2026-07-01
2026-07-01 23:16Z
CRIT

CVE-2026-14420 — Out: of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14420

Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 9.6 (CRITICAL)

CWECWE 125CWECWE 787TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-01
2026-07-01 23:16Z
CRIT

CVE-2026-14419 — Use: after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14419

Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-01
2026-07-01 23:16Z
CRIT

CVE-2026-14417 — Use: after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14417

Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-01
2026-07-01 23:16Z
CRIT

CVE-2026-14416 — Out: of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14416

Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 9.6 (CRITICAL)

CWECWE 125TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-01
2026-07-01 23:16Z
HIGH

CVE-2026-14415 — Inappropriate: implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14415

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDInappropriateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-01
2026-07-01 23:16Z
HIGH

CVE-2026-14413 — Uninitialized: Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14413

Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 457VNDUninitializedTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-01
2026-07-01 23:16Z
HIGH

CVE-2026-14412 — Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14412

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 20TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-01
2026-07-01 23:16Z
CRIT

CVE-2026-14411 — Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14411

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 20TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-01
2026-07-01 23:16Z
HIGH

CVE-2026-14407 — Inappropriate: implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14407

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 94CWECWE 119VNDInappropriateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-01
2026-07-01 23:16Z
CRIT

CVE-2026-14405 — Uninitialized: Use in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14405

Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 9.6 (CRITICAL)

CWECWE 457VNDUninitializedTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-01
2026-07-01 23:16Z
HIGH

CVE-2026-14403 — Use: after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14403

Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-01
2026-07-01 23:16Z
HIGH

CVE-2026-14401 — Insufficient validation of untrusted input in ANGLE in Google Chrome on Android prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14401

Insufficient validation of untrusted input in ANGLE in Google Chrome on Android prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 20TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-01
2026-07-01 23:16Z
HIGH

CVE-2026-14400 — Out: of bounds write in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14400

Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 787TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-01
2026-07-01 23:16Z
CRIT

CVE-2026-14398 — Use: after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14398

Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-01
2026-07-01 23:16Z
CRIT

CVE-2026-14397 — Out: of bounds write in ANGLE in Google Chrome on Mac prior to 150.0.7871.46

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14397

Out of bounds write in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 787TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-01
2026-07-01 23:16Z
HIGH

CVE-2026-14395 — Out: of bounds write in V8 in Google Chrome prior to 150.0.7871.46 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14395

Out of bounds write in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 787TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-01
2026-07-01 23:16Z
HIGH

CVE-2026-14394 — Use: after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14394

Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-01
2026-07-01 23:16Z
HIGH

CVE-2026-14393 — Use: after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14393

Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-01
2026-07-01 23:16Z
CRIT

CVE-2026-14392 — Out: of bounds write in Tint in Google Chrome prior to 150.0.7871.46 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14392

Out of bounds write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 787TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-01
2026-07-01 23:16Z
CRIT

CVE-2026-14390 — Use: after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14390

Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-01
2026-07-01 23:16Z
HIGH

CVE-2026-14389 — Integer: overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14389

Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.3 (HIGH)

CWECWE 472TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-01
2026-07-01 23:16Z
CRIT

CVE-2026-14387 — Integer: overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14387

Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 472TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-01
2026-07-01 23:16Z
HIGH

CVE-2026-14385 — Heap: buffer overflow in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14385

Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-01
2026-07-01 23:16Z
HIGH

CVE-2026-14383 — Inappropriate: implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14383

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 94CWECWE 119VNDInappropriateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-01
2026-07-01 23:16Z
CRIT

CVE-2026-14382 — Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14382

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 20TYPVulnerability
9.6
CVSS v3.1
98
Edit Score