By year
Vulnerabilities disclosed in 2026
CVEs published in 2026 with SEC.co analysis.
8541 published vulnerabilities · page 46 of 86
- CVE-2026-13896MEDIUM 6.5
Google Chrome versions prior to 150.0.7871.47 contain a flaw in the Glic component that allows attackers to bypass navigation restrictions—mechanisms that prevent unauthorized page transitions or frame navigation. An attacker who crafts a malicious HTML page and tricks a user into visiting it can circumvent these protections, potentially redirecting the user to unintended destinations or manipulating browser navigation in ways that violate security policies. The vulnerability requires user interaction (clicking a link or visiting a page) but needs no special privileges to exploit.
- CVE-2026-13900MEDIUM 6.5
A vulnerability in Google Chrome's Chromecast implementation allows an attacker who has already compromised the browser's renderer process to bypass navigation security restrictions. The attacker would need to serve a specially crafted web page to exploit this weakness, potentially allowing unauthorized navigation that the browser normally blocks. This requires pre-existing renderer compromise, making it a secondary exploitation path rather than a direct attack vector.
- CVE-2026-13904MEDIUM 6.5
Google Chrome on iOS has a flaw in its Safe Browsing feature that allows attackers to bypass navigation restrictions designed to protect users from malicious sites. An attacker could craft a malicious HTML page that, when visited, tricks Chrome's safety mechanisms into allowing navigation to a blocked site. The vulnerability requires user interaction—the user must visit the attacker's page—but does not require special system privileges or browser configuration.
- CVE-2026-13906MEDIUM 6.5
Google Chrome versions before 150.0.7871.47 contain an out-of-bounds read vulnerability in its codec handling code. An attacker can craft a malicious HTML page that, when visited by a user, reads data from Chrome's process memory and potentially exposes sensitive information. The vulnerability requires user interaction (visiting a webpage) but no special privileges, and affects confidentiality only—not availability or integrity.
- CVE-2026-13908MEDIUM 6.5
Google Chrome on iOS versions before 150.0.7871.47 contain a flaw in the Omnibox (address bar) that allows attackers to bypass navigation security controls. An attacker could trick a user into performing specific gestures—like taps or swipes—while serving malicious network traffic, enabling the browser to navigate to unintended destinations or bypass intended restrictions. The vulnerability requires user interaction and network-level attack capability, but succeeds against users who may not notice subtle UI manipulation.
- CVE-2026-13910MEDIUM 6.5
Google Chrome on Android contains a vulnerability in its WebXR implementation that can allow attackers to steal data from websites you visit. An attacker would need to trick you into visiting a malicious webpage, but once there, they could potentially access sensitive information from other websites you have open in your browser. The vulnerability affects Chrome versions before 150.0.7871.47 on Android devices.
- CVE-2026-13913MEDIUM 6.5
Google Chrome on iOS has a weakness in how it enforces security policies for the autofill feature. A remote attacker can craft a malicious web page that, if a user interacts with it in specific ways, could leak sensitive data across website boundaries that should normally be hidden from each other. The vulnerability affects Chrome versions prior to 150.0.7871.47 and requires user interaction to exploit.
- CVE-2026-13917MEDIUM 6.5
Google Chrome for iOS contains a validation flaw that allows attackers to bypass navigation restrictions through a specially crafted web page. The vulnerability requires a user to perform specific interactions with the browser UI, but does not require any special privileges or configuration. An attacker could potentially redirect users to unintended destinations or manipulate the browsing experience by circumventing Chrome's navigation safeguards.
- CVE-2026-13919MEDIUM 6.5
Google Chrome prior to version 150.0.7871.47 contains a vulnerability in its extension security model that allows an attacker with an already-compromised renderer process to circumvent site isolation protections through a specially crafted web page. Site isolation is Chrome's fundamental defense mechanism that runs each website in a separate process; bypassing it could allow an attacker to access sensitive data from other sites the user is visiting. This requires both a prior renderer compromise and user interaction with a malicious page, but once those conditions are met, the integrity of Chrome's cross-site security boundary is undermined.
- CVE-2026-13921MEDIUM 6.5
Google Chrome versions prior to 150.0.7871.47 contain a flaw in how it validates input to the DeviceBoundSessionCredentials feature. An attacker can craft a malicious HTML page that, when visited by a user, bypasses Chrome's same-origin policy—a core security boundary that prevents websites from accessing data or making requests on behalf of other sites. The vulnerability requires user interaction (visiting the crafted page) but does not require special privileges to exploit.
- CVE-2026-13922MEDIUM 6.5
A side-channel vulnerability in Google Chrome's Paint component allows an attacker to extract sensitive data across website boundaries through a specially crafted webpage. The flaw affects Chrome versions before 150.0.7871.47 and requires user interaction (visiting a malicious site), but does not require special network access or browser extensions. An attacker cannot modify data or crash the browser with this flaw—only read information they shouldn't have access to.
- CVE-2026-13923MEDIUM 6.5
A flaw in Google Chrome's GPU rendering system on Android allows attackers to trick users into visiting a malicious website that extracts sensitive data from the browser's memory. The vulnerability stems from uninitialized memory in the GPU component—essentially, data that should have been cleared wasn't, leaving fragments of previous operations exposed. An attacker can craft a specially designed webpage that, when viewed by a Chrome user on Android, reads this uninitialized memory and exfiltrates information. Chrome version 150.0.7871.47 and later patch this issue.
