2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14122 — Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Windows prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14122

Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.1 (HIGH)

CWECWE 20TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14121 — Google Chrome: Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14121

Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Low) CVSSv3.1 8.1 (HIGH)

CWECWE 416VNDGoogleTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-14120 — Inappropriate: implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14120

Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 9.6 (CRITICAL)

CWECWE 693VNDInappropriateTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-14113 — Use: after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14113

Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14111 — Use: after free in WebProtect in Google Chrome prior to 150.0.7871.47 allowed an attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14111

Use after free in WebProtect in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Low) CVSSv3.1 8.1 (HIGH)

CWECWE 416TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-14109 — Mojo: Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.47 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14109

Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 9.6 (CRITICAL)

CWECWE 602VNDMojoTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14108 — Use: after free in PDFium in Google Chrome prior to 150.0.7871.47 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14108

Use after free in PDFium in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14107 — Use: after free in Scheduling in Google Chrome prior to 150.0.7871.47 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14107

Use after free in Scheduling in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-14106 — Insufficient validation of untrusted input in Text in Google Chrome on Android prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14106

Insufficient validation of untrusted input in Text in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 9.6 (CRITICAL)

CWECWE 20TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-14105 — Speech: Insufficient policy enforcement in Speech in Google Chrome prior to 150.0.7871.47 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14105

Insufficient policy enforcement in Speech in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 9.6 (CRITICAL)

CWECWE 346VNDSpeechTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14104 — Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14104

Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 20TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14102 — Use: after free in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14102

Use after free in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-14101 — Sandbox: Insufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 150.0.7871.47 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14101

Insufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 9.6 (CRITICAL)

CWECWE 693TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14099 — Use: after free in Chrome for iOS in Google Chrome on iOS prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14099

Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-14097 — Inappropriate: implementation in WebAppInstalls in Google Chrome on Mac prior to 150.0.7871.47 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14097

Inappropriate implementation in WebAppInstalls in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 9.6 (CRITICAL)

CWECWE 693VNDInappropriateTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-14095 — Browser: Insufficient policy enforcement in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14095

Insufficient policy enforcement in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 9.6 (CRITICAL)

CWECWE 20CWECWE 693VNDBrowserTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-14093 — Use: after free in Cast in Google Chrome prior to 150.0.7871.47 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14093

Use after free in Cast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14091 — Use: after free in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14091

Use after free in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-14090 — Insufficient validation of untrusted input in CameraCapture in Google Chrome on ChromeOS prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14090

Insufficient validation of untrusted input in CameraCapture in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 9.8 (CRITICAL)

CWECWE 125TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14087 — Heap: buffer overflow in WebNN in Google Chrome on Windows prior to 150.0.7871.47 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14087

Heap buffer overflow in WebNN in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 20CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14086 — HID: Insufficient policy enforcement in HID in Google Chrome prior to 150.0.7871.47 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14086

Insufficient policy enforcement in HID in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 602VNDHidTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14084 — Insufficient validation of untrusted input in Chromoting in Google Chrome prior to 150.0.7871.47 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14084

Insufficient validation of untrusted input in Chromoting in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 20TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14078 — Insufficient validation of untrusted input in WebRTC in Google Chrome prior to 150.0.7871.47 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14078

Insufficient validation of untrusted input in WebRTC in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 20TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14067 — Google Chrome: Use after free in Chrome for iOS in Google Chrome on iOS prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14067

Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 416VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-14056 — Google Chrome: Insufficient validation of untrusted input in Media in Google Chrome prior to 150.0.7871.47 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14056

Insufficient validation of untrusted input in Media in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Low) CVSSv3.1 9.6 (CRITICAL)

CWECWE 20VNDGoogleTYPVulnerability
9.6
CVSS v3.1
98
Edit Score