SB2026082632 - Multiple vulnerabilities in Google Chrome
Published: August 26, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 327 vulnerabilities.
1) Use-after-free (CVE-ID: CVE-2026-79282)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error in ANGLE component. A remote attacker can trick the victim into visiting a specially crafted website and execute arbitrary code on the system.
2) Use-after-free (CVE-ID: CVE-2026-79290)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Aura component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
3) Use-after-free (CVE-ID: CVE-2026-79054)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Chromecast component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
4) Input validation error (CVE-ID: CVE-2026-79121)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input in Chromecast in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and execute arbitrary code on the system.
5) Use-after-free (CVE-ID: CVE-2026-79224)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Chromecast component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
6) Use-after-free (CVE-ID: CVE-2026-79052)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Aura component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
7) Use-after-free (CVE-ID: CVE-2026-79150)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Views component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
8) Use of Uninitialized Variable (CVE-ID: CVE-2026-78935)
CWE-ID: CWE-457 - Use of Uninitialized Variable
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to boundary error in Mobile in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the system.
9) Use-after-free (CVE-ID: CVE-2026-79012)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Safebrowsing component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
10) Use-after-free (CVE-ID: CVE-2026-79200)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Aura component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
11) Out-of-bounds read (CVE-ID: CVE-2026-78989)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition in the ANGLE component. A remote attacker can create a specially crafted website, trick the victim into opening it, trigger an out-of-bounds read error and read contents of memory on the system.
12) Buffer overflow (CVE-ID: CVE-2026-79069)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a boundary error in Tint in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger a buffer overflow and execute arbitrary code on the system.
13) Type Confusion (CVE-ID: CVE-2026-79175)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a type confusion error within the Accessibility component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger a type confusion error and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
14) Improper Authorization (CVE-ID: CVE-2026-79218)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to incorrect authorization in Sandbox in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.
15) Use-after-free (CVE-ID: CVE-2026-79195)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Script component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
16) Use-after-free (CVE-ID: CVE-2026-78939)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Chromecast component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
17) Use-after-free (CVE-ID: CVE-2026-79194)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Chromoting component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
18) Use-after-free (CVE-ID: CVE-2026-79247)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Chromoting component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
19) Use-after-free (CVE-ID: CVE-2026-79219)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Bluetooth component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
20) Use-after-free (CVE-ID: CVE-2026-79047)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Views component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
21) Integer overflow (CVE-ID: CVE-2026-79292)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in Chromecast component in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page, trigger an integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
22) Use of uninitialized resource (CVE-ID: CVE-2026-78986)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to usage of uninitialized resources in GPU in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger uninitialized usage of resources and compromise the affected system.
23) Use-after-free (CVE-ID: CVE-2026-79039)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Mobile component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
24) Race condition (CVE-ID: CVE-2026-78934)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a race condition in ReadAloud in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and execute arbitrary code on the target system.
25) Spoofing attack (CVE-ID: CVE-2026-79011)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to spoof the user interface.
The vulnerability exists due to ui misrepresentation in browser when rendering web content. A remote attacker can persuade a victim to open crafted content to spoof the user interface.
User interaction is required.
26) Improper Authorization (CVE-ID: CVE-2026-78911)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to incorrect authorization in USB in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.
27) Use-after-free (CVE-ID: CVE-2026-79257)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Views component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
28) Use-after-free (CVE-ID: CVE-2026-79202)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Chromecast component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
29) Improper access control (CVE-ID: CVE-2026-79212)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in Passwords when handling password management operations. A remote attacker can trigger the vulnerable functionality to disclose sensitive information.
User interaction is required.
30) Use-after-free (CVE-ID: CVE-2026-79183)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Accessibility component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
31) Race condition (CVE-ID: CVE-2026-79155)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a race condition in FileSystem in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and execute arbitrary code on the target system.
32) Improper Authorization (CVE-ID: CVE-2026-79093)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to incorrect authorization in Paint in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.
33) Out-of-bounds write (CVE-ID: CVE-2026-79019)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted HTML content in ANGLE. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.
34) Use-after-free (CVE-ID: CVE-2026-79187)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the WebRTC component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
35) Input validation error (CVE-ID: CVE-2026-79288)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input in Autofill in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and execute arbitrary code on the system.
36) Buffer overflow (CVE-ID: CVE-2026-79130)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a boundary error in ANGLE in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger a buffer overflow and execute arbitrary code on the system.
37) Use of uninitialized resource (CVE-ID: CVE-2026-78965)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to usage of uninitialized resources in ANGLE in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger uninitialized usage of resources and compromise the affected system.
38) Race condition (CVE-ID: CVE-2026-79117)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a race condition in WebAppInstalls in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and execute arbitrary code on the target system.
39) Improper Authorization (CVE-ID: CVE-2026-79082)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to incorrect authorization in Transactions Platform in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.
40) Input validation error (CVE-ID: CVE-2026-79111)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input in Dawn in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and execute arbitrary code on the system.
41) Improper Validation of Unsafe Equivalence in Input (CVE-ID: CVE-2026-79072)
CWE-ID: CWE-1289 - Improper Validation of Unsafe Equivalence in Input
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper state validation in Performance when handling browser operations. A remote attacker can trigger the vulnerable code path to cause a denial of service.
User interaction is required.
42) Buffer overflow (CVE-ID: CVE-2026-79142)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a boundary error in ANGLE in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger a buffer overflow and execute arbitrary code on the system.
43) Buffer overflow (CVE-ID: CVE-2026-78948)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a boundary error in WebGL in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger a buffer overflow and execute arbitrary code on the system.
44) Information disclosure (CVE-ID: CVE-2026-78908)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in Canvas when rendering content. A remote attacker can cause the browser to process crafted web content to disclose sensitive information.
User interaction is required to visit crafted web content.
45) Information disclosure (CVE-ID: CVE-2026-78895)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an information leak in Paint when rendering content. A remote attacker can cause the browser to process crafted content to disclose sensitive information.
User interaction is required to visit or open crafted content.
46) Out-of-bounds write (CVE-ID: CVE-2026-79043)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted HTML content in ANGLE. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.
47) Use-after-free (CVE-ID: CVE-2026-79235)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the WebGL component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
48) Use-after-free (CVE-ID: CVE-2026-79232)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Aura component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
49) Use of uninitialized resource (CVE-ID: CVE-2026-79118)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to usage of uninitialized resources in ANGLE in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger uninitialized usage of resources and compromise the affected system.
50) Improper Authorization (CVE-ID: CVE-2026-79174)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to incorrect authorization in Extensions in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.
51) Input validation error (CVE-ID: CVE-2026-78900)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input in Media in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and execute arbitrary code on the system.
52) Out-of-bounds write (CVE-ID: CVE-2026-79188)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted HTML content in ANGLE. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.
53) Out-of-bounds write (CVE-ID: CVE-2026-79189)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted HTML content in ANGLE. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.