- CVE-2026-13924MEDIUM 6.5
A flaw in Chrome's Android WebView allows an attacker who has already compromised the browser's rendering engine to bypass the same-origin policy—a core security boundary that prevents one website from accessing data belonging to another. The attacker would need to serve a specially crafted HTML page to trigger the bypass. This is a Medium-severity issue affecting Chrome versions before 150.0.7871.47 on Android.
- CVE-2026-13926MEDIUM 6.5
A flaw in Google Chrome's network validation allows an attacker who has already compromised Chrome's renderer process to bypass navigation security controls. The vulnerability exists because Chrome does not sufficiently validate untrusted input when handling network operations. An attacker would craft a malicious HTML page to trigger the bypass. While the attacker must have compromised the renderer first, the ability to then circumvent navigation restrictions could enable further malicious actions, such as redirecting users to unintended sites or accessing restricted resources.
- CVE-2026-13930MEDIUM 6.5
Google Chrome versions before 150.0.7871.47 contain a flaw in how the browser enforces navigation restrictions. An attacker can craft a malicious webpage that tricks the browser into allowing navigation to blocked or restricted destinations. The attack requires user interaction (clicking or interacting with the page) but doesn't require any special permissions or authentication. While the security rating is medium, the impact is real: users visiting a malicious site could be redirected to phishing pages, malware distribution sites, or other dangerous destinations that Chrome's security policies should have prevented.
- CVE-2026-13931MEDIUM 6.5
A vulnerability in Google Chrome's media handling on Windows allows an attacker who has already compromised the renderer process to trick users into believing they're interacting with a legitimate interface, when in fact they're seeing a fake one created by the attacker. The vulnerability requires the renderer to be compromised first, making it part of a multi-stage attack chain. It affects Chrome versions prior to 150.0.7871.47 on Windows.
- CVE-2026-13932MEDIUM 6.5
A vulnerability in Google Chrome on Android allows an attacker who has already compromised the browser's rendering engine to steal sensitive data from websites you visit. The attacker would need to trick you into visiting a malicious webpage, but once you do and given they control the renderer process, they can access information from other websites you have open—bypassing normal browser security boundaries. This affects Chrome versions before 150.0.7871.47 on Android devices.
- CVE-2026-13935MEDIUM 6.5
Google Chrome versions prior to 150.0.7871.47 contain a side-channel vulnerability in the ComputePressure API that allows an attacker to extract sensitive cross-origin data through a specially crafted webpage. The vulnerability does not require special privileges or system access—only that a user visit a malicious site—but does not enable attackers to modify data or disrupt service. The flaw stems from timing or behavioral information leakage when the browser queries system pressure metrics, potentially exposing information about other websites or applications running concurrently.
- CVE-2026-13936MEDIUM 6.5
Google Chrome on Android contains a flaw in how it handles password-related functionality that could allow an attacker to trick users into visiting a malicious webpage and leak sensitive information from the browser's memory. The vulnerability requires user interaction—specifically clicking a link or visiting a crafted site—but does not require any special privileges or authentication. Chrome version 150.0.7871.47 and earlier on Android are affected.
- CVE-2026-13937MEDIUM 6.5
Google Chrome versions before 150.0.7871.47 contain a flaw in password policy enforcement that could allow an attacker who has already compromised the browser's rendering engine to steal sensitive information from websites you visit. The attacker would craft a malicious web page to extract data that should remain isolated between different websites. While this requires the renderer process to be compromised first, it represents a meaningful step in a multi-stage attack chain.
- CVE-2026-13940MEDIUM 6.5
Google Chrome versions before 150.0.7871.47 contain a flaw in how the Cast feature handles uninitialized memory during type conversion. An attacker positioned on the same local network as a victim can send specially crafted network packets to trigger this bug, potentially reading sensitive data from Chrome's process memory without requiring user interaction or special privileges. The vulnerability is classified as medium severity.
- CVE-2026-13943MEDIUM 6.5
Google Chrome on Android contains a flaw where uninitialized memory in the CSS rendering engine can leak sensitive data to attackers. An attacker crafts a malicious webpage and tricks a user into visiting it; the browser then exposes fragments of process memory—potentially containing passwords, tokens, or other confidential information—that the attacker can read. This affects Chrome versions before 150.0.7871.47 on Android.
- CVE-2026-13949MEDIUM 6.5
A flaw in Google Chrome's payment handling on Android devices could allow an attacker to steal sensitive information from the browser's memory. The vulnerability requires a user to visit a malicious website, but does not require any special user privileges or browser configuration. An attacker could craft a deceptive web page that, when viewed, bypasses Chrome's security policies and leaks data from the payment system's process memory—potentially exposing payment-related information or other sensitive details stored there.
- CVE-2026-13953MEDIUM 6.5
Google Chrome versions before 150.0.7871.47 contain a flaw in how the SplitView feature handles navigation security checks. An attacker who has already compromised Chrome's renderer process—the component that executes web content—can exploit this weakness to bypass built-in navigation restrictions by serving a crafted HTML page. The vulnerability requires the attacker to have prior control of the renderer process, which substantially limits the attack surface but remains serious in environments where renderer compromise is plausible.
- CVE-2026-13954MEDIUM 6.5
Google Chrome on Android contains a flaw in how it enforces security policies when processing XML within web pages. An attacker can craft a malicious HTML page that, when visited by a user, allows the attacker to read sensitive data held in Chrome's process memory. This vulnerability requires user interaction (visiting a malicious page) but does not require the attacker to be authenticated or have special privileges. The vulnerability was patched in Chrome version 150.0.7871.47 and later.
