2w ago
2026-06-04 23:16Z
HIGH

CVE-2026-10911 — Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10911

Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 20TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2w ago
2026-06-04 23:16Z
HIGH

CVE-2026-10910 — Type: Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10910

Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 843VNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-06-04 23:16Z
HIGH

CVE-2026-10909 — Use: after free in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10909

Use after free in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2w ago
2026-06-04 23:16Z
HIGH

CVE-2026-10908 — Use: after free in FullScreen in Google Chrome on Windows prior to 149.0.7827.53 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10908

Use after free in FullScreen in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2w ago
2026-06-04 23:16Z
HIGH

CVE-2026-10907 — Out: of bounds write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10907

Out of bounds write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 787TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-06-04 23:16Z
HIGH

CVE-2026-10905 — Use: after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10905

Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2w ago
2026-06-04 23:16Z
HIGH

CVE-2026-10904 — Inappropriate: implementation in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10904

Inappropriate implementation in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 94CWECWE 20CWECWE 119VNDInappropriateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2w ago
2026-06-04 23:16Z
HIGH

CVE-2026-10903 — Use: after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10903

Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-06-04 23:16Z
HIGH

CVE-2026-10902 — Use: after free in Ozone in Google Chrome prior to 149.0.7827.53 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10902

Use after free in Ozone in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-06-04 23:16Z
HIGH

CVE-2026-10898 — Stack: buffer overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10898

Stack buffer overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.3 (HIGH)

CWECWE 121VNDStackTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2w ago
2026-06-04 23:16Z
HIGH

CVE-2026-10897 — Inappropriate: implementation in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10897

Inappropriate implementation in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)

CWECWE 787VNDInappropriateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-06-04 23:16Z
HIGH

CVE-2026-10896 — Use: after free in Chrome for iOS in Google Chrome on iOS prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10896

Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-06-04 23:16Z
HIGH

CVE-2026-10895 — Use: after free in Ozone in Google Chrome prior to 149.0.7827.53 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10895

Use after free in Ozone in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-06-04 23:16Z
HIGH

CVE-2026-10894 — Use: after free in Printing in Google Chrome on Linux prior to 149.0.7827.53 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10894

Use after free in Printing in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2w ago
2026-06-04 23:16Z
HIGH

CVE-2026-10893 — Use: after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10893

Use after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-06-04 23:16Z
CRIT

CVE-2026-10892 — Out: of bounds write in GPU in Google Chrome on Android prior to 149.0.7827.53

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10892

Out of bounds write in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 9.6 (CRITICAL)

CWECWE 787TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2w ago
2026-06-04 23:16Z
HIGH

CVE-2026-10891 — Use: after free in GFX in Google Chrome on Linux prior to 149.0.7827.53 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10891

Use after free in GFX in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-06-04 23:16Z
HIGH

CVE-2026-10890 — Use: after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10890

Use after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-06-04 23:16Z
HIGH

CVE-2026-10889 — Out: of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10889

Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.3 (HIGH)

CWECWE 125TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2w ago
2026-06-04 23:16Z
HIGH

CVE-2026-10888 — Use: after free in Cast Streaming in Google Chrome prior to 149.0.7827.53 allowed an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10888

Use after free in Cast Streaming in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-06-04 23:16Z
HIGH

CVE-2026-10887 — Use: after free in Chromoting in Google Chrome on Mac prior to 149.0.7827.53 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10887

Use after free in Chromoting in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical) CVSSv3.1 8.1 (HIGH)

CWECWE 416TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-06-04 23:16Z
CRIT

CVE-2026-10886 — Use: after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10886

Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2w ago
2026-06-04 23:16Z
HIGH

CVE-2026-10885 — Use: after free in Chrome for iOS in Google Chrome on iOS prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10885

Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-06-04 23:16Z
HIGH

CVE-2026-10884 — Use: after free in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10884

Use after free in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2w ago
2026-06-04 23:16Z
HIGH

CVE-2026-10883 — Type: Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10883

Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)

CWECWE 787VNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score