2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8574 — Use: after free in Core in Google Chrome on Windows prior to 148.0.7778.168 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8574

Use after free in Core in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8573 — Integer: overflow in Codecs in Google Chrome on Windows prior to 148.0.7778.168 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8573

Integer overflow in Codecs in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium) CVSSv3.1 8.3 (HIGH)

CWECWE 472TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8571 — GPU: Insufficient policy enforcement in GPU in Google Chrome on Android prior to 148.0.7778.168 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8571

Insufficient policy enforcement in GPU in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.3 (HIGH)

CWECWE 693VNDGpuTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8569 — Out: of bounds write in Codecs in Google Chrome on Mac prior to 148.0.7778.168

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8569

Out of bounds write in Codecs in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium) CVSSv3.1 8.3 (HIGH)

CWECWE 787TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8558 — Out: of bounds write in Fonts in Google Chrome prior to 148.0.7778.168 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8558

Out of bounds write in Fonts in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 787TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8555 — Use: after free in GTK in Google Chrome on Windows prior to 148.0.7778.168 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8555

Use after free in GTK in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8551 — Use: after free in Downloads in Google Chrome prior to 148.0.7778.168 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8551

Use after free in Downloads in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8549 — Use: after free in Media in Google Chrome prior to 148.0.7778.168 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8549

Use after free in Media in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8548 — Out: of bounds write in Media in Google Chrome prior to 148.0.7778.168 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8548

Out of bounds write in Media in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 787TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8544 — Use: after free in Media in Google Chrome prior to 148.0.7778.168 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8544

Use after free in Media in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8542 — Use: after free in Core in Google Chrome on Windows prior to 148.0.7778.168 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8542

Use after free in Core in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8540 — Type: Confusion in V8 in Google Chrome prior to 148.0.7778.168 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8540

Type Confusion in V8 in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 843VNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8534 — Integer: overflow in GPU in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8534

Integer overflow in GPU in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 472TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8533 — Use: after free in Accessibility in Google Chrome prior to 148.0.7778.168 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8533

Use after free in Accessibility in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8532 — Integer: overflow in XML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8532

Integer overflow in XML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 472TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8531 — Heap: buffer overflow in WebML in Google Chrome on Windows prior to 148.0.7778.168 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8531

Heap buffer overflow in WebML in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8530 — Use: after free in Network in Google Chrome on Windows prior to 148.0.7778.168 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8530

Use after free in Network in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8529 — Heap: buffer overflow in Codecs in Google Chrome prior to 148.0.7778.168 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8529

Heap buffer overflow in Codecs in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8527 — Insufficient validation of untrusted input in Downloads in Google Chrome prior to 148.0.7778.168 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8527

Insufficient validation of untrusted input in Downloads in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 20TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8526 — Out: of bounds write in WebRTC in Google Chrome prior to 148.0.7778.168 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8526

Out of bounds write in WebRTC in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 787TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8525 — Heap: buffer overflow in ANGLE in Google Chrome on Mac prior to 148.0.7778.168 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8525

Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8524 — Out: of bounds write in WebAudio in Google Chrome prior to 148.0.7778.168 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8524

Out of bounds write in WebAudio in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 787TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8523 — Use: after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8523

Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8522 — Use: after free in Downloads in Google Chrome on Mac prior to 148.0.7778.168 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8522

Use after free in Downloads in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8520 — Race: in Payments in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8520

Race in Payments in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.3 (HIGH)

CWECWE 362VNDRaceTYPVulnerability
8.3
CVSS v3.1
92
Edit Score