- CVE-2026-13958MEDIUM 6.5
Google Chrome on Windows contains a memory safety bug in its codec handling that can leak sensitive information to attackers. When a user visits a specially crafted webpage, Chrome may fail to properly initialize certain codec variables, allowing the attacker to read unencrypted data from the browser's memory. This is a confidentiality risk—attackers cannot modify or destroy data, but they may access things like cached credentials, session tokens, or other sensitive information stored in memory during codec operations.
- CVE-2026-13962MEDIUM 6.5
A weakness in how Google Chrome validates PDF data could allow an attacker who has already compromised Chrome's renderer process to bypass navigation protections using a specially crafted webpage. The vulnerability requires both a prior compromise of the renderer and user interaction, limiting its real-world attack surface but representing a meaningful integrity risk once initial access is established.
- CVE-2026-13964MEDIUM 6.5
Google Chrome's WebView component on Android contains a flaw that allows attackers to circumvent navigation restrictions through a specially crafted web page. An attacker could trick a user into visiting a malicious HTML page, which then bypasses security controls that normally prevent unauthorized navigation to restricted destinations. This is a policy enforcement gap rather than a code execution vulnerability, meaning the browser's security rules aren't being properly applied in certain conditions.
- CVE-2026-13985MEDIUM 6.5
A flaw in Google Chrome's MediaCapture implementation allows attackers who have already compromised the browser's renderer process to trick users into interacting with fake UI elements. The attacker crafts a malicious HTML page that makes legitimate-looking interface components appear where they shouldn't, enabling social engineering attacks. This requires the renderer process to already be compromised, limiting the threat to scenarios where initial access has been established through other means.
- CVE-2026-13988MEDIUM 6.5
A vulnerability in Google Chrome's Paint feature allows attackers to trick users with fake visual elements on web pages. An attacker could craft a deceptive HTML page that, when visited, displays misleading UI elements—such as fake browser controls or warning dialogs—to manipulate user behavior. This affects Chrome versions before 150.0.7871.47 and requires user interaction (clicking or viewing the page) to be exploited. The attack has no impact on data confidentiality or system availability, but could be used for social engineering, credential theft, or other deception-based attacks.
- CVE-2026-13990MEDIUM 6.5
A vulnerability in Google Chrome's data transfer handling on Windows allows attackers who have already compromised the browser's renderer process to trick users into believing they are interacting with legitimate UI elements. The attacker would craft a malicious webpage that, once loaded, manipulates what appears on screen to deceive the user—for example, making a dangerous action look safe or hiding warning dialogs. This requires the renderer process to be compromised first, which is a meaningful prerequisite but not uncommon in real-world attack chains.
- CVE-2026-13996MEDIUM 6.5
Google Chrome versions before 150.0.7871.47 contain a flaw in how it handles permissions that allows an attacker to trick users with a fake webpage. When users visit a malicious site, the browser may display misleading permission prompts or UI elements, making it appear that certain actions have been approved or denied when they actually haven't. This spoofing attack requires user interaction—the victim must visit the crafted page—but does not result in data theft or system crashes.
- CVE-2026-14002MEDIUM 6.5
Google Chrome versions before 150.0.7871.47 contain a flaw in how the browser handles geolocation permissions that allows an attacker who has already compromised Chrome's renderer process to trick users with fake permission dialogs or spoofed UI elements. An attacker would need to first gain control of the renderer process through another vulnerability or attack vector, then exploit this weakness to display misleading geolocation prompts, potentially deceiving users into granting location access they wouldn't otherwise grant.
- CVE-2026-14004MEDIUM 6.5
A flaw in Google Chrome's CSS rendering engine can allow attackers to extract sensitive information from websites you visit. By crafting a malicious webpage, an attacker could potentially read data that should remain private between you and other websites you're logged into—such as account details or personal information. The vulnerability requires user interaction (clicking a link or visiting a page) and affects Chrome versions before 150.0.7871.47.
- CVE-2026-14007MEDIUM 6.5
Google Chrome versions before 150.0.7871.47 contain a flaw in how it enforces the Permissions Policy—a security feature that controls what browser capabilities (like camera, microphone, geolocation) web pages can access. An attacker can craft a malicious HTML page that tricks the browser into allowing navigation or access that should have been blocked by policy. The vulnerability requires user interaction (clicking a link or opening the page), but once triggered, it can bypass navigation restrictions that administrators or page developers intended to enforce.
- CVE-2026-14008MEDIUM 6.5
A memory disclosure vulnerability exists in Google Chrome's WebXR implementation on Android devices. An attacker can craft a malicious HTML page that, when visited by a user, reads uninitialized memory from the browser process. This could expose sensitive information such as encryption keys, authentication tokens, or other data previously used by the browser. The vulnerability requires user interaction—the victim must visit the crafted page—but does not require any special browser settings or user privileges to exploit.
- CVE-2026-14010MEDIUM 6.5
Google Chrome on Windows contains a flaw in how it handles certain codec operations, leaving uninitialized memory accessible to attackers. By serving a specially crafted webpage, an attacker can trick a user into visiting a malicious site and extract sensitive data—such as fragments of passwords, encryption keys, or other in-memory secrets—that happened to be nearby in the browser process. This is a memory disclosure vulnerability that requires user interaction (clicking a link or visiting a site) but poses meaningful risk because the leaked data could be valuable to an attacker.
- CVE-2026-14014MEDIUM 6.5
Google Chrome versions before 150.0.7871.47 contain a flaw in the Paint component that allows attackers to trick users into seeing a fake or misleading interface. An attacker would host a malicious webpage; when a user visits it, the page can manipulate what appears on screen to mimic legitimate UI elements (buttons, dialogs, login prompts) or hide the true nature of the content. This is a user-interaction vulnerability—the attack requires a victim to visit the crafted page, but no special browser settings or authentication bypass is needed.
