2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-13965 — Use: after free in Oilpan in Google Chrome prior to 150.0.7871.47 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13965

Use after free in Oilpan in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-13951 — USB: Insufficient policy enforcement in USB in Google Chrome prior to 150.0.7871.47 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13951

Insufficient policy enforcement in USB in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.3 (HIGH)

CWECWE 693VNDUsbTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-13938 — Google Chrome: Integer overflow in Fonts in Google Chrome prior to 150.0.7871.47 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13938

Integer overflow in Fonts in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH) · EPSS 11th percentile

CWECWE 472VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-13934 — Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13934

Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 20TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-13928 — Insufficient validation of untrusted input in Enterprise in Google Chrome prior to 150.0.7871.47 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13928

Insufficient validation of untrusted input in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 20TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-13920 — Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13920

Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 20TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-13918 — Use: after free in Chrome for iOS in Google Chrome on iOS prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13918

Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-13915 — Use: after free in Chrome for iOS in Google Chrome on iOS prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13915

Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-13909 — DevTools: Insufficient policy enforcement in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13909

Insufficient policy enforcement in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 693VNDDevtoolsTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-13903 — Bluetooth: Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13903

Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 602VNDBluetoothTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-13901 — Serial: Insufficient policy enforcement in Serial in Google Chrome prior to 150.0.7871.47 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13901

Insufficient policy enforcement in Serial in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 20CWECWE 602VNDSerialTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-13899 — Use: after free in HTML in Google Chrome prior to 150.0.7871.47 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13899

Use after free in HTML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-13898 — Use: after free in Cast Receiver in Google Chrome prior to 150.0.7871.47 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13898

Use after free in Cast Receiver in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-13897 — Chromecast: Insufficient policy enforcement in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13897

Insufficient policy enforcement in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 284VNDChromecastTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-13888 — Google Chrome: Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13888

Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-13885 — Google Chrome: Use after free in Skia in Google Chrome on Android prior to 150.0.7871.47 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13885

Use after free in Skia in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-13884 — Google Chrome: Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a local attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13884

Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a local attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-13883 — Type: Confusion in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13883

Type Confusion in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 843VNDTypeTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-13882 — Race: in USB in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13882

Race in USB in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 362VNDRaceTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-13880 — Use: after free in USB in Google Chrome on Mac prior to 150.0.7871.47 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13880

Use after free in USB in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-13878 — Use: after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13878

Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-13872 — Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13872

Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: Medium) CVSSv3.1 9.1 (CRITICAL)

CWECWE 20TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-13870 — Google Chrome: Use after free in WebView in Google Chrome on Android prior to 150.0.7871.47 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13870

Use after free in WebView in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-13869 — Use: after free in Device in Google Chrome on Windows prior to 150.0.7871.47 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13869

Use after free in Device in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-13864 — WebHID: Insufficient policy enforcement in WebHID in Google Chrome prior to 150.0.7871.47 allowed an attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13864

Insufficient policy enforcement in WebHID in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Medium) CVSSv3.1 8.1 (HIGH)

CWECWE 284VNDWebhidTYPVulnerability
8.1
CVSS v3.1
91
Edit Score