54) Out-of-bounds write (CVE-ID: CVE-2026-79048)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted HTML content in ANGLE. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.
55) Out-of-bounds write (CVE-ID: CVE-2026-79240)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted HTML content in ANGLE. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.
56) Race condition (CVE-ID: CVE-2026-79014)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a race condition in Autofill in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and execute arbitrary code on the target system.
57) Use-after-free (CVE-ID: CVE-2026-79198)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Platform component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
58) Out-of-bounds write (CVE-ID: CVE-2026-79131)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted HTML content in ANGLE. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.
59) Use-after-free (CVE-ID: CVE-2026-79149)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the ANGLE component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
60) Use-after-free (CVE-ID: CVE-2026-79275)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the ANGLE component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
61) Out-of-bounds write (CVE-ID: CVE-2026-79138)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted HTML content in ANGLE. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.
62) Use-after-free (CVE-ID: CVE-2026-79026)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Extensions component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
63) Use-after-free (CVE-ID: CVE-2026-79027)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the WebRTC component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
64) Type Confusion (CVE-ID: CVE-2026-78904)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a type confusion error within the ANGLE component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger a type confusion error and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
65) Use-after-free (CVE-ID: CVE-2026-78899)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the V8 component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
66) Improper Authorization (CVE-ID: CVE-2026-78954)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to incorrect authorization in Extensions in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.
67) Information disclosure (CVE-ID: CVE-2026-79274)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in GPU when rendering content. A remote attacker can trigger processing of crafted web content to disclose sensitive information.
User interaction is required to visit or open crafted content.
68) Type Confusion (CVE-ID: CVE-2026-78938)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a type confusion error within the V8 component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger a type confusion error and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
69) Out-of-bounds write (CVE-ID: CVE-2026-78952)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted HTML content in Crashpad. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.
70) Type Confusion (CVE-ID: CVE-2026-79236)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a type confusion error within the V8 component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger a type confusion error and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
71) Use-after-free (CVE-ID: CVE-2026-79078)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the FedCM component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
72) Type Confusion (CVE-ID: CVE-2026-79209)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a type confusion error within the Animation component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a type confusion error and gain access to sensitive information.
73) Improper access control (CVE-ID: CVE-2026-79030)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in Autofill when rendering browser content. A remote attacker can induce a discrepancy in Autofill behavior to disclose sensitive information.
User interaction is required.
74) Stack-based buffer overflow (CVE-ID: CVE-2026-79216)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to stack-based buffer overflow in Blink when rendering web content. A remote attacker can persuade a victim to open a specially crafted page to execute arbitrary code.
User interaction is required.
75) Use of uninitialized resource (CVE-ID: CVE-2026-79007)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uninitialized resource usage in GPU when rendering content. A remote attacker can trigger processing of crafted web content to cause a denial of service.
User interaction is required to visit or open crafted content.
76) Information disclosure (CVE-ID: CVE-2026-78893)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in QUIC in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
77) Improper Authorization (CVE-ID: CVE-2026-79222)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to improper access control in CustomTabs when handling requests. A remote attacker can send a specially crafted request to bypass authorization checks.
78) Race condition (CVE-ID: CVE-2026-79071)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a race condition in GPU when rendering content. A remote attacker can trigger concurrent operations to cause a denial of service.
User interaction is required.
79) Input validation error (CVE-ID: CVE-2026-79076)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in Sync when handling crafted input. A remote attacker can trigger the vulnerable functionality to cause a denial of service.
User interaction is required.
80) Improper access control (CVE-ID: CVE-2026-79088)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to improper access control in FileSystem when handling crafted browser interactions. A remote attacker can trigger the vulnerable functionality to bypass authorization checks.
User interaction is required.
81) Improper Authorization (CVE-ID: CVE-2026-79104)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to improper access control in Sensor when handling web content. A remote attacker can cause the browser to access Sensor functionality in an unauthorized manner to bypass authorization checks.
User interaction is required to visit or render crafted web content.
82) Improper Authorization (CVE-ID: CVE-2026-79044)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to improper access control in WebAppInstalls when handling web application install operations. A remote attacker can trigger crafted install-related actions to bypass authorization checks.
User interaction is required.
83) Use of uninitialized resource (CVE-ID: CVE-2026-78958)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use of uninitialized resource in Skia when rendering content. A remote attacker can trick the victim into opening crafted content to cause a denial of service.
User interaction is required.
84) Improper access control (CVE-ID: CVE-2026-78961)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization restrictions.
The vulnerability exists due to improper access control in Core when handling browser operations. A remote attacker can perform unauthorized actions to bypass authorization restrictions.
User interaction is required.
85) Improper access control (CVE-ID: CVE-2026-79262)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization controls.
The vulnerability exists due to improper access control in Network when handling requests. A remote attacker can send a specially crafted request to bypass authorization controls.
86) Input validation error (CVE-ID: CVE-2026-79106)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in Input when processing user-supplied input. A remote attacker can craft malicious content to cause a denial of service.
User interaction is required to process the crafted content.
87) Spoofing attack (CVE-ID: CVE-2026-79176)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to spoof the user interface.
The vulnerability exists due to ui misrepresentation in Extensions when rendering extension content. A remote attacker can craft a malicious extension interface to spoof the user interface.
User interaction is required.
88) Externally Controlled Reference to a Resource in Another Sphere (CVE-ID: CVE-2026-78966)
CWE-ID: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to an externally controlled reference in QUIC when processing network input. A remote attacker can cause the browser to process crafted QUIC data to execute arbitrary code.
User interaction is required.
89) Improper access control (CVE-ID: CVE-2026-79186)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization controls.
The vulnerability exists due to improper access control in Network when handling network operations. A remote attacker can trigger crafted interaction with the browser to bypass authorization controls.
User interaction is required.
90) Race condition (CVE-ID: CVE-2026-79267)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a race condition in Workers when processing web content. A remote attacker can trick the victim into accessing crafted content to execute arbitrary code.
User interaction is required.
91) Observable discrepancy (CVE-ID: CVE-2026-79016)
CWE-ID: CWE-203 - Observable discrepancy
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an observable discrepancy in SVG when rendering content. A remote attacker can trick the victim into opening crafted content to disclose sensitive information.
User interaction is required.
92) Use-after-free (CVE-ID: CVE-2026-79010)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in Network when processing crafted content. A remote attacker can cause the application to access a resource after it has been released to execute arbitrary code.
User interaction is required to trigger the issue.
93) Incorrect authorization (CVE-ID: CVE-2026-79286)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization restrictions.
The vulnerability exists due to improper access control in CustomTabs when handling user-initiated navigation or content access. A remote attacker can trigger crafted interaction flows to bypass authorization restrictions.
User interaction is required.
94) Use-after-free (CVE-ID: CVE-2026-78945)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Views in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
95) Improper privilege management (CVE-ID: CVE-2026-78999)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper privilege management in Navigation when handling web content. A remote attacker can cause the browser to process specially crafted content to escalate privileges.