- CVE-2026-14015MEDIUM 6.5
A race condition in Google Chrome's WebRTC implementation on Windows allows an attacker to trick users into visiting a malicious webpage that leaks data across security boundaries. The vulnerability is triggered during a timing-sensitive sequence in the WebRTC audio/video processing stack, where data meant to be isolated between different website origins becomes accessible. An attacker would need user interaction—specifically, the victim must visit the crafted HTML page—but once there, sensitive information from other websites could be exposed without further prompting.
- CVE-2026-14016MEDIUM 6.5
Google Chrome versions prior to 150.0.7871.47 contain a flaw in how SVG (Scalable Vector Graphics) content is processed that could allow an attacker to steal sensitive data from other websites. An attacker would need to trick a user into visiting a malicious webpage, but once there, the vulnerability could be exploited to access information the user has access to on other sites—bypassing the browser's normal cross-origin security boundary.
- CVE-2026-14019MEDIUM 6.5
A flaw in Google Chrome's password manager implementation allowed attackers to steal sensitive cross-origin data through a specially crafted webpage. The vulnerability required user interaction—specifically clicking on a malicious HTML page—but did not require any special privileges or complex setup to exploit. Chrome versions prior to 150.0.7871.47 are affected.
- CVE-2026-14021MEDIUM 6.5
A vulnerability in Google Chrome's StorageAccessAPI allows a remote attacker who has already compromised a user's Chrome renderer process to steal data from other websites that the user has visited. This requires both renderer compromise and user interaction with a malicious webpage, but if achieved, could leak sensitive cross-origin information. Chrome version 150.0.7871.47 and later address this issue.
- CVE-2026-14022MEDIUM 6.5
Google Chrome versions before 150.0.7871.47 contain a flaw that allows attackers who have already compromised Chrome's renderer process to steal data from websites the user visits. The vulnerability stems from inadequate validation of network input and requires an attacker to first gain control of the renderer—typically through a separate browser exploit—then use a specially crafted webpage to exfiltrate sensitive cross-origin information that should be protected from access.
- CVE-2026-14023MEDIUM 6.5
A flaw in Google Chrome's input validation allows attackers to bypass the same-origin policy—a fundamental browser security boundary—by sending users a specially crafted web page. This could enable unauthorized access to sensitive data from other websites the user is logged into. The vulnerability affects Chrome versions before 150.0.7871.47 and requires user interaction (visiting a malicious page).
- CVE-2026-14029MEDIUM 6.5
Groundhogg, a WordPress plugin used for customer relationship management, newsletters, and marketing automation, contains a SQL injection flaw that allows authenticated users with certain privileges to extract sensitive data from the database. The vulnerability exists in versions up to 4.5.8 and is triggered through the 'select' parameter, which the plugin fails to properly sanitize before using in database queries. While exploitation requires an attacker to already have a Groundhogg user account with custom-level access or higher, the capability needed (view_contacts) is granted by default to most built-in Groundhogg roles above subscriber level, making it a realistic threat for organizations running this plugin.
- CVE-2026-14033MEDIUM 6.5
Google Chrome on Windows contains a weakness in how it enforces policies related to media handling. An attacker can craft a malicious webpage that, when visited by a user, bypasses Chrome's site isolation feature—a critical security boundary that prevents one website from accessing data or capabilities of another. The vulnerability requires user interaction (clicking a link, visiting a page) and affects Chrome versions before 150.0.7871.47. While Chromium rates this as low severity internally, the CVSS score of 6.5 reflects the integrity impact of circumventing site isolation, making it a medium-severity concern in standard vulnerability assessment frameworks.
- CVE-2026-14035MEDIUM 6.5
Google Chrome versions prior to 150.0.7871.47 contain a Bluetooth-related security flaw that allows an attacker to extract sensitive information from the browser's memory. An attacker would need to trick a user into visiting a malicious webpage; if successful, the attacker could read data that shouldn't be accessible, such as authentication tokens, session data, or other confidential information stored in memory. Chrome itself rates this as low severity, though the CVSS score reflects moderate risk due to the ease of exploitation and the sensitivity of potential data exposure.
- CVE-2026-14048MEDIUM 6.5
A use-after-free flaw in Google Chrome's Chromecast component allows an attacker positioned on the same local network to extract sensitive data from the browser's memory using a specially crafted malicious peripheral device. The vulnerability affects Chrome versions before 150.0.7871.47 across Windows, macOS, and Linux systems.
- CVE-2026-14050MEDIUM 6.5
A weakness in how Google Chrome enforces security policies for the Passwords feature before version 150.0.7871.47 could allow an attacker to trick users into visiting a malicious webpage that leaks sensitive data across different websites. The attacker cannot directly compromise the browser; instead, they must craft a convincing HTML page and convince the user to visit it. Once a user is on that page, the vulnerability permits unauthorized access to information from other origins—effectively bypassing the browser's same-origin policy protections.
- CVE-2026-14051MEDIUM 6.5
A memory disclosure vulnerability exists in Google Chrome's GamepadAPI prior to version 150.0.7871.47. An attacker who has already compromised Chrome's renderer process can craft a malicious webpage to read uninitialized memory, potentially exposing sensitive data. The vulnerability requires user interaction (visiting a crafted page) and prior renderer compromise, making it a secondary risk in multi-stage attack chains rather than an entry vector.
