, meaning it's a post-compromise escalation rather than a primary attack vector.
- CVE-2026-12438HIGH 8.3
A flaw in how Google Chrome handles web content on Android devices could allow an attacker to escape the browser's security sandbox if they first compromise Chrome's rendering process. The attacker would need to craft a malicious HTML page to trigger the vulnerability. While Chrome's sandbox is designed to isolate web content from the underlying system, this weakness creates a path to break out of that isolation—a severe issue because it could lead to full device compromise. The vulnerability affects Chrome versions before 149.0.7827.155 on Android.
- CVE-2026-12451HIGH 8.3
Google Chrome versions before 149.0.7827.155 contain a use-after-free vulnerability in the DigitalCredentials component that can allow attackers who have already compromised the renderer process to break out of Chrome's sandbox and potentially execute arbitrary code on the host system. The vulnerability requires both renderer compromise and user interaction, making it a multi-stage attack chain. An attacker would first need to trick a user into visiting a malicious webpage, then leverage this flaw to escape Chrome's security boundaries.
- CVE-2026-12454HIGH 8.3
CVE-2026-12454 is a race condition flaw in Google Chrome's Safe Browsing feature on macOS that allows an attacker who has already compromised Chrome's renderer process to escape the browser sandbox and gain access to the underlying system. The vulnerability requires a specially crafted HTML page and user interaction, but once triggered, it can lead to complete system compromise. This is a high-severity issue because successful exploitation means an attacker can move from browser isolation into full OS-level execution.
- CVE-2026-12464HIGH 8.3
A use-after-free memory vulnerability in Google Chrome's browser engine allows an attacker who has already compromised the renderer process to break out of the browser's sandbox and potentially execute arbitrary code with full system privileges. The vulnerability requires an attacker to first gain control of Chrome's renderer (the process that interprets web pages), then serve a specially crafted HTML page to trigger the memory corruption. This is a high-severity issue because sandbox escapes eliminate one of Chrome's primary security boundaries.
- CVE-2026-12465HIGH 8.3
CVE-2026-12465 is a sandbox escape vulnerability in Google Chrome that stems from improper handling of object lifecycles in the Metrics component. An attacker who has already compromised Chrome's renderer process can exploit a crafted HTML page to break out of the browser sandbox and gain access to the underlying system. This is a post-compromise escalation path that requires the renderer to be compromised first, but once achieved, allows full system access.
- CVE-2026-12467HIGH 8.3
Google Chrome versions before 149.0.7827.155 contain a use-after-free memory safety vulnerability in the Extensions system. An attacker who has already compromised a Chrome renderer process could exploit this flaw via a malicious HTML page to break out of Chrome's sandbox and gain full system access. The vulnerability requires user interaction (opening a crafted page) and successful renderer compromise, but once those conditions are met, the sandbox escape could be severe.
- CVE-2026-12468HIGH 8.3
A race condition in Chrome's auto-update mechanism on macOS allows an attacker who has already compromised the browser's rendering engine to escape the sandbox and gain full system privileges. The vulnerability requires the attacker to first breach the renderer process (a less privileged part of Chrome) through a malicious web page, then exploit a timing flaw in the updater to break out of Chrome's security isolation. This is a chained attack: the initial compromise is necessary, but once achieved, the sandbox escape becomes a critical escalation path. Chrome versions before 149.0.7827.155 on macOS are affected.
- CVE-2026-13025HIGH 8.3
A race condition in Google Chrome's Developer Tools allows attackers who have already compromised Chrome's renderer process to break out of Chrome's security sandbox and gain access to the underlying operating system. The vulnerability requires the attacker to deliver a specially crafted webpage, but can lead to complete system compromise. This affects Chrome versions before 149.0.7827.197.
- CVE-2026-13131HIGH 8.3
GeoWebPlayer is a plugin used by various GeoVision surveillance and management software products (GV-VMS, GV-Cloud, and others) to provide enhanced web interface capabilities via a WebSocket server. A flaw in how the plugin validates user input allows attackers to access memory regions outside intended boundaries by supplying out-of-range index values in commands like `connectInfo`. Because the WebSocket server accepts connections from localhost, an attacker who has already gained local network access or code execution on the host system could exploit this to read sensitive data, modify system behavior, or crash the application.