User interaction is required to trigger the issue.
96) Information disclosure (CVE-ID: CVE-2026-78941)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in Core in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
97) Input validation error (CVE-ID: CVE-2026-79032)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in Network when handling requests. A remote attacker can send specially crafted input to cause a denial of service.
User interaction is required to trigger the issue.
98) Input validation error (CVE-ID: CVE-2026-79109)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in Printing when processing print-related content. A remote attacker can trick the victim into processing specially crafted content to cause a denial of service.
User interaction is required.
99) Externally Controlled Reference to a Resource in Another Sphere (CVE-ID: CVE-2026-79256)
CWE-ID: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to an externally controlled reference in WebView when rendering web content. A remote attacker can persuade a victim to open crafted content to execute arbitrary code.
User interaction is required.
100) Improper access control (CVE-ID: CVE-2026-79237)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization.
The vulnerability exists due to improper access control in Navigation when handling navigation requests. A remote attacker can trigger crafted navigation actions to bypass authorization.
User interaction is required.
101) Improper access control (CVE-ID: CVE-2026-78898)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization restrictions.
The vulnerability exists due to improper access control in Downloads when handling download operations. A remote attacker can trigger crafted browser interactions to bypass authorization restrictions.
User interaction is required.
102) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-78985)
CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper reference resolution in FileSystem when handling filesystem operations. A remote attacker can convince a victim to interact with crafted content to disclose sensitive information.
User interaction is required.
103) Observable discrepancy (CVE-ID: CVE-2026-79028)
CWE-ID: CWE-203 - Observable discrepancy
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to observable discrepancy in network when handling network operations. A remote attacker can trigger observable differences to disclose sensitive information.
User interaction is required.
104) Use-after-free (CVE-ID: CVE-2026-79210)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Audio in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
105) Race condition (CVE-ID: CVE-2026-79046)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a race condition in Permissions when handling browser permission operations. A remote attacker can trigger a race condition to cause a denial of service.
User interaction is required.
106) Use-after-free (CVE-ID: CVE-2026-79129)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Sessions in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
107) Use-after-free (CVE-ID: CVE-2026-78937)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Search in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
108) Information disclosure (CVE-ID: CVE-2026-78987)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in Canvas in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
109) Use-after-free (CVE-ID: CVE-2026-78990)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Compositing in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
110) Use-after-free (CVE-ID: CVE-2026-78909)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Views in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
111) Information disclosure (CVE-ID: CVE-2026-79271)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in DOM in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
112) Information disclosure (CVE-ID: CVE-2026-79144)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in Skia in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
113) Input validation error (CVE-ID: CVE-2026-79065)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in Network when handling network data. A remote attacker can send specially crafted input to cause a denial of service.
User interaction is required.
114) Input validation error (CVE-ID: CVE-2026-79192)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in Variations when processing user-supplied input. A remote attacker can trigger the vulnerable code path to cause a denial of service.
User interaction is required.
115) Use-after-free (CVE-ID: CVE-2026-79140)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Views in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
116) Use-after-free (CVE-ID: CVE-2026-79128)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Views in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
117) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-78942)
CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to incorrect reference resolution in Loader when processing web content. A remote attacker can cause the victim to open a specially crafted page to execute arbitrary code.
User interaction is required to visit a crafted web page.
118) Improper access control (CVE-ID: CVE-2026-79116)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to improper access control in Viz when handling browser operations. A remote attacker can trigger the vulnerable code path to bypass authorization checks.
User interaction is required.
119) Protection mechanism failure (CVE-ID: CVE-2026-79006)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass security restrictions.
The vulnerability exists due to protection mechanism failure in HttpsUpgrades when handling web content. A remote attacker can cause the browser to process crafted content to bypass security restrictions.
User interaction is required.
120) Information disclosure (CVE-ID: CVE-2026-79095)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in Payments in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
121) Inadequate Encryption Strength (CVE-ID: CVE-2026-79084)
CWE-ID: CWE-326 - Inadequate Encryption Strength
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to inadequate encryption strength in Notifications when processing notification data. A remote attacker can leverage weak encryption protections to disclose sensitive information.
User interaction is required.
122) Race condition (CVE-ID: CVE-2026-78991)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a race condition in WebProtect when rendering content. A remote attacker can trigger a race condition to cause a denial of service.
User interaction is required.
123) Improper Authorization (CVE-ID: CVE-2026-79248)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization restrictions.
The vulnerability exists due to improper access control in Input when handling input processing. A remote attacker can trigger the vulnerable behavior to bypass authorization restrictions.
User interaction is required.
124) Heap-based buffer overflow (CVE-ID: CVE-2026-78891)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in WebRTC when processing crafted content. A remote attacker can trick the victim into opening crafted content to execute arbitrary code.
User interaction is required.
125) Improper access control (CVE-ID: CVE-2026-79031)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in Preload when handling web content. A remote attacker can cause the browser to expose improperly protected resources to disclose sensitive information.
User interaction is required to trigger the issue.
126) Improper access control (CVE-ID: CVE-2026-79110)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to improper access control in Preload when handling browser functionality. A remote attacker can trigger the vulnerable code path to bypass authorization checks.
User interaction is required.
127) Improper access control (CVE-ID: CVE-2026-79136)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to improper access control in ServiceWorker when handling web content. A remote attacker can cause the browser to process crafted content to bypass authorization checks.
User interaction is required to visit or render crafted content.
128) Improper access control (CVE-ID: CVE-2026-78907)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization restrictions.
The vulnerability exists due to improper access control in WebProtect when handling web content. A remote attacker can cause the browser to process crafted content to bypass authorization restrictions.
User interaction is required.
129) Input validation error (CVE-ID: CVE-2026-79087)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to inject unintended content.
The vulnerability exists due to improper input validation in Chrome Tabs when handling crafted tab-related input. A remote attacker can supply crafted input to inject unintended content.
User interaction is required.
130) Heap-based buffer overflow (CVE-ID: CVE-2026-79231)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Media when processing media content. A remote attacker can cause the victim to process specially crafted media content to execute arbitrary code.
User interaction is required to process the crafted content.
131) Use of uninitialized resource (CVE-ID: CVE-2026-78969)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use of uninitialized resource in Video when processing crafted content. A remote attacker can persuade a victim to open specially crafted content to cause a denial of service.
User interaction is required.
132) Improper access control (CVE-ID: CVE-2026-79137)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization restrictions.
The vulnerability exists due to improper access control in Extensions when handling extension-related functionality. A remote attacker can trigger the flawed authorization logic to bypass authorization restrictions.
User interaction is required.
133) Race condition (CVE-ID: CVE-2026-79057)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a race condition in Start when handling browser operations. A remote attacker can trigger concurrent actions to cause a denial of service.
User interaction is required.
134) Race condition (CVE-ID: CVE-2026-78894)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a race condition in Payments when processing user-supplied content. A remote attacker can trigger a race condition to execute arbitrary code.