- CVE-2026-14059MEDIUM 6.5
A security weakness in Google Chrome's Related-Website-Sets feature allows attackers to trick users into visiting a malicious webpage that can steal data from other websites the user is logged into. The vulnerability affects Chrome versions before 150.0.7871.47 and requires user interaction (clicking a link or visiting the malicious page). While the Chromium project rated this as low severity, the CVSS score reflects a medium-risk profile because of its potential to expose sensitive cross-origin information without the user's knowledge.
- CVE-2026-14061MEDIUM 6.5
A flaw in Google Chrome's Dawn graphics component allows attackers to trick users into visiting specially crafted web pages that can leak sensitive information from the browser's memory. The vulnerability requires user interaction—the victim must visit a malicious site—but once they do, attackers may be able to read data that should remain private, such as authentication tokens or other browser state. This affects Chrome versions before 150.0.7871.47 across Windows, macOS, and Linux systems.
- CVE-2026-14065MEDIUM 6.5
CVE-2026-14065 is a navigation-bypass vulnerability in Google Chrome versions before 150.0.7871.47. An attacker who has already compromised Chrome's renderer process (the component that executes web page content) can craft a malicious HTML page to circumvent built-in navigation security controls. While this requires prior renderer compromise, the impact allows unauthorized navigation to restricted destinations. The Chromium project rates this as low severity, though the CVSS score of 6.5 reflects the potential for integrity violation.
- CVE-2026-14069MEDIUM 6.5
An integer overflow vulnerability exists in the WebNN (Web Neural Network) component of Google Chrome versions before 150.0.7871.47. An attacker could craft a malicious HTML page that, when visited, exploits this flaw to read sensitive data from the browser's memory. The vulnerability requires user interaction (visiting a malicious site) but does not require any special privileges or system access.
- CVE-2026-14070MEDIUM 6.5
A memory safety vulnerability in Google Chrome's WebNN (Web Neural Network) component allows attackers to leak sensitive data from the browser's memory. An attacker can craft a malicious webpage that, when visited by a user, exploits an integer overflow to read unintended data from the running process. While Chrome classified this as low severity internally, the confidentiality impact warrants attention from a defense perspective.
- CVE-2026-14071MEDIUM 6.5
Google Chrome versions before 150.0.7871.47 contain a side-channel vulnerability in the WebAudio component that allows attackers to extract sensitive cross-origin data through a specially crafted webpage. An attacker would need to trick a user into visiting a malicious site, but once there, they could potentially read data from other websites the user has open—a serious breach of browser security boundaries. The vulnerability is rated MEDIUM severity due to its reliance on user interaction and limited scope of impact.
- CVE-2026-14074MEDIUM 6.5
A side-channel vulnerability in Google Chrome's WebAuthentication implementation on iOS allows an attacker to leak sensitive cross-origin data through a crafted web page. The flaw exists in Chrome versions before 150.0.7871.47 and requires user interaction to trigger. An attacker would craft a malicious HTML page that, when visited by a victim, exploits timing or behavioral differences in the WebAuthentication API to infer or extract data from other websites the user has authenticated to.
- CVE-2026-14081MEDIUM 6.5
Google Chrome versions before 150.0.7871.47 contain a flaw in DevTools policy enforcement that could allow an attacker to extract sensitive data from browser process memory. The vulnerability requires social engineering—convincing a user to install a malicious extension—but once installed, the extension can bypass DevTools restrictions to access confidential information. This is not a flaw users can trigger by visiting a website; it hinges on the user's decision to add untrusted code to their browser.
- CVE-2026-14082MEDIUM 6.5
A race condition in Google Chrome's storage subsystem allows attackers to access sensitive data across different websites through a specially crafted HTML page. The vulnerability requires user interaction—such as visiting a malicious webpage—but doesn't need special privileges or browser configuration to exploit. While Chromium's own severity rating is 'Low,' the confidentiality impact warrants a medium-severity classification due to the potential exposure of cross-origin data that should otherwise be isolated by browser security boundaries.
- CVE-2026-14085MEDIUM 6.5
A side-channel vulnerability in Google Chrome's CSS rendering engine allows attackers to extract sensitive cross-origin data through a specially crafted webpage. An attacker can trick a user into visiting a malicious site that leaks information from other sites the user has open in the same browser—such as authentication tokens, form data, or private content. The vulnerability requires user interaction (visiting the malicious page) but does not need special browser settings or elevated privileges. Chrome versions prior to 150.0.7871.47 are affected.
- CVE-2026-14088MEDIUM 6.5
A memory leakage vulnerability in Chrome's Canvas rendering on Android devices allows attackers to trick users into visiting a malicious webpage that can read sensitive data from the browser's memory. The attacker needs the user to interact with the page, but no special privileges or complex attack setup is required. Chrome versions prior to 150.0.7871.47 on Android are affected.
- CVE-2026-14096MEDIUM 6.5
A flaw in Google Chrome's input handling on Android could allow an attacker to steal sensitive information across different websites, but only if they've already compromised Chrome's renderer process—the engine that executes web content. The attacker would need to trick the user into visiting a specially crafted webpage. This is a medium-severity issue affecting Chrome versions before 150.0.7871.47.
- CVE-2026-14098MEDIUM 6.5
A flaw in how Google Chrome handles CSS allows an attacker to craft a malicious webpage that can read data from websites on different domains—a cross-origin information leak. The vulnerability affects Chrome versions before 150.0.7871.47. While the attack requires user interaction (visiting the malicious page), the potential impact is significant: sensitive information from other websites could be exposed to the attacker. This is classified as a medium-severity issue, though Chromium's own assessment rated the underlying CSS implementation flaw as low severity.