- CVE-2026-13132HIGH 8.3
GeoWebPlayer is a browser plugin used by GeoVision surveillance software (GV-VMS, GV-Cloud, and related platforms) to enable advanced web interface features. The plugin runs a local websocket server that accepts commands from the browser. A critical flaw exists in how the plugin validates index parameters passed in commands like `setStream`—it fails to verify that these index values fall within valid array bounds. An attacker who can trick a user into visiting a malicious webpage while logged into a GeoVision web interface could send specially crafted websocket commands that access memory beyond intended array boundaries, potentially leading to information disclosure, unauthorized control changes, or system crashes.
- CVE-2026-13281HIGH 8.3
CVE-2026-13281 is a high-severity integer overflow vulnerability in the Mojo component of Google Chrome that could allow an attacker to escape the browser's sandbox if they first compromise the renderer process. An attacker would need to trick a user into opening a malicious file while controlling the renderer, creating a two-stage attack pathway. Successful exploitation could grant an attacker full system-level access beyond Chrome's security boundaries.
- CVE-2026-13744HIGH 8.3
Snowflake CLI versions before 3.19 contain a vulnerability that allows attackers to inject and execute unauthorized SQL commands. An attacker can craft malicious repository content, project configuration files, manifest data, or specification inputs that, when processed by a vulnerable CLI command, will execute SQL statements in the context of the user's Snowflake database session. The actual damage depends on what database permissions that user has. Exploitation requires the victim to actively process the attacker's content, so this is not a passive network attack.
- CVE-2026-13801HIGH 8.3
Google Chrome contains an integer overflow vulnerability in its Chromecast implementation that could allow an attacker to escape the browser's security sandbox. The flaw requires the attacker to first compromise the renderer process—the part of Chrome that executes web content—and then trick a user into visiting a specially crafted webpage. If successful, an attacker could break out of Chrome's sandbox isolation and gain access to the underlying operating system. This vulnerability affects Chrome versions before 150.0.7871.47 across Windows, macOS, and Linux.
- CVE-2026-13803HIGH 8.3
A type confusion vulnerability in Google Chrome's tab handling mechanism allows an attacker who has already compromised a renderer process to escape the browser's sandbox through a specially crafted HTML page. This is a multi-step attack: the attacker must first gain code execution within Chrome's renderer process, then leverage this type confusion flaw to break out of the sandbox entirely, potentially gaining full system access. The vulnerability affects Chrome versions before 150.0.7871.47.
- CVE-2026-13804HIGH 8.3
Google Chrome contains a use-after-free vulnerability in its Chromecast component that could allow an attacker to escape the browser's security sandbox. The flaw requires the attacker to first compromise the renderer process—the sandboxed component that processes web content—and then trick a user into visiting a malicious website. If successful, the attacker could break out of the sandbox and gain broader system access. This vulnerability affects Chrome versions prior to 150.0.7871.47.
- CVE-2026-13813HIGH 8.3
A security flaw in Google Chrome for iOS allows attackers who have already compromised Chrome's rendering engine to break out of the browser's sandbox—a protective boundary designed to limit damage if a web page is malicious. The attacker would need to craft a specially designed webpage to trigger the escape. This vulnerability affects Chrome versions before 150.0.7871.47 on iOS devices.
- CVE-2026-13823HIGH 8.3
A use-after-free memory vulnerability exists in Glic, a component of Google Chrome. An attacker who has already compromised Chrome's renderer process can exploit this flaw through a specially crafted HTML page to break out of Chrome's sandbox, potentially gaining full system access. This requires two prerequisites: a prior renderer compromise and user interaction with the malicious page.
- CVE-2026-13829HIGH 8.3
A flaw in Google Chrome's Settings component on Windows allows an attacker who has already compromised Chrome's rendering engine to break out of the browser's security sandbox and gain broader system access. The vulnerability requires the attacker to first control the renderer process—typically through a separate browser exploit—and then use a specially crafted webpage to escape the sandbox. Chrome versions before 150.0.7871.47 are vulnerable.
