| Integer overflow in Skia in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML… CVE-2026-103629 | Severity medium |
| Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the… CVE-2026-103628 | Severity critical |
| Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social… CVE-2026-103626 | Severity critical |
| Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a… CVE-2026-103625 | Severity high |
| Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the… CVE-2026-103624 | Severity high |
| Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a… CVE-2026-103622 | Severity high |
| Integer overflow in Compositing in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted… CVE-2026-103621 | Severity medium |
| chromium-browser: angle: chromium-browser: arbitrary code execution via buffer overflow in ANGLE CVE-2026-102331 | Severity critical |
| chromium-browser: chromium-browser: Incorrect authorization in SiteIsolation CVE-2026-102330 | Severity medium |
| chromium-browser: chromium-browser: Cross-site scripting in WebUI CVE-2026-102329 | Severity high |
| chromium-browser: chromium-browser: Type confusion in V8 CVE-2026-102328 | Severity high |
| chromium-browser: chromium-browser: Incorrect authorization in WebView CVE-2026-102327 | Severity high |
| chromium-browser: chromium-browser: Type confusion in V8 CVE-2026-102326 | Severity high |
| chromium-browser: chromium-browser: Uninitialized resource in Skia CVE-2026-102325 | Severity medium |
| chromium-browser: chromium-browser: Use after free in PictureInPicture CVE-2026-102324 | Severity high |
| chromium-browser: chromium-browser: Type confusion in V8 CVE-2026-102323 | Severity high |
| chromium-browser: chromium-browser: Type confusion in V8 CVE-2026-102321 | Severity high |
| chromium-browser: chromium-browser: Missing authorization in CORS CVE-2026-102320 | Severity medium |
| chromium-browser: chromium-browser: Uninitialized resource in GPU CVE-2026-102319 | Severity high |
| chromium-browser: chromium-browser: Out of bounds read in WebGL CVE-2026-102318 | Severity high |
| chromium-browser: chromium-browser: Improper privilege management in Mojo CVE-2026-102317 | Severity high |
| chromium-browser: chromium-browser: Use after free in Views CVE-2026-102316 | Severity critical |
| chromium-browser: chromium-browser: Uninitialized resource in Media CVE-2026-102315 | Severity high |
| chromium-browser: chromium-browser: UI misrepresentation in TabStrip CVE-2026-102314 | Severity medium |
| chromium-browser: angle: chromium-browser: Information disclosure via uninitialized resource in ANGLE CVE-2026-102313 | Severity high |
| chromium-browser: chromium-browser: UI misrepresentation in Omnibox CVE-2026-102312 | Severity medium |
| chromium-browser: chromium-browser: Uninitialized resource in GPU CVE-2026-102311 | Severity high |
| chromium-browser: chromium-browser: Missing authorization in Payments CVE-2026-102310 | Severity medium |
| chromium-browser: chromium-browser: Use after free in FullScreen CVE-2026-102309 | Severity critical |
| Use after free in Views in Google Chrome prior to 154.0.8037.92 allowed a remote attacker leveraging social engineering to execute… CVE-2026-102308 | Severity critical |
| chromium-browser: chromium-browser: Uninitialized resource in Dawn CVE-2026-102307 | Severity high |
| chromium-browser: chromium-browser: Use after free in Bluetooth CVE-2026-102306 | Severity critical |
| chromium-browser: chromium-browser: UI misrepresentation in SignIn CVE-2026-102305 | Severity medium |
| chromium-browser: chromium-browser: Use after free in Passwords CVE-2026-102304 | Severity critical |
| chromium-browser: chromium-browser: Uninitialized resource in GPU CVE-2026-102303 | Severity medium |
| chromium-browser: chromium-browser: Buffer overflow in V8 CVE-2026-102302 | Severity high |
| chromium-browser: chromium-browser: Out of bounds write in GPU CVE-2026-102301 | Severity high |
| chromium-browser: chromium-browser: Uninitialized resource in WebGPU CVE-2026-102300 | Severity medium |
| chromium-browser: chromium-browser: Type confusion in V8 CVE-2026-102299 | Severity high |
| Inappropriate implementation in PlatformIntegration in Google Chrome on on Windows prior to 154.0.8037.57 allowed a remote attacker… CVE-2026-95385 | Severity medium |
| Race condition in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially leak sensitive… CVE-2026-95384 | Severity medium |
| chromium-browser: Improper input validation in Auth CVE-2026-95382 | Severity medium |
| Improper input validation in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer… CVE-2026-95381 | Severity high |
| chromium-browser: Type confusion in V8 CVE-2026-95380 | Severity high |
| Externally controlled reference in DevTools in Google Chrome prior to 154.0.8037.57 allowed an adjacent attacker leveraging social… CVE-2026-95376 | Severity high |
| Incorrect authorization in BrowserTag in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer… CVE-2026-95375 | Severity medium |
| Incorrect authorization in Network in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a… CVE-2026-95374 | Severity medium |
| chromium-browser: Use after free in DevTools CVE-2026-95373 | Severity high |
| Use after free in Chromecast in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to… CVE-2026-95372 | Severity high |
| Missing authorization in Views in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer… CVE-2026-95371 | Severity medium |
| Inappropriate implementation in NFC in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions… CVE-2026-95370 | Severity medium |