- CVE-2026-14100MEDIUM 6.5
CVE-2026-14100 is a data leakage vulnerability in Google Chrome's NetworkCache component that allows attackers to extract sensitive information across website boundaries. An attacker crafts a malicious HTML page and tricks a user into visiting it; the flaw then permits unauthorized access to data that should remain isolated between different websites. While Google rates the underlying defect as low severity, the practical impact—cross-origin data exposure—warrants a medium CVSS score because it requires user interaction but reliably compromises confidentiality.
- CVE-2026-14103MEDIUM 6.5
A use-after-free memory flaw in Google Chrome's SSL/TLS implementation on ChromeOS allows an attacker to craft a malicious webpage that, when visited, can leak sensitive data from the browser's memory. The vulnerability requires user interaction (visiting a malicious site) but does not require authentication and can run over the network. Chrome versions before 150.0.7871.47 are affected. While Chromium's security team rated this as Low severity, the CVSS 3.1 score of 6.5 reflects the potential for meaningful confidentiality impact.
- CVE-2026-14118MEDIUM 6.5
A flaw in Chrome's developer tools allows attackers to trick users into leaking sensitive data from other websites through a specially crafted web page. The vulnerability requires users to perform specific interactions within DevTools, making it a social engineering attack rather than something that exploits silently. While Chromium rates this as low severity, the ability to cross origin boundaries and steal data elevates the practical risk for users who frequently interact with sensitive websites.
- CVE-2026-14119MEDIUM 6.5
Google Chrome on Windows contains a type confusion vulnerability in its Bluetooth handling that could allow an attacker already present on your local network to read sensitive data from Chrome's process memory by presenting a specially crafted Bluetooth peripheral. The vulnerability affects Chrome versions before 150.0.7871.47. While the technical severity is rated Medium, the practical risk is moderated by the requirement that an attacker must already have local network access and the ability to present a malicious Bluetooth device.
- CVE-2026-14125MEDIUM 6.5
A flaw in the ANGLE graphics library used by Google Chrome can leak sensitive data from a user's computer memory to an attacker through a malicious webpage. When a user visits a crafted HTML page, uninitialized memory containing potentially sensitive information becomes accessible, allowing the attacker to read data that should have been protected. The vulnerability requires user interaction—specifically visiting a malicious site—but no special privileges or complex setup are needed on the attacker's side.
- CVE-2026-14146MEDIUM 6.5
Google Chrome versions before 150.0.7871.47 contain a flaw in how the browser processes CSS that could allow an attacker to trick users into visiting a malicious website and leak data from other websites the user has open. The vulnerability requires user interaction (clicking a link or visiting a page) but does not require the attacker to have special privileges or bypass browser security features. While Chromium's security team rated this Low severity internally, the CVSS score reflects a Medium risk due to the potential for unauthorized information disclosure across security boundaries.
- CVE-2026-14148MEDIUM 6.5
A type confusion flaw in Google Chrome's CSS handling allows a remote attacker to trick a user into visiting a malicious webpage and potentially read sensitive data from the browser's process memory. The vulnerability requires user interaction (clicking a link or visiting a page) but no special privileges. While Chromium rates the severity as low, the ability to leak memory contents elevates practical risk for targeted attacks.
- CVE-2026-14155MEDIUM 6.5
A flaw in Google Chrome's StorageAccessAPI—a mechanism that allows websites to request cross-origin data access—fails to enforce sufficient security policies. This permits an attacker to craft a malicious webpage that tricks users into leaking sensitive data from other websites. The vulnerability requires user interaction and is limited to information disclosure; it does not enable data modification or service disruption. Chrome versions prior to 150.0.7871.47 are affected.
- CVE-2026-14156MEDIUM 6.5
A flaw in Google Chrome's StorageAccessAPI allowed attackers who had already compromised the browser's rendering engine to bypass the same-origin policy—a core security boundary that prevents malicious websites from accessing data belonging to other sites. The attacker would need to trick a user into visiting a specially crafted webpage while the renderer process was already compromised. This vulnerability affects Chrome versions before 150.0.7871.47.
- CVE-2026-14258MEDIUM 6.5
dhcpcd, a widely used DHCP client daemon, contains a flaw in how it processes IPv6 Router Advertisement messages from the network. An attacker on the local network segment can send a specially crafted Router Advertisement packet with a zero-length option that bypasses validation checks. When the daemon attempts to reparse this malformed packet, it enters an infinite loop, consuming CPU resources until the process is manually stopped or the system is rebooted. This results in a denial-of-service condition affecting the target system's availability.
- CVE-2026-14324MEDIUM 6.5
A flaw in the RAOP (Remote Audio Output Protocol) module allows an attacker on the local network to cause a denial of service by sending requests with extremely large Content-Length values. The module fails to properly validate these values and does not check whether internal memory allocation operations succeed, leading to potential crashes or service unavailability.
- CVE-2026-14381MEDIUM 6.5
Google Chrome versions before 150.0.7871.46 contain a flaw in the WebAppInstalls security UI that allows attackers to deceive users through carefully crafted web pages. An attacker can make Chrome's security indicators or install prompts appear fake, potentially tricking users into installing malicious web applications or granting unintended permissions. The vulnerability requires user interaction to exploit but poses a real risk because users rely on Chrome's visual cues to make trust decisions.
- CVE-2026-14384MEDIUM 6.5
A memory safety flaw in Chrome's graphics rendering engine (ANGLE) allows attackers to read sensitive data across security boundaries on Windows systems. By serving a specially crafted webpage, an attacker can trick a user into visiting a malicious site and leak information that should remain private—such as data from other websites the user has open. The vulnerability requires user interaction (clicking or visiting a link) but does not require the attacker to be authenticated or have special privileges.