- CVE-2026-13832HIGH 8.3
Google Chrome versions before 150.0.7871.47 contain a use-after-free memory vulnerability in the Headless browser component. An attacker who has already compromised Chrome's renderer process could exploit this flaw by serving a specially crafted webpage to escape the browser sandbox—breaking out of the security boundary that normally isolates web content from the host system. This is a privilege escalation risk for users visiting malicious sites, assuming the attacker has already gained initial renderer-level access.
- CVE-2026-13834HIGH 8.3
Google Chrome contains a vulnerability in its ANGLE graphics library that could allow an attacker who has already compromised the renderer process to escape the browser sandbox through a malicious HTML page. The vulnerability stems from insufficient validation of untrusted input. An attacker would need to first compromise the renderer process and trick a user into visiting a crafted page, but successful exploitation would grant access to the full system outside the sandbox protection that normally isolates the browser.
- CVE-2026-13841HIGH 8.3
A flaw in Chrome's Skia graphics library allows an attacker who has already compromised the browser's renderer process to escape the sandbox and gain full system access. The vulnerability requires an attacker to first breach the renderer—for instance, via a malicious website—then exploit the integer overflow to break out of Chrome's security boundary. While the initial compromise is non-trivial, the sandbox escape amplifies the damage significantly.
- CVE-2026-13951HIGH 8.3
A vulnerability in Google Chrome's USB policy enforcement allows an attacker who has already compromised the browser's renderer process—the component that interprets web content—to potentially break out of Chrome's sandbox security boundary. The attacker would need to trick a user into visiting a maliciously crafted webpage. Once the renderer is compromised, this flaw could enable unauthorized access to the system, modification of data, or system unavailability. The issue affects Chrome versions before 150.0.7871.47.
- CVE-2026-14151HIGH 8.3
Google Chrome versions prior to 150.0.7871.47 contain a flaw in how its AI components handle certain operations, which could allow an attacker to escape the browser's sandbox security boundary. The attack requires two conditions: first, the attacker must already have compromised Chrome's renderer process (the part that displays web pages), and second, the user must interact with a malicious web page. If both conditions are met, the attacker could gain unauthorized access to the system beyond what the sandbox normally permits. While Google rates this as low severity internally, the potential impact—full system compromise through sandbox escape—warrants urgent patching.
- CVE-2026-14389HIGH 8.3
A flaw in Skia, the graphics engine used by Google Chrome, allows an attacker who already has code running in Chrome's renderer process to break out of the browser's security sandbox and gain control of your entire system. The vulnerability stems from an integer overflow—a math error in how the code handles very large numbers—that can be triggered by a specially crafted webpage. While Chrome's sandbox normally isolates the renderer from the rest of your computer, this flaw lets someone bypass that protection. The attack requires two things: first, the attacker must already have compromised the renderer process (through another vulnerability or social engineering), and second, you must visit a malicious webpage. Chrome versions before 150.0.7871.46 are affected.
- CVE-2026-14400HIGH 8.3
A memory writing flaw in Google Chrome's ANGLE graphics library allows an attacker who has already compromised the renderer process to escape the browser sandbox and gain broader system access. The attacker would need to serve a specially crafted webpage, but exploitation requires the renderer to be compromised first. Chrome versions before 150.0.7871.46 are affected.
- CVE-2026-14401HIGH 8.3
A vulnerability in Google Chrome's graphics rendering engine (ANGLE) on Android devices allows an attacker who has already compromised the browser's renderer process to potentially break out of the sandbox through a malicious HTML page. The vulnerability stems from insufficient checking of user input before it's processed by the graphics layer. Chrome version 150.0.7871.46 and earlier on Android are affected.
- CVE-2026-14412HIGH 8.3
Google Chrome versions prior to 150.0.7871.46 contain a vulnerability in ANGLE (the graphics abstraction layer) that permits sandbox escape. An attacker must first compromise Chrome's renderer process—the isolated component that executes website code—then exploit insufficient input validation to break out of the sandbox entirely. Once escaped, the attacker gains full system access equivalent to the logged-in user. The vulnerability requires user interaction (visiting a malicious page) but not social engineering beyond that.
