Subscribe, build a custom feed, or pitch a sponsorship at hello@acadenix.com
Latest intel// live feed
CVE-2026-9924 — Heap: buffer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed
Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)
CVE-2026-9923 — Use: after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote
Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)
CVE-2026-9918 — Inappropriate: implementation in Tint in Google Chrome prior to 148.0.7778.216 allowed a remote attacker
Inappropriate implementation in Tint in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)
CVE-2026-9916 — Out: of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a
Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)
CVE-2026-9915 — Heap: buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote
Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)
CVE-2026-9914 — Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)
CVE-2026-9910 — Out: of bounds memory access in ANGLE in Google Chrome prior to 148.0.7778.216 allowed
Out of bounds memory access in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)
CVE-2026-9906 — Out: of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a
Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)
CVE-2026-9905 — Use: after free in Accessibility in Google Chrome on Windows prior to 148.0.7778.216 allowed
Use after free in Accessibility in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)
CVE-2026-9904 — Use: after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote
Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)
CVE-2026-9902 — Use: after free in Accessibility in Google Chrome prior to 148.0.7778.216 allowed a remote
Use after free in Accessibility in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)
CVE-2026-9900 — Out: of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a
Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)
CVE-2026-9899 — Use: after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote
Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)
CVE-2026-9898 — Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to
Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)
CVE-2026-9897 — Use: after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote
Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)
CVE-2026-9896 — Out: of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a
Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)
CVE-2026-9895 — Out: of bounds read in GPU in Google Chrome prior to 148.0.7778.216 allowed a
Out of bounds read in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)
CVE-2026-9894 — Use: after free in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote
Use after free in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)
CVE-2026-9893 — Use: after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote
Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.3 (HIGH)
CVE-2026-9892 — Inappropriate: implementation in Skia in Google Chrome on Android prior to 148.0.7778.216 allowed a
Inappropriate implementation in Skia in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.3 (HIGH)
CVE-2026-9891 — Use: after free in Extensions in Google Chrome prior to 148.0.7778.216 allowed a remote
Use after free in Extensions in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: Critical) CVSSv3.1 9.0 (CRITICAL)
CVE-2026-9890 — Use: after free in XR in Google Chrome on Windows prior to 148.0.7778.216 allowed
Use after free in XR in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.3 (HIGH)
CVE-2026-9889 — Out: of bounds read and write in Dawn in Google Chrome on Android prior
Out of bounds read and write in Dawn in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.3 (HIGH)
CVE-2026-9888 — Use: after free in WebView in Google Chrome on Android prior to 148.0.7778.216 allowed
Use after free in WebView in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.3 (HIGH)
CVE-2026-9887 — Google Chrome: Use after free in Proxy in Google Chrome prior to 148.0.7778.216 allowed a remote
Use after free in Proxy in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted PAC script. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)