2026-07-30
2026-07-30 01:17Z
CRIT

CVE-2026-17987 — Insufficient validation of untrusted input in Notifications in Google Chrome prior to 151.0.7922.72 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17987

Insufficient validation of untrusted input in Notifications in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. (Chromium security severity: Low) CVSSv3.1 9.6 (CRITICAL)

CWECWE 20TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:17Z
HIGH

CVE-2026-17971 — Inappropriate: implementation in Frame in Google Chrome prior to 151.0.7922.72 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17971

Inappropriate implementation in Frame in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 125VNDInappropriateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:17Z
HIGH

CVE-2026-17969 — Inappropriate: implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17969

Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDInappropriateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:17Z
HIGH

CVE-2026-17967 — Use: after free in Chrome for iOS in Google Chrome on iOS prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17967

Use after free in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:17Z
HIGH

CVE-2026-17956 — Inappropriate: implementation in Scheduling in Google Chrome prior to 151.0.7922.72 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17956

Inappropriate implementation in Scheduling in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDInappropriateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17951 — Heap: buffer overflow in WebRTC in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17951

Heap buffer overflow in WebRTC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17950 — Inappropriate: implementation in Safebrowsing in Google Chrome on Mac prior to 151.0.7922.72 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17950

Inappropriate implementation in Safebrowsing in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code via a malicious file. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDInappropriateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17947 — Use: after free in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17947

Use after free in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17940 — Insufficient validation of untrusted input in Picture-in-Picture in Google Chrome on Android prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17940

Insufficient validation of untrusted input in Picture-in-Picture in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 9.6 (CRITICAL)

CWECWE 20TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17935 — Heap: buffer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17935

Heap buffer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17924 — Use: after free in DNS in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17924

Use after free in DNS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17922 — Inappropriate: implementation in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17922

Inappropriate implementation in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDInappropriateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17920 — Use: after free in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17920

Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17918 — Use: after free in Sync in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17918

Use after free in Sync in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17899 — DevTools: Insufficient policy enforcement in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17899

Insufficient policy enforcement in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 693VNDDevtoolsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17894 — Use: after free in Views in Google Chrome on Linux prior to 151.0.7922.72 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17894

Use after free in Views in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17886 — Use: after free in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17886

Use after free in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17884 — Object: lifecycle issue in WebRTC in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17884

Object lifecycle issue in WebRTC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416VNDObjectTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17881 — Integer: overflow in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17881

Integer overflow in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17877 — Inappropriate: implementation in Chromoting in Google Chrome on Linux prior to 151.0.7922.72 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17877

Inappropriate implementation in Chromoting in Google Chrome on Linux prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via malicious network traffic. (Chromium security severity: Medium) CVSSv3.1 8.4 (HIGH)

CWECWE 269VNDInappropriateTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17875 — Use: after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17875

Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17869 — Out: of bounds read in WebXR in Google Chrome prior to 151.0.7922.72 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17869

Out of bounds read in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.1 (HIGH) · EPSS 8th percentile

CWECWE 125TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17868 — USB: Insufficient policy enforcement in USB in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17868

Insufficient policy enforcement in USB in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDUsbTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17865 — Inappropriate: implementation in Crypto in Google Chrome on Mac prior to 151.0.7922.72 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17865

Inappropriate implementation in Crypto in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL) · EPSS 8th percentile

CWECWE 693VNDInappropriateTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17856 — Inappropriate: implementation in Network in Google Chrome on Mac prior to 151.0.7922.72 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17856

Inappropriate implementation in Network in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL) · EPSS 8th percentile

CWECWE 693VNDInappropriateTYPVulnerability
9.6
CVSS v3.1
98
Edit Score