User interaction is required to reach the vulnerable browser functionality.
135) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-79264)
CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper reference resolution in Preload when rendering content. A remote attacker can trick the victim into opening crafted content to execute arbitrary code.
User interaction is required.
136) Heap-based buffer overflow (CVE-ID: CVE-2026-78910)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to heap-based buffer overflow in V8 when processing crafted web content. A remote attacker can cause the victim to open a specially crafted webpage to execute arbitrary code.
User interaction is required to visit a crafted webpage.
137) Input validation error (CVE-ID: CVE-2026-79066)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in Navigation when handling navigation requests. A remote attacker can induce the victim to open crafted content to cause a denial of service.
User interaction is required.
138) Input validation error (CVE-ID: CVE-2026-79255)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in WebRTC when processing crafted content. A remote attacker can trick the victim into rendering crafted content to cause a denial of service.
User interaction is required.
139) Improper access control (CVE-ID: CVE-2026-79086)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to improper access control in CustomTabs when handling requests. A remote attacker can send a specially crafted request to bypass authorization checks.
140) Improper access control (CVE-ID: CVE-2026-79038)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to improper access control in WebProtect when handling web content. A remote attacker can cause the browser to process crafted content to bypass authorization checks.
User interaction is required to load the crafted content.
141) Improper Initialization (CVE-ID: CVE-2026-78940)
CWE-ID: CWE-665 - Improper Initialization
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper initialization in Network when handling network input. A remote attacker can trigger the flaw to cause a denial of service.
User interaction is required.
142) Improper access control (CVE-ID: CVE-2026-79107)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization restrictions.
The vulnerability exists due to improper access control in TabGroups when handling browser operations. A remote attacker can perform unauthorized actions to bypass authorization restrictions.
User interaction is required.
143) Use of uninitialized resource (CVE-ID: CVE-2026-79120)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use of uninitialized resource in ANGLE when rendering content. A remote attacker can trigger the vulnerable code path to cause a denial of service.
User interaction is required.
144) Use of uninitialized resource (CVE-ID: CVE-2026-79270)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uninitialized resource usage in ANGLE when rendering web content. A remote attacker can persuade a victim to open specially crafted content to cause a denial of service.
User interaction is required to trigger the issue.
145) Incorrect authorization (CVE-ID: CVE-2026-79067)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to improper access control in Network when handling requests. A remote attacker can send a specially crafted request to bypass authorization checks.
146) Improper access control (CVE-ID: CVE-2026-79213)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to improper access control in WebAppInstalls when handling web application installation operations. A remote attacker can perform crafted installation-related actions to bypass authorization checks.
User interaction is required.
147) Input validation error (CVE-ID: CVE-2026-78943)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in Editing when processing crafted web content. A remote attacker can trigger the flaw to cause a denial of service.
User interaction is required to trigger the issue.
148) Input validation error (CVE-ID: CVE-2026-79259)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unspecified impacts.
The vulnerability exists due to improper input validation in Safebrowsing when processing user-supplied content. A remote attacker can cause Chrome to process crafted content to perform unspecified impacts.
User interaction is required.
149) Missing Authorization (CVE-ID: CVE-2026-79208)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to missing authorization in HTTP2 when handling requests. A remote attacker can send a specially crafted request to bypass authorization checks.
150) Input validation error (CVE-ID: CVE-2026-79251)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in Network when handling network input. A remote attacker can send specially crafted network data to cause a denial of service.
User interaction is required.
151) Improper privilege management (CVE-ID: CVE-2026-79226)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper privilege management in Regional Capabilities when handling browser functionality. A remote attacker can perform crafted actions to escalate privileges.
User interaction is required.
152) Missing Authorization (CVE-ID: CVE-2026-79042)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to improper access control in Payments when handling payment-related operations. A remote attacker can perform unauthorized actions to bypass authorization checks.
153) Information disclosure (CVE-ID: CVE-2026-79122)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in SignIn in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
154) Incorrect authorization (CVE-ID: CVE-2026-79199)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to incorrect authorization in Network when handling requests. A remote attacker can send a specially crafted request to bypass authorization checks.
User interaction is required.
155) Input validation error (CVE-ID: CVE-2026-79013)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in Sync when handling user-supplied sync data. A remote attacker can send specially crafted data to cause a denial of service.
User interaction is required.
156) Information disclosure (CVE-ID: CVE-2026-79074)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in Network in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
157) Integer overflow (CVE-ID: CVE-2026-79215)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to a integer overflow in WebGL in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.
158) Improper access control (CVE-ID: CVE-2026-79049)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in Passwords when resolving references. A remote attacker can cause the application to process crafted content to disclose sensitive information.
User interaction is required.
159) Input validation error (CVE-ID: CVE-2026-79132)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in Input when processing user-supplied input. A remote attacker can supply specially crafted input to cause a denial of service.
User interaction is required.
160) Improper access control (CVE-ID: CVE-2026-79201)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass security restrictions.
The vulnerability exists due to improper access control in Workers when handling worker-related content. A remote attacker can trick the victim into interacting with crafted web content to bypass security restrictions.
User interaction is required.
161) Improper Authorization (CVE-ID: CVE-2026-79051)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization restrictions.
The vulnerability exists due to improper access control in Loader when handling browser operations. A remote attacker can trigger the vulnerable behavior to bypass authorization restrictions.
User interaction is required.
162) Improper access control (CVE-ID: CVE-2026-79053)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to improper access control in Lighthouse when handling browser functionality. A remote attacker can perform unauthorized actions to bypass authorization checks.
User interaction is required.
163) Use of uninitialized resource (CVE-ID: CVE-2026-79285)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uninitialized resource usage in ANGLE when rendering content. A remote attacker can trick the victim into opening crafted content to cause a denial of service.
User interaction is required.
164) Race condition (CVE-ID: CVE-2026-78906)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a race condition in ANGLE when rendering content. A remote attacker can trigger a race condition to cause a denial of service.
User interaction is required to render crafted content.
165) Spoofing attack (CVE-ID: CVE-2026-79250)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to spoof the user interface.
The vulnerability exists due to ui misrepresentation in Navigation when rendering web content. A remote attacker can craft misleading content to spoof the user interface.
User interaction is required.
166) Out-of-bounds read (CVE-ID: CVE-2026-79020)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the Skia component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.
167) Improper access control (CVE-ID: CVE-2026-79217)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization restrictions.
The vulnerability exists due to improper access control in Mobile when handling crafted web content. A remote attacker can cause the victim to access crafted content to bypass authorization restrictions.
User interaction is required.
168) Spoofing attack (CVE-ID: CVE-2026-79204)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to spoof the user interface.
The vulnerability exists due to ui misrepresentation in input handling when rendering crafted content. A remote attacker can cause the browser to display misleading interface elements to spoof the user interface.
User interaction is required.
169) Spoofing attack (CVE-ID: CVE-2026-78912)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to spoof the user interface.