- CVE-2026-14386MEDIUM 6.5
A memory access vulnerability in Chrome's graphics rendering engine (ANGLE) allows attackers to read sensitive data from your browser's memory by tricking you into visiting a specially crafted webpage. The vulnerability affects Chrome versions before 150.0.7871.46 and requires user interaction—you must click or view malicious content for the attack to work. An attacker cannot execute code or crash your browser, but they could potentially steal passwords, tokens, or other sensitive information stored in memory.
- CVE-2026-14388MEDIUM 6.5
Google Chrome versions before 150.0.7871.46 contain a memory reading vulnerability in the ANGLE graphics library. A remote attacker can exploit this by serving a specially crafted HTML page to a user. If a user visits the malicious page, the attacker may extract sensitive information—such as passwords, encryption keys, or other data—from Chrome's process memory. The vulnerability requires user interaction (clicking a link or visiting a site) but does not require any special privileges or configuration.
- CVE-2026-14396MEDIUM 6.5
A memory safety issue in the ANGLE graphics library used by Google Chrome allows attackers to read sensitive data across website boundaries. When a user visits a malicious webpage, an attacker can craft specific HTML content that triggers an out-of-bounds memory read. This flaw enables unauthorized access to data intended for other websites—a cross-origin information disclosure. The vulnerability requires user interaction (visiting a malicious page) but does not require any special browser configuration or credentials.
- CVE-2026-14399MEDIUM 6.5
A memory initialization flaw in Chrome's graphics rendering engine (Dawn) could allow an attacker to trick a user into visiting a specially crafted webpage that reads sensitive data from the browser's memory. The issue affects Chrome versions before 150.0.7871.46 and requires user interaction—the victim must click through or visit a malicious site—but does not require any special system privileges. Once exploited, an attacker gains read access to information already in memory, potentially including cached credentials, session tokens, or other sensitive data processed by the browser.
- CVE-2026-14402MEDIUM 6.5
A memory disclosure vulnerability in Google Chrome's ANGLE graphics library on Windows allows attackers to leak sensitive data from the browser process. An attacker can craft a malicious HTML page that, when visited by a user, reads uninitialized memory regions. While this does not allow code execution or system compromise, the leaked data could include passwords, session tokens, or other secrets resident in Chrome's memory space.
- CVE-2026-14404MEDIUM 6.5
A flaw in Google Chrome's PDF rendering engine (PDFium) allows attackers to trick users with misleading visual elements in specially crafted PDF files. When you open a malicious PDF, the attacker can manipulate what appears on screen to deceive you about the file's true content or origin—for example, making a phishing document look legitimate. The vulnerability affects Chrome versions before 150.0.7871.46 and requires user interaction (opening the PDF) to exploit.
- CVE-2026-14408MEDIUM 6.5
Google Chrome versions before 150.0.7871.46 contain a memory initialization flaw in Dawn (Chrome's graphics abstraction layer) that allows attackers to trick users into visiting malicious web pages and potentially read sensitive data from the browser process. The vulnerability requires user interaction—specifically clicking a link or visiting a crafted website—but does not require special permissions or an authenticated account.
- CVE-2026-14421MEDIUM 6.5
A memory initialization flaw in Google Chrome's graphics library (Dawn) allows an attacker to trick users into visiting a malicious website that leaks sensitive data from the browser's memory. The vulnerability affects Chrome on ChromeOS systems prior to version 150.0.7871.46. While exploitation requires user interaction—clicking a link or visiting a crafted page—the flaw can expose information that might aid further attacks, such as cryptographic keys or session tokens. The impact is information disclosure only; the attacker cannot execute code or crash the system.
- CVE-2026-14714MEDIUM 6.5
A flaw in chatgpt-on-wechat (CowAgent) version 2.1.0 allows attackers to bypass authentication on the WeChat endpoint by manipulating or omitting a required security token. The vulnerable code fails to validate whether the token is actually present before attempting signature verification, meaning an empty or missing token can pass authentication checks. An attacker can exploit this remotely without credentials to interfere with message integrity or system availability.
- CVE-2026-14792MEDIUM 6.5
A security flaw in Formbricks 5.0.0 allows remote attackers to bypass access controls on survey-related functionality without requiring authentication. The vulnerability exists in the survey link handling component and can be exploited to modify data or disrupt availability. Upgrading to version 5.1.0-rc.1 or later resolves the issue.
- CVE-2026-14803MEDIUM 6.5
Mojo::JSON, a widely-used JSON parsing library for Perl, has a vulnerability in its pure-Perl decoder that allows attackers to consume excessive memory through deeply nested JSON structures. When a malicious or malformed JSON document with extreme nesting depth is parsed, the decoder recurses without limits, exhausting available memory and crashing the application. This affects only the pure-Perl fallback decoder; systems using the faster Cpanel::JSON::XS library are unaffected. Any Perl application that accepts JSON input from untrusted sources—such as HTTP request bodies—is vulnerable if Cpanel::JSON::XS is not installed or has been explicitly disabled.
- CVE-2026-14898MEDIUM 6.5
The OpenAI Codex desktop app for macOS has a vulnerability that allows attackers to steal sensitive information from users' sessions. An attacker can craft malicious prompts that trick the Codex model into generating URLs pointing to attacker-controlled servers. When the app displays the response, it automatically loads these remote images without requiring the user to click anything, causing the embedded sensitive data—like API keys or source code—to be sent to the attacker. This happens because the app renders Markdown-formatted responses and fetches remote images automatically.
