2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9939 — Heap: buffer overflow in WebCodecs in Google Chrome prior to 148.0.7778.216 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9939

Heap buffer overflow in WebCodecs in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9938 — Inappropriate: implementation in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9938

Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDInappropriateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9937 — Use: after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9937

Use after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9936 — Use: after free in GFX in Google Chrome on Mac prior to 148.0.7778.216 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9936

Use after free in GFX in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9932 — Use: after free in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9932

Use after free in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9931 — Use: after free in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9931

Use after free in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9928 — Out: of bounds read in ANGLE in Google Chrome on Windows prior to 148.0.7778.216

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9928

Out of bounds read in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 125TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9927 — Use: after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9927

Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9926 — Heap: buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9926

Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9925 — Use: after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9925

Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9924 — Heap: buffer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9924

Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9923 — Use: after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9923

Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 23:16Z
CRIT

CVE-2026-9918 — Inappropriate: implementation in Tint in Google Chrome prior to 148.0.7778.216 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9918

Inappropriate implementation in Tint in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 269VNDInappropriateTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9916 — Out: of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9916

Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 787TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9915 — Heap: buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9915

Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9914 — Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9914

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 20TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9910 — Out: of bounds memory access in ANGLE in Google Chrome prior to 148.0.7778.216 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9910

Out of bounds memory access in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 125CWECWE 787TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9906 — Out: of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9906

Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 787TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9905 — Use: after free in Accessibility in Google Chrome on Windows prior to 148.0.7778.216 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9905

Use after free in Accessibility in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9904 — Use: after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9904

Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9902 — Use: after free in Accessibility in Google Chrome prior to 148.0.7778.216 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9902

Use after free in Accessibility in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9900 — Out: of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9900

Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 787TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9899 — Use: after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9899

Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9898 — Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9898

Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 20TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-28
2026-05-28 23:16Z
HIGH

CVE-2026-9897 — Use: after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9897

Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score