The vulnerability exists due to ui misrepresentation in browser when rendering content. A remote attacker can craft malicious content to spoof the user interface.
User interaction is required.
170) Improper access control (CVE-ID: CVE-2026-78955)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in PerformanceAPIs when rendering web content. A remote attacker can cause the browser to expose an observable discrepancy to disclose sensitive information.
User interaction is required to visit a crafted website.
171) Improper access control (CVE-ID: CVE-2026-79143)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to improper access control in FileSystem when handling browser operations. A remote attacker can trigger unauthorized FileSystem actions to bypass authorization checks.
User interaction is required.
172) Out-of-bounds read (CVE-ID: CVE-2026-79241)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the GPU component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.
173) Improper access control (CVE-ID: CVE-2026-78967)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to improper access control in BFCache when handling cached page state. A remote attacker can cause the browser to use a back-forward cache state in a way that bypasses authorization checks to bypass authorization checks.
User interaction is required.
174) Input validation error (CVE-ID: CVE-2026-79214)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in Preload when processing web content. A remote attacker can persuade a victim to open crafted content to cause a denial of service.
User interaction is required.
175) Improper access control (CVE-ID: CVE-2026-79228)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization restrictions.
The vulnerability exists due to improper access control in SiteIsolation when rendering content. A remote attacker can cause the browser to process crafted web content to bypass authorization restrictions.
User interaction is required to visit or render crafted content.
176) Improper Authorization (CVE-ID: CVE-2026-78953)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization restrictions.
The vulnerability exists due to improper access control in SiteIsolation when rendering web content. A remote attacker can cause the browser to process crafted content to bypass authorization restrictions.
User interaction is required to visit a crafted webpage.
177) Use of uninitialized resource (CVE-ID: CVE-2026-79229)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uninitialized resource usage in ANGLE when rendering content. A remote attacker can trick the victim into rendering specially crafted content to cause a denial of service.
User interaction is required.
178) Improper access control (CVE-ID: CVE-2026-79002)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization controls.
The vulnerability exists due to improper access control in SiteIsolation when rendering web content. A remote attacker can cause the browser to process crafted content to bypass authorization controls.
User interaction is required to visit or load crafted content.
179) Input validation error (CVE-ID: CVE-2026-79272)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in FindInPage when processing user-supplied input. A remote attacker can trigger the vulnerable functionality to cause a denial of service.
User interaction is required.
180) Out-of-bounds write (CVE-ID: CVE-2026-79127)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted HTML content in ANGLE. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.
181) Input validation error (CVE-ID: CVE-2026-79151)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in Safebrowsing when processing untrusted content. A remote attacker can persuade the victim to access specially crafted web content to cause a denial of service.
User interaction is required.
182) Observable discrepancy (CVE-ID: CVE-2026-78936)
CWE-ID: CWE-203 - Observable discrepancy
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an observable discrepancy in CustomTabs when rendering content. A remote attacker can trick the victim into interacting with crafted web content to disclose sensitive information.
User interaction is required.
183) Type Confusion (CVE-ID: CVE-2026-78905)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a type confusion error within the ANGLE component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a type confusion error and gain access to sensitive information.
184) Improper access control (CVE-ID: CVE-2026-79050)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization.
The vulnerability exists due to improper access control in Network when handling network requests. A remote attacker can trigger the vulnerable network logic to bypass authorization.
User interaction is required.
185) Input validation error (CVE-ID: CVE-2026-79008)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in GPU when processing crafted content. A remote attacker can trick the victim into opening crafted content to cause a denial of service.
User interaction is required.
186) Improper access control (CVE-ID: CVE-2026-78975)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to improper access control in DOM when processing web content. A remote attacker can trick the victim into visiting a crafted webpage to bypass authorization checks.
User interaction is required to visit a crafted webpage.
187) Observable discrepancy (CVE-ID: CVE-2026-79287)
CWE-ID: CWE-203 - Observable discrepancy
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an observable discrepancy in forms when rendering content. A remote attacker can trick the victim into interacting with crafted content to disclose sensitive information.
User interaction is required.
188) Race condition (CVE-ID: CVE-2026-79094)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a race condition in Workers when handling web content. A remote attacker can trigger concurrent worker operations to cause a denial of service.
User interaction is required to visit or render crafted web content.
189) Spoofing attack (CVE-ID: CVE-2026-79173)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to misrepresent the user interface.
The vulnerability exists due to ui misrepresentation in WebAppInstalls when rendering web application installation content. A remote attacker can present crafted content to misrepresent the user interface.
User interaction is required.
190) Input validation error (CVE-ID: CVE-2026-78976)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in StorageAccessAPI when handling crafted web content. A remote attacker can trick the victim into visiting a specially crafted page to cause a denial of service.
User interaction is required to visit a crafted page.
191) Improper privilege management (CVE-ID: CVE-2026-79276)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper privilege management in FileSystem when handling crafted web content. A remote attacker can induce the victim to access crafted content to escalate privileges.
User interaction is required.
192) Improper Authorization (CVE-ID: CVE-2026-79191)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization restrictions.
The vulnerability exists due to improper access control in SiteIsolation when rendering content. A remote attacker can trigger the browser to process crafted web content to bypass authorization restrictions.
User interaction is required to visit crafted web content.
193) Incorrect authorization (CVE-ID: CVE-2026-79099)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to improper access control in Network when handling requests. A remote attacker can send crafted input to bypass authorization checks.
User interaction is required.
194) Information disclosure (CVE-ID: CVE-2026-79024)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in ServiceWorker in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
195) Information disclosure (CVE-ID: CVE-2026-79193)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in Canvas in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
196) Observable discrepancy (CVE-ID: CVE-2026-79242)
CWE-ID: CWE-203 - Observable discrepancy
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper rendering in HTML when rendering content. A remote attacker can cause the browser to process crafted HTML to disclose sensitive information.
User interaction is required to open or render crafted content.
197) Spoofing attack (CVE-ID: CVE-2026-79180)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to spoof the user interface.
The vulnerability exists due to ui misrepresentation in CustomTabs when rendering web content. A remote attacker can cause crafted content to be displayed in a misleading way to spoof the user interface.
User interaction is required.
198) Information disclosure (CVE-ID: CVE-2026-79293)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in Animation in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
199) Improper access control (CVE-ID: CVE-2026-79023)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization.
The vulnerability exists due to improper access control in Editing when handling user-initiated editing operations. A remote attacker can trigger crafted interaction with editing functionality to bypass authorization.
User interaction is required.
200) Information disclosure (CVE-ID: CVE-2026-79146)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in CustomTabs in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
201) Improper access control (CVE-ID: CVE-2026-79238)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization controls.
The vulnerability exists due to improper access control in ServiceWorker when handling web content. A remote attacker can trigger crafted browser interactions to bypass authorization controls.
User interaction is required.
