2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17894 — Use: after free in Views in Google Chrome on Linux prior to 151.0.7922.72 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17894

Use after free in Views in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17886 — Use: after free in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17886

Use after free in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17884 — Object: lifecycle issue in WebRTC in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17884

Object lifecycle issue in WebRTC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416VNDObjectTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17881 — Integer: overflow in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17881

Integer overflow in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17877 — Inappropriate: implementation in Chromoting in Google Chrome on Linux prior to 151.0.7922.72 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17877

Inappropriate implementation in Chromoting in Google Chrome on Linux prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via malicious network traffic. (Chromium security severity: Medium) CVSSv3.1 8.4 (HIGH)

CWECWE 269VNDInappropriateTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17875 — Use: after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17875

Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17869 — Out: of bounds read in WebXR in Google Chrome prior to 151.0.7922.72 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17869

Out of bounds read in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.1 (HIGH) · EPSS 8th percentile

CWECWE 125TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17868 — USB: Insufficient policy enforcement in USB in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17868

Insufficient policy enforcement in USB in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDUsbTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17865 — Inappropriate: implementation in Crypto in Google Chrome on Mac prior to 151.0.7922.72 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17865

Inappropriate implementation in Crypto in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL) · EPSS 8th percentile

CWECWE 693VNDInappropriateTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17856 — Inappropriate: implementation in Network in Google Chrome on Mac prior to 151.0.7922.72 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17856

Inappropriate implementation in Network in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL) · EPSS 8th percentile

CWECWE 693VNDInappropriateTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17855 — Race: in DevTools in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17855

Race in DevTools in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL) · EPSS 4th percentile

CWECWE 362VNDRaceTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17848 — Integer: overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17848

Integer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL) · EPSS 6th percentile

CWECWE 20TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17847 — Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17847

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL) · EPSS 8th percentile

CWECWE 20TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17837 — Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17837

Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL) · EPSS 7th percentile

CWECWE 20TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17836 — Use: after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17836

Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17834 — Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17834

Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL) · EPSS 7th percentile

CWECWE 20TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17832 — Use: after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17832

Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL) · EPSS 7th percentile

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17807 — Use: after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17807

Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17804 — Use: after free in Media in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17804

Use after free in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL) · EPSS 11th percentile

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17803 — Insufficient validation of untrusted input in Save to Drive in Google Chrome prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17803

Insufficient validation of untrusted input in Save to Drive in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL) · EPSS 9th percentile

CWECWE 20TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17801 — Out: of bounds read and write in ANGLE in Google Chrome prior to 151.0.7922.72

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17801

Out of bounds read and write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL) · EPSS 11th percentile

CWECWE 125TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17786 — Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17786

Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 20TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17784 — Use: after free in Audio in Google Chrome on Mac prior to 151.0.7922.72 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17784

Use after free in Audio in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH) · EPSS 11th percentile

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17778 — Use: after free in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17778

Use after free in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17768 — Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 151.0.7922.72 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17768

Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL) · EPSS 11th percentile

CWECWE 20TYPVulnerability
9.6
CVSS v3.1
98
Edit Score