- CVE-2026-14413HIGH 8.3
Google Chrome contains a flaw in ANGLE (Almost Native Graphics Layer Engine), its graphics abstraction layer, where certain variables are not properly initialized before use. An attacker who has already compromised Chrome's renderer process—the sandbox component that runs web content—can exploit this uninitialized memory to potentially break out of the sandbox entirely, gaining full system access. The vulnerability requires user interaction (visiting a malicious webpage) but affects versions before 150.0.7871.46.
- CVE-2026-14427HIGH 8.3
A memory corruption bug exists in Google Chrome's Skia graphics library that could allow an attacker to break out of Chrome's sandbox protection. The vulnerability requires an attacker to first compromise Chrome's renderer process—the component that displays web pages—and then serve a specially crafted HTML page to trigger a heap buffer overflow. If successfully exploited, the attacker could potentially escape the sandbox and gain broader access to the system.
- CVE-2026-14428HIGH 8.3
A validation flaw in Chrome's graphics rendering engine (Dawn) on Android allows an attacker who has already compromised the browser's renderer process to escape the sandbox and gain full system access. The vulnerability requires the attacker to have renderer-level access and trick a user into visiting a malicious webpage, but if those conditions are met, it bypasses a critical security boundary that normally prevents browser processes from accessing the underlying operating system.
- CVE-2026-14429HIGH 8.3
CVE-2026-14429 is a sandbox escape vulnerability in Google Chrome's Skia graphics library. An attacker who has already compromised Chrome's renderer process—the isolated sandbox where web content runs—can exploit insufficient input validation to break out of that sandbox and gain access to the user's full system. The attack requires the renderer to be compromised first and user interaction (such as visiting a malicious webpage), but once those conditions are met, the attacker can potentially access files, install malware, or execute arbitrary code with user privileges.
- CVE-2026-15119HIGH 8.3
A race condition exists in Google Chrome's GetUserMedia function that could allow an attacker to escape the browser's sandbox if they have already compromised the renderer process. The vulnerability requires user interaction and only affects Chrome versions before 150.0.7871.115. While this is a high-severity flaw, it requires a multi-step attack chain where the attacker must first gain code execution within the renderer before attempting the sandbox escape.
- CVE-2026-15120HIGH 8.3
A use-after-free memory vulnerability exists in Google Chrome's core rendering engine on Windows systems. An attacker who gains control of Chrome's renderer process—the isolated component that parses web content—can exploit this flaw via a malicious web page to escape the browser sandbox and execute arbitrary code with system privileges. The vulnerability requires both renderer compromise and user interaction, but the potential impact is severe because successful exploitation breaks Chrome's fundamental security isolation.
- CVE-2026-15122HIGH 8.3
Google Chrome on Windows contains a vulnerability in its codec handling that could allow an attacker who has already compromised the browser's renderer process to break out of the sandbox and gain full system access. The vulnerability requires both a compromised renderer and user interaction with a malicious webpage, but if successfully exploited, it could lead to complete system compromise. Chrome versions prior to 150.0.7871.115 are affected.
- CVE-2026-2053HIGH 8.3
WSO2 API Manager contains a vulnerability in how it processes WS-Addressing headers—a standard part of SOAP web service communications. The vulnerability stems from insufficient validation of user-controlled input within these headers. An unauthenticated attacker can exploit this by crafting malicious WS-Addressing headers that trick the API Manager into making requests to arbitrary destinations. This effectively turns the API Manager into a proxy for attacker-controlled network reconnaissance and access attempts, potentially exposing internal resources that should be isolated from external networks.
- CVE-2026-32905HIGH 8.3
OpenClaw versions before 2026.5.4 contain a flaw that lets users with basic chat access create device enrollment codes they shouldn't be able to generate. An attacker with legitimate chat permissions can issue bootstrap codes that add new devices with full operator and node-level capabilities to the system. Once enrolled, these devices retain administrative credentials indefinitely until an administrator manually removes them, creating a persistent backdoor.
- CVE-2026-34914HIGH 8.3
Revive Adserver versions 6.0.6 and earlier contain a SQL injection vulnerability in the zone-include.php script. A low-privileged user can manipulate the clientid parameter to inject SQL commands, potentially accessing, modifying, or deleting sensitive data from the underlying database. The vulnerability requires authentication, which limits exposure but still poses significant risk in shared hosting or multi-tenant environments where user accounts are readily available.