202) Observable discrepancy (CVE-ID: CVE-2026-78949)
CWE-ID: CWE-203 - Observable discrepancy
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an observable discrepancy in CustomTabs when rendering content. A remote attacker can trick the victim into rendering crafted content to disclose sensitive information.
User interaction is required.
203) Information disclosure (CVE-ID: CVE-2026-79291)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in CSS in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
204) Spoofing attack (CVE-ID: CVE-2026-79283)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to spoof the user interface.
The vulnerability exists due to ui misrepresentation in Geometry when rendering content. A remote attacker can craft malicious content to spoof the user interface.
User interaction is required to trigger the issue.
205) Improper access control (CVE-ID: CVE-2026-78892)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to improper access control in Chromoting when handling user interaction with the browser. A remote attacker can trigger the vulnerable functionality to bypass authorization checks.
User interaction is required.
206) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-79070)
CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper reference resolution in Cache when processing web content. A remote attacker can cause the browser to handle crafted content to disclose sensitive information.
User interaction is required to visit or render crafted content.
207) Improper access control (CVE-ID: CVE-2026-79205)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to improper access control in Network when handling requests. A remote attacker can send a crafted request to bypass authorization checks.
User interaction is required.
208) Incomplete cleanup (CVE-ID: CVE-2026-78903)
CWE-ID: CWE-459 - Incomplete cleanup
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation protections.
The vulnerability exists due to incomplete cleanup in SiteIsolation when rendering content. A remote attacker can trigger the vulnerable behavior to bypass site isolation protections.
User interaction is required.
209) Improper Handling of Case Sensitivity (CVE-ID: CVE-2026-78959)
CWE-ID: CWE-178 - Improper Handling of Case Sensitivity
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper handling of case sensitivity in FileSystem when handling file system operations. A remote attacker can cause the browser to process case-sensitive file system paths in an unexpected manner to disclose sensitive information.
User interaction is required for exploitation.
210) Cross-site scripting (CVE-ID: CVE-2026-79234)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to inject unintended content.
The vulnerability exists due to improper neutralization of input during web page generation in the CSS handling component when rendering crafted web content. A remote attacker can cause the browser to process crafted CSS content to inject unintended content.
User interaction is required to load or open crafted web content.
211) Use-after-free (CVE-ID: CVE-2026-78983)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Views in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
212) Protection mechanism failure (CVE-ID: CVE-2026-79083)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass security restrictions.
The vulnerability exists due to improper enforcement of behavioral workflow in Media when processing media content. A remote attacker can cause the victim to process crafted media content to bypass security restrictions.
User interaction is required.
213) Use-after-free (CVE-ID: CVE-2026-78944)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within DevTools in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
214) Improper access control (CVE-ID: CVE-2026-79178)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to improper access control in Web Authentication (Passkeys & Security Keys) when handling web authentication requests. A remote attacker can perform crafted authentication interactions to bypass authorization checks.
User interaction is required.
215) Information disclosure (CVE-ID: CVE-2026-79059)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in BFCache in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
216) Use-after-free (CVE-ID: CVE-2026-79245)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within UI in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
217) Out-of-bounds read (CVE-ID: CVE-2026-78978)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the ANGLE component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.
218) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-79103)
CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to incorrect reference resolution in Speech when rendering content. A remote attacker can trick the victim into opening crafted content to execute arbitrary code.
User interaction is required.
219) Improper Authorization (CVE-ID: CVE-2026-79154)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to improper access control in DevTools when handling remote content with user interaction. A remote attacker can convince a victim to interact with crafted web content to bypass authorization checks.
User interaction is required.
220) Input validation error (CVE-ID: CVE-2026-79230)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in ANGLE when rendering content. A remote attacker can trick the victim into rendering crafted content to cause a denial of service.
User interaction is required.
221) Exposure of Resource to Wrong Sphere (CVE-ID: CVE-2026-79068)
CWE-ID: CWE-668 - Exposure of resource to wrong sphere
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper resource exposure in StreamsAPI when handling web content. A remote attacker can cause the browser to expose resources to disclose sensitive information.
User interaction is required to visit or load crafted web content.
222) Use of uninitialized resource (CVE-ID: CVE-2026-79269)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use of uninitialized resource in ANGLE when rendering content. A remote attacker can trick the victim into rendering crafted content to cause a denial of service.
User interaction is required.
223) Improper Authorization (CVE-ID: CVE-2026-79085)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to improper access control in Network when handling requests. A remote attacker can send a crafted request to bypass authorization checks.
224) Improper access control (CVE-ID: CVE-2026-79134)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain unauthorized access to media devices.
The vulnerability exists due to improper access control in GetUserMedia when handling media access requests. A remote attacker can trigger crafted web content to gain unauthorized access to media devices.
User interaction is required to visit or interact with crafted content.
225) Use-after-free (CVE-ID: CVE-2026-79064)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Network in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
226) Improper access control (CVE-ID: CVE-2026-79003)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain unauthorized access to device functionality.
The vulnerability exists due to improper access control in Device when handling crafted interaction with the browser. A remote attacker can trigger unauthorized operations to gain unauthorized access to device functionality.
User interaction is required.
227) Information disclosure (CVE-ID: CVE-2026-79220)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in Network in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
228) Use-after-free (CVE-ID: CVE-2026-78951)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within ServiceWorker in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
229) Code Injection (CVE-ID: CVE-2026-79249)
CWE-ID: CWE-94 - Improper Control of Generation of Code ('Code Injection')
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to code injection in Bisection when processing crafted web content. A remote attacker can cause the victim to open crafted content to execute arbitrary code.
User interaction is required.
230) Use-after-free (CVE-ID: CVE-2026-79091)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Bluetooth in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
231) Improper Resource Shutdown or Release (CVE-ID: CVE-2026-79265)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in GetUserMedia when rendering content. A remote attacker can entice a user to interact with crafted web content to cause a denial of service.
User interaction is required.
232) Use-after-free (CVE-ID: CVE-2026-78913)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Chromoting in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
233) Improper Authorization (CVE-ID: CVE-2026-79258)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization restrictions.
The vulnerability exists due to improper access control in WebXR when handling web content. A remote attacker can craft malicious content to bypass authorization restrictions.
User interaction is required to visit a crafted page.
234) Improper access control (CVE-ID: CVE-2026-79211)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization restrictions.
The vulnerability exists due to improper access control in USB when handling requests. A remote attacker can send a specially crafted request to bypass authorization restrictions.
User interaction is required.
235) Information disclosure (CVE-ID: CVE-2026-79252)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in ServiceWorker in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
236) Use of uninitialized resource (CVE-ID: CVE-2026-78962)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use of uninitialized resource in WebXR when rendering content. A remote attacker can trick the victim into visiting a crafted page to cause a denial of service.
User interaction is required.
237) Race condition (CVE-ID: CVE-2026-78901)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a race condition in V8 when processing web content. A remote attacker can trick the victim into visiting a specially crafted website to execute arbitrary code.
User interaction is required.