- CVE-2026-14904MEDIUM 6.5
AWS Research and Engineering Studio (RES) contains a flaw that allows authenticated users to read any file on the cluster-manager server by exploiting how the system handles SSH key uploads. An attacker with valid credentials can replace their SSH private key with a symbolic link pointing to sensitive files elsewhere on the server. Because the cluster-manager process runs with root privileges, this exposes files that should be restricted, including other users' SSH keys and application secrets. This is a privilege-escalation risk that requires valid authentication to exploit, but once inside, the attacker gains broad file-read access they shouldn't have.
- CVE-2026-1500MEDIUM 6.5
GitLab CE and EE are vulnerable to a denial-of-service attack that can be triggered by authenticated users uploading specially crafted files. When an attacker sends a malicious file, the affected GitLab instance consumes excessive system resources (CPU, memory, disk I/O) without proper limits, potentially making the service unavailable to legitimate users. The vulnerability requires valid login credentials but no special user privileges to exploit.
- CVE-2026-15104MEDIUM 6.5
The BetterDocs plugin for WordPress—used to build internal documentation, knowledge bases, and FAQ systems—contains a SQL injection vulnerability in versions up to 4.6.0. An authenticated user with custom-level access or higher can manipulate a language parameter to inject malicious SQL commands and extract sensitive data from the site's database. The attack requires a supported multilingual plugin (WPML, Polylang, qTranslate, Weglot, or TranslatePress) to be active, which gates the vulnerable code path.
- CVE-2026-15109MEDIUM 6.5
A memory initialization flaw in ANGLE (the graphics abstraction layer used by Chrome) could allow an attacker to trick a user into visiting a malicious website that leaks sensitive data from the browser's memory. The vulnerability requires user interaction—a user must click a link or visit the page—but once there, the flaw enables reading uninitialized memory that may contain passwords, tokens, or other private information.
- CVE-2026-15154MEDIUM 6.5
A vulnerability in Red Hat OpenShift AI's guardrails-detectors component allows attackers to craft malicious regular expressions that trigger excessive processing on the system. When processed by the detection API, these expressions cause a worker process to consume all available CPU indefinitely, effectively freezing the LLM safeguard pipeline and preventing legitimate requests from being served.
- CVE-2026-15192MEDIUM 6.5
A missing authentication vulnerability exists in Mettle Sendportal's API webhook handlers for email service integrations (Sendgrid, Postmark, Postal, Mailjet). An unauthenticated attacker can remotely manipulate webhook functions, potentially allowing unauthorized interception or modification of email delivery notifications. The vulnerability affects versions up to and including 3.0.1, and public exploitation details are available.
- CVE-2026-15287MEDIUM 6.5
The rtMedia plugin for WordPress, which integrates with BuddyPress and bbPress, contains a SQL injection vulnerability in how it processes the order_by parameter. Attackers who have at minimum a subscriber-level WordPress account can manipulate this parameter to inject malicious SQL commands into database queries. This allows them to read sensitive data stored in the WordPress database without modifying or deleting it. The vulnerability affects all versions up to and including 4.6.18.
- CVE-2026-1869MEDIUM 6.5
A critical vulnerability in the popular User Registration & Membership WordPress plugin allows attackers to bypass payment processing and activate premium memberships without paying. The flaw exists in the payment confirmation function, which fails to validate user input properly. Any visitor to a site running the vulnerable plugin can exploit this to gain access to paid content and features, potentially causing revenue loss and unauthorized access to restricted materials.
- CVE-2026-1871MEDIUM 6.5
TP-Link Tapo C200 v5 camera firmware contains a flaw in how it validates incoming RTSP (Real Time Streaming Protocol) authentication requests. An attacker on the local network can send a specially crafted authentication message that overflows a memory buffer, crashing the camera's streaming service and forcing an automatic reboot. During this outage, users cannot view live video or manage the camera remotely. Once the camera restarts, service is restored, but the vulnerability remains exploitable, making repeated attacks feasible.
- CVE-2026-22551MEDIUM 6.5
Eclipse Theia, a browser-based IDE platform, contains a vulnerability in its AI chat feature that allows attackers to exfiltrate sensitive workspace data. When a user opens a malicious or compromised workspace and interacts with the AI chat, an attacker can inject prompts that trick the AI into generating Markdown image tags pointing to attacker-controlled servers. Because Theia automatically renders these images by fetching them from arbitrary URLs, the attacker can encode sensitive information—such as file contents, API keys, or conversation history—in the image URL itself, effectively stealing it. This requires user interaction (opening a workspace and using AI chat) but no special privileges. The risk is elevated in environments where developers regularly open workspaces from untrusted or semi-trusted sources.
- CVE-2026-22899MEDIUM 6.5
A NULL pointer dereference flaw in QNAP File Station 6 allows authenticated users to crash the service, causing a denial-of-service condition. An attacker must first obtain valid user credentials to exploit this vulnerability. The issue does not compromise confidentiality or integrity—only availability. QNAP has released a patch for File Station 5 version 5.5.6.5208 and later; however, the advisory indicates File Station 6 remains affected, and a specific patched version for File Station 6 has not yet been disclosed in available vendor guidance.
- CVE-2026-23638MEDIUM 6.5
Kiteworks, a platform designed to secure and control data sharing across organizations, contains a flaw that allows authenticated users to modify form approval workflows that belong to other users. The vulnerability stems from inadequate checks on who actually owns or has permission to modify a particular form's configuration. An attacker with valid Kiteworks credentials could exploit this to alter how forms route for approval, potentially disrupting legitimate business processes or gaining unauthorized visibility into sensitive approvals.