2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9998 — Integer: overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9998

Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 472TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9997 — Use: after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9997

Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9995 — Use: after free in WebXR in Google Chrome prior to 148.0.7778.216 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9995

Use after free in WebXR in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9994 — Use: after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9994

Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9993 — Use: after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9993

Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9992 — Use: after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9992

Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9988 — Use: after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.216 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9988

Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9984 — Use: after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9984

Use after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9983 — Type: Confusion in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9983

Type Confusion in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 843VNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9982 — Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9982

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 20TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9978 — Use: after free in Glic in Google Chrome prior to 148.0.7778.216 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9978

Use after free in Glic in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9977 — Insufficient validation of untrusted input in WebShare in Google Chrome on Android prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9977

Insufficient validation of untrusted input in WebShare in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 20TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9976 — Inappropriate: implementation in USB in Google Chrome prior to 148.0.7778.216 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9976

Inappropriate implementation in USB in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDInappropriateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9975 — Out: of bounds read and write in ANGLE in Google Chrome prior to 148.0.7778.216

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9975

Out of bounds read and write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9974 — Out: of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9974

Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 787TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9973 — Out: of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9973

Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 787TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9972 — Uninitialized: Use in Gamepad in Google Chrome on Mac prior to 148.0.7778.216 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9972

Uninitialized Use in Gamepad in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 457VNDUninitializedTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9970 — Use: after free in WebGL in Google Chrome prior to 148.0.7778.216 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9970

Use after free in WebGL in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9969 — Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9969

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 20TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9968 — Integer: overflow in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9968

Integer overflow in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 472TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 23:16Z
CRIT

CVE-2026-9967 — Out: of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9967

Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 787TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9966 — Integer: overflow in XML in Google Chrome on Windows prior to 148.0.7778.216 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9966

Integer overflow in XML in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 472TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9965 — Out: of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9965

Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 787TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9964 — Use: after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9964

Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: High) CVSSv3.1 8.1 (HIGH)

CWECWE 416TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9962 — Use: after free in WebRTC in Google Chrome prior to 148.0.7778.216 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9962

Use after free in WebRTC in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score