238) Use-after-free (CVE-ID: CVE-2026-79097)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within V8 in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
239) Type Confusion (CVE-ID: CVE-2026-79227)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a type confusion error within the DevTools component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a type confusion error and gain access to sensitive information.
240) Input validation error (CVE-ID: CVE-2026-79203)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper input validation in DevTools when processing user-supplied input. A remote attacker can trick the victim into interacting with crafted content to execute arbitrary code.
User interaction is required.
241) Insufficient Control Flow Management (CVE-ID: CVE-2026-79033)
CWE-ID: CWE-691 - Insufficient Control Flow Management
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass intended control flow restrictions.
The vulnerability exists due to improper control flow management in DevTools when handling browser content. A remote attacker can cause the victim to interact with crafted content to bypass intended control flow restrictions.
User interaction is required.
242) Input validation error (CVE-ID: CVE-2026-79139)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in Media when processing crafted media content. A remote attacker can trick the victim into processing crafted media content to cause a denial of service.
User interaction is required to process the crafted media content.
243) Use of uninitialized resource (CVE-ID: CVE-2026-79221)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use of uninitialized resource in Dawn when rendering web content. A remote attacker can trigger the browser to process crafted content to cause a denial of service.
User interaction is required to open or render crafted content.
244) Information disclosure (CVE-ID: CVE-2026-79034)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in CORS in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
245) Information disclosure (CVE-ID: CVE-2026-79075)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in Geolocation in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
246) Information disclosure (CVE-ID: CVE-2026-78960)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in Extensions in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
247) Use of uninitialized resource (CVE-ID: CVE-2026-78984)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uninitialized resource usage in GPU when rendering content. A remote attacker can trigger the vulnerable code path to cause a denial of service.
User interaction is required.
248) Input validation error (CVE-ID: CVE-2026-78963)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in Media when processing crafted media content. A remote attacker can trick the victim into processing crafted media content to cause a denial of service.
User interaction is required.
249) Out-of-bounds read (CVE-ID: CVE-2026-79004)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the Media component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.
250) Input validation error (CVE-ID: CVE-2026-79182)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in Media when rendering content. A remote attacker can trick the victim into opening crafted content to cause a denial of service.
User interaction is required.
251) Information disclosure (CVE-ID: CVE-2026-79185)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in DOM in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
252) Improper Validation of Syntactic Correctness of Input (CVE-ID: CVE-2026-79073)
CWE-ID: CWE-1286 - Improper Validation of Syntactic Correctness of Input
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper state validation in Parser when parsing input. A remote attacker can supply specially crafted input to cause a denial of service.
User interaction is required to process crafted content.
253) Use-after-free (CVE-ID: CVE-2026-79266)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within DevTools in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
254) Input validation error (CVE-ID: CVE-2026-79025)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper input validation in Workers when processing user-supplied content. A remote attacker can trigger the vulnerable worker handling to execute arbitrary code.
User interaction is required.
255) Improper access control (CVE-ID: CVE-2026-79141)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization restrictions.
The vulnerability exists due to improper access control in Browser when handling browser operations. A remote attacker can perform unauthorized actions to bypass authorization restrictions.
User interaction is required.
256) Spoofing attack (CVE-ID: CVE-2026-78974)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to spoof the user interface.
The vulnerability exists due to ui misrepresentation in Linux Toolkit Theming when rendering browser interface elements. A remote attacker can cause crafted content to be displayed to spoof the user interface.
User interaction is required.
257) Improper access control (CVE-ID: CVE-2026-79055)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in Sharing when handling sharing operations. A remote attacker can induce the victim to interact with crafted content to disclose sensitive information.
User interaction is required.
258) Race condition (CVE-ID: CVE-2026-79263)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a race condition in Extensions when processing extension-related operations. A remote attacker can trigger concurrent operations to cause a denial of service.
User interaction is required.
259) Improper access control (CVE-ID: CVE-2026-79124)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in Intents when handling web content. A remote attacker can persuade a victim to open a crafted page to disclose sensitive information.
User interaction is required.
260) Missing Authorization (CVE-ID: CVE-2026-79184)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to improper access control in Preload when handling browser operations. A remote attacker can leverage the missing authorization to bypass authorization checks.
User interaction is required.
261) Use-after-free (CVE-ID: CVE-2026-79289)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in Workers when processing web content. A remote attacker can cause the victim to open a specially crafted page to execute arbitrary code.
User interaction is required to visit a crafted web page.
262) Improper access control (CVE-ID: CVE-2026-79001)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the Bluetooth component when handling web content. A remote attacker can cause the browser to access the vulnerable functionality to disclose sensitive information.
User interaction is required.
263) Improper access control (CVE-ID: CVE-2026-79077)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization controls.
The vulnerability exists due to improper access control in WebProtect when handling web content. A remote attacker can cause the browser to process crafted content to bypass authorization controls.
User interaction is required to trigger the issue.
264) Integer overflow (CVE-ID: CVE-2026-78950)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to crash the browser.
The vulnerability exists due to a integer overflow in WebRTC in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.
265) Race condition (CVE-ID: CVE-2026-79196)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a race condition in Editing when rendering content. A remote attacker can trigger a race condition to cause a denial of service.
User interaction is required to trigger the issue.
266) Input validation error (CVE-ID: CVE-2026-79000)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper input validation in DeviceBoundSessionCredentials when processing crafted web content. A remote attacker can trick the victim into interacting with crafted content to execute arbitrary code.
User interaction is required.
267) Race condition (CVE-ID: CVE-2026-78979)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a race condition in Core when rendering content. A remote attacker can trigger concurrent operations to cause a denial of service.
User interaction is required.
268) Observable discrepancy (CVE-ID: CVE-2026-79181)
CWE-ID: CWE-203 - Observable discrepancy
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a security impact via an observable discrepancy.
The vulnerability exists due to improper handling of an observable discrepancy in Glic when rendering content. A remote attacker can induce the browser to process crafted content to cause a security impact via an observable discrepancy.
User interaction is required.
269) Improper Authorization (CVE-ID: CVE-2026-79190)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization restrictions.
The vulnerability exists due to improper access control in Extensions when handling extension authorization. A remote attacker can manipulate extension-related interactions to bypass authorization restrictions.
User interaction is required for exploitation.
270) Out-of-bounds read (CVE-ID: CVE-2026-79206)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to a boundary condition within the FileSystem component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and crash the browser.
271) Improper Authorization (CVE-ID: CVE-2026-78897)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization controls.
The vulnerability exists due to improper access control in BrowserTag when handling browser content. A remote attacker can trigger the vulnerable functionality to bypass authorization controls.
User interaction is required.
272) Use-after-free (CVE-ID: CVE-2026-79119)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to use-after-free error in PDF in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.
273) Race condition (CVE-ID: CVE-2026-79089)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a race condition in Transactions Platform when handling browser operations. A remote attacker can trigger concurrent operations to cause a denial of service.
