2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17758 — Heap: buffer overflow in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17758

Heap buffer overflow in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 122VNDHeapTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17752 — Use: after free in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17752

Use after free in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17751 — Inappropriate: implementation in AdFilter in Google Chrome prior to 151.0.7922.72 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17751

Inappropriate implementation in AdFilter in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDInappropriateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17749 — Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17749

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL) · EPSS 3th percentile

CWECWE 20TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17738 — Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17738

Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL) · EPSS 11th percentile

CWECWE 20TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17735 — Insufficient validation of untrusted input in BFCache in Google Chrome prior to 151.0.7922.72 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17735

Insufficient validation of untrusted input in BFCache in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.7 (HIGH) · EPSS 11th percentile

CWECWE 20TYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17729 — Use: after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17729

Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH) · EPSS 12th percentile

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17727 — Out: of bounds write in WebGL in Google Chrome on Android prior to 151.0.7922.72

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17727

Out of bounds write in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 787TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17726 — Integer: overflow in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17726

Integer overflow in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 190TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17725 — Type: Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17725

Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 843VNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17723 — Use: after free in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17723

Use after free in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17722 — Object: lifecycle issue in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17722

Object lifecycle issue in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416VNDObjectTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17721 — Out: of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17721

Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 787TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17719 — Use: after free in Input in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17719

Use after free in Input in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17718 — Use: after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17718

Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17717 — Integer: overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17717

Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 190TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17716 — Use: after free in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17716

Use after free in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via malicious network traffic. (Chromium security severity: High) CVSSv3.1 8.4 (HIGH)

CWECWE 416TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17713 — Insufficient validation of untrusted input in Accessibility in Google Chrome on Android prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17713

Insufficient validation of untrusted input in Accessibility in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 20TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17712 — Race: in Skia in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17712

Race in Skia in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 362VNDRaceTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17711 — Race: in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17711

Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 362VNDRaceTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17710 — Inappropriate: implementation in MHTML in Google Chrome on Mac prior to 151.0.7922.72 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17710

Inappropriate implementation in MHTML in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 693VNDInappropriateTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17709 — Race: in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17709

Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 362VNDRaceTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17708 — Use: after free in Audio in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17708

Use after free in Audio in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17705 — Integer: overflow in libxml in Google Chrome prior to 151.0.7922.72 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17705

Integer overflow in libxml in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 190TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17704 — Use: after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17704

Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score