2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14087 — Heap: buffer overflow in WebNN in Google Chrome on Windows prior to 150.0.7871.47 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14087

Heap buffer overflow in WebNN in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 20CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14086 — HID: Insufficient policy enforcement in HID in Google Chrome prior to 150.0.7871.47 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14086

Insufficient policy enforcement in HID in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 602VNDHidTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14084 — Insufficient validation of untrusted input in Chromoting in Google Chrome prior to 150.0.7871.47 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14084

Insufficient validation of untrusted input in Chromoting in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 20TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14078 — Insufficient validation of untrusted input in WebRTC in Google Chrome prior to 150.0.7871.47 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14078

Insufficient validation of untrusted input in WebRTC in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 20TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14067 — Google Chrome: Use after free in Chrome for iOS in Google Chrome on iOS prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14067

Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 416VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-14056 — Google Chrome: Insufficient validation of untrusted input in Media in Google Chrome prior to 150.0.7871.47 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14056

Insufficient validation of untrusted input in Media in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Low) CVSSv3.1 9.6 (CRITICAL)

CWECWE 20VNDGoogleTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-14055 — Google Chrome: Insufficient validation of untrusted input in Device Trust in Google Chrome on Windows prior

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14055

Insufficient validation of untrusted input in Device Trust in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 9.6 (CRITICAL)

CWECWE 20VNDGoogleTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-14044 — Use: after free in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14044

Use after free in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-14043 — Use: after free in GetUserMedia in Google Chrome prior to 150.0.7871.47 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14043

Use after free in GetUserMedia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14041 — Serial: Insufficient policy enforcement in Serial in Google Chrome prior to 150.0.7871.47 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14041

Insufficient policy enforcement in Serial in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 602VNDSerialTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14040 — Use: after free in BrowserTag in Google Chrome prior to 150.0.7871.47 allowed an attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14040

Use after free in BrowserTag in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-14038 — Google Chrome: Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14038

Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 9.3 (CRITICAL)

CWECWE 20VNDGoogleTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-14037 — Google Chrome: Insufficient policy enforcement in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14037

Insufficient policy enforcement in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 9.6 (CRITICAL)

CWECWE 693VNDGoogleVNDGpuTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14036 — Bluetooth: Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14036

Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 602VNDBluetoothTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14032 — Use: after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14032

Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Low) CVSSv3.1 8.1 (HIGH)

CWECWE 416TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14027 — Use: after free in SignIn in Google Chrome prior to 150.0.7871.47 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14027

Use after free in SignIn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14025 — Use: after free in Views in Google Chrome on Mac prior to 150.0.7871.47 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14025

Use after free in Views in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14024 — Use: after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14024

Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-14017 — Inappropriate: implementation in Navigation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14017

Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 693VNDInappropriateTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14011 — Out: of bounds read in SurfaceCapture in Google Chrome prior to 150.0.7871.47 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14011

Out of bounds read in SurfaceCapture in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.1 (HIGH)

CWECWE 125TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14009 — Inappropriate: implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14009

Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 20VNDInappropriateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14006 — Use: after free in Navigation in Google Chrome prior to 150.0.7871.47 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14006

Use after free in Navigation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14005 — Use: after free in Omnibox in Google Chrome on Android prior to 150.0.7871.47 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14005

Use after free in Omnibox in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-13974 — Integer: overflow in Safe Browsing in Google Chrome on Mac prior to 150.0.7871.47 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13974

Integer overflow in Safe Browsing in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Medium) CVSSv3.1 8.1 (HIGH) · EPSS 10th percentile

CWECWE 190CWECWE 472TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-13967 — Heap: buffer overflow in V8 in Google Chrome prior to 150.0.7871.47 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13967

Heap buffer overflow in V8 in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 843VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score