| Inappropriate implementation in XML in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code… CVE-2026-95369 | Severity high |
| Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to… CVE-2026-95368 | Severity medium |
| Information leak in DataTransfer in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process… CVE-2026-95367 | Severity medium |
| Use of released resource in Core in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process… CVE-2026-95366 | Severity medium |
| Type confusion in IndexedDB in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside… CVE-2026-95365 | Severity high |
| Improper input validation in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted… CVE-2026-95364 | Severity medium |
| UI misrepresentation in FileSystem in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof… CVE-2026-95363 | Severity medium |
| Cross-site request forgery in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to… CVE-2026-95362 | Severity high |
| Confused deputy in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web… CVE-2026-95361 | Severity medium |
| Race condition in Editing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain… CVE-2026-95360 | Severity medium |
| chromium-browser: Uninitialized resource in GPU CVE-2026-95359 | Severity medium |
| Incorrect authorization in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to bypass system access… CVE-2026-95358 | Severity medium |
| chromium-browser: Out of bounds write in GPU CVE-2026-95357 | Severity critical |
| Use after free in WindowDialog in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to… CVE-2026-95356 | Severity critical |
| chromium-browser: Incorrect authorization in Navigation CVE-2026-95355 | Severity high |
| chromium-browser: Use after free in Verifier CVE-2026-95354 | Severity high |
| Use after free in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox… CVE-2026-95353 | Severity high |
| Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to… CVE-2026-95352 | Severity medium |
| chromium-browser: Use after free in Views CVE-2026-95351 | Severity high |
| chromium-browser: angle: Buffer overflow in ANGLE CVE-2026-95350 | Severity critical |
| Buffer overflow in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary… CVE-2026-95349 | Severity critical |
| Use after free in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to… CVE-2026-95348 | Severity high |
| chromium-browser: Use after free in Updater CVE-2026-95347 | Severity critical |
| UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via crafted… CVE-2026-95346 | Severity medium |
| Use after free in Actor in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via… CVE-2026-95345 | Severity high |
| Race condition in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass site… CVE-2026-95344 | Severity high |
| Use after free in WebAudio in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox… CVE-2026-95343 | Severity high |
| chromium-browser: Missing authorization in V8 CVE-2026-95342 | Severity medium |
| Improper input validation in Desktop in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer… CVE-2026-95341 | Severity high |
| Incorrect authorization in PictureInPicture in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering… CVE-2026-95340 | Severity medium |
| Use after free in ServiceWorker in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the… CVE-2026-95339 | Severity critical |
| Use after free in PDFium in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via… CVE-2026-95338 | Severity high |
| UI misrepresentation in Messages in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker leveraging social… CVE-2026-95337 | Severity medium |
| Information leak in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering… CVE-2026-95336 | Severity medium |
| Use after free in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to… CVE-2026-95335 | Severity high |
| Incorrect reference resolution in WebProtect in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the… CVE-2026-95334 | Severity high |
| chromium-browser: Use after free in Metrics CVE-2026-95333 | Severity high |
| chromium-browser: Use of uninitialized variable in Tint CVE-2026-95332 | Severity medium |
| chromium-browser: angle: Out of bounds write in ANGLE CVE-2026-95331 | Severity critical |
| Improper state validation in Downloads in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access… CVE-2026-95330 | Severity medium |
| chromium-browser: Out of bounds write in WebGL CVE-2026-95329 | Severity critical |
| Confused deputy in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker leveraging social engineering to… CVE-2026-95328 | Severity medium |
| Information leak in Networking in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to leak sensitive information via a… CVE-2026-95327 | Severity medium |
| Incomplete cleanup in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass… CVE-2026-95326 | Severity high |
| chromium-browser: angle: Use after free in ANGLE CVE-2026-95325 | Severity critical |
| chromium-browser: Uninitialized resource in GPU CVE-2026-95324 | Severity high |
| UI misrepresentation in Chromium in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering… CVE-2026-95323 | Severity medium |
| Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer… CVE-2026-95322 | Severity high |
| UI misrepresentation in Payments in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a… CVE-2026-95321 | Severity medium |