User interaction is required.
274) Information disclosure (CVE-ID: CVE-2026-79147)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in Skia when rendering content. A remote attacker can trick the victim into opening crafted content to disclose sensitive information.
User interaction is required.
275) Spoofing attack (CVE-ID: CVE-2026-79098)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to spoof the user interface.
The vulnerability exists due to ui misrepresentation in PermissionElement when rendering permission-related content. A remote attacker can cause specially crafted content to be displayed to spoof the user interface.
User interaction is required.
276) Spoofing attack (CVE-ID: CVE-2026-79022)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to spoof the user interface.
The vulnerability exists due to improper neutralization of user interface elements in Transactions Platform when rendering content. A remote attacker can craft misleading content to spoof the user interface.
User interaction is required to trigger the issue.
277) Spoofing attack (CVE-ID: CVE-2026-79233)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to misrepresent the user interface.
The vulnerability exists due to improper neutralization of ui elements in CustomTabs when rendering web content. A remote attacker can craft content that triggers misleading interface presentation to misrepresent the user interface.
User interaction is required.
278) Improper access control (CVE-ID: CVE-2026-79261)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization controls.
The vulnerability exists due to improper access control in Controls when handling browser functionality. A remote attacker can perform unauthorized actions to bypass authorization controls.
User interaction is required.
279) Use of uninitialized resource (CVE-ID: CVE-2026-78977)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use of uninitialized resource in GPU when rendering crafted web content. A remote attacker can trigger the browser to process crafted content to cause a denial of service.
User interaction is required to open or render crafted web content.
280) Use of uninitialized resource (CVE-ID: CVE-2026-79040)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use of uninitialized resource in GPU when rendering content. A remote attacker can trigger the browser to process crafted content to cause a denial of service.
User interaction is required to load crafted content.
281) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-79273)
CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper reference resolution in WebView when rendering content. A remote attacker can trick the victim into rendering crafted content to cause a denial of service.
User interaction is required.
282) Input validation error (CVE-ID: CVE-2026-79243)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in ReadingList when processing user-supplied input. A remote attacker can trick the victim into interacting with crafted content to cause a denial of service.
User interaction is required.
283) Input validation error (CVE-ID: CVE-2026-79123)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in NTP Footer when rendering content. A remote attacker can trick the victim into rendering crafted content to cause a denial of service.
User interaction is required.
284) Improper access control (CVE-ID: CVE-2026-79005)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to improper access control in StorageAccessAPI when handling storage access requests. A remote attacker can craft malicious web content to bypass authorization checks.
User interaction is required to visit or load crafted web content.
285) Improper privilege management (CVE-ID: CVE-2026-79090)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper privilege management in Actor when handling browser content. A remote attacker can trigger the vulnerable component to escalate privileges.
User interaction is required.
286) Improper access control (CVE-ID: CVE-2026-78946)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization restrictions.
The vulnerability exists due to improper access control in Select when processing content in the browser. A remote attacker can cause the browser to access the vulnerable component to bypass authorization restrictions.
User interaction is required to trigger the issue.
287) Incorrect authorization (CVE-ID: CVE-2026-78968)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization.
The vulnerability exists due to improper access control in Core when handling browser operations. A remote attacker can trigger the vulnerable functionality to bypass authorization.
User interaction is required.
288) Incorrect authorization (CVE-ID: CVE-2026-79041)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization.
The vulnerability exists due to improper access control in browser when handling browser operations. A remote attacker can perform unauthorized actions to bypass authorization.
User interaction is required.
289) Spoofing attack (CVE-ID: CVE-2026-79284)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to spoof the user interface.
The vulnerability exists due to ui misrepresentation in Core when rendering content. A remote attacker can cause the browser to display misleading interface elements to spoof the user interface.
User interaction is required.
290) Improper access control (CVE-ID: CVE-2026-78896)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in StorageAccessAPI when handling web content. A remote attacker can craft malicious content to disclose sensitive information.
User interaction is required to visit or load crafted web content.
291) Missing Authorization (CVE-ID: CVE-2026-79058)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in Passwords when handling password-related operations. A remote attacker can trigger unauthorized access to password data to disclose sensitive information.
User interaction is required.
292) Spoofing attack (CVE-ID: CVE-2026-79009)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to spoof the user interface.
The vulnerability exists due to ui misrepresentation in the UI when rendering browser interface content. A remote attacker can cause misleading interface elements to be displayed to spoof the user interface.
User interaction is required.
293) Improper Authorization (CVE-ID: CVE-2026-79060)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to improper access control in StorageAccessAPI when handling web content. A remote attacker can cause the browser to process crafted content to bypass authorization checks.
User interaction is required.
294) Improper access control (CVE-ID: CVE-2026-79177)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization.
The vulnerability exists due to improper access control in Media when handling browser content. A remote attacker can cause the browser to access media-related functionality in an unauthorized manner to bypass authorization.
User interaction is required.
295) Type Confusion (CVE-ID: CVE-2026-78956)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a type confusion error within the V8 component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a type confusion error and crash the browser.
296) Out-of-bounds read (CVE-ID: CVE-2026-79239)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to a boundary condition within the Tint component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and crash the browser.
297) Input validation error (CVE-ID: CVE-2026-79015)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in ServiceWorker when processing web content. A remote attacker can trick the victim into opening crafted content to cause a denial of service.
User interaction is required to trigger the issue.
298) Spoofing attack (CVE-ID: CVE-2026-79108)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to spoof the user interface.
The vulnerability exists due to ui misrepresentation in Web Authentication (Passkeys & Security Keys) when rendering authentication-related browser interface elements. A remote attacker can present misleading authentication interface content to spoof the user interface.
User interaction is required.
299) Use-after-free (CVE-ID: CVE-2026-79056)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to use-after-free error in ServiceWorker in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.
300) Information disclosure (CVE-ID: CVE-2026-79018)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in FoldableAPIs when handling web content. A remote attacker can persuade a victim to visit a specially crafted webpage to disclose sensitive information.
User interaction is required to visit a crafted webpage.
301) Input validation error (CVE-ID: CVE-2026-78980)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in ReaderMode when rendering content. A remote attacker can trick the victim into opening crafted content to cause a denial of service.
User interaction is required to trigger the issue.
302) Incomplete cleanup (CVE-ID: CVE-2026-78947)
CWE-ID: CWE-459 - Incomplete cleanup
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to incomplete cleanup in Chromium when processing crafted web content. A remote attacker can trigger the vulnerable condition to cause a denial of service.
User interaction is required to trigger the issue.
303) Use-after-free (CVE-ID: CVE-2026-79244)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to use-after-free error in Animation in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.
304) Out-of-bounds read (CVE-ID: CVE-2026-79112)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to a boundary condition within the Skia component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and crash the browser.
305) Information disclosure (CVE-ID: CVE-2026-79246)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in DataTransfer when handling web content. A remote attacker can craft malicious content to disclose sensitive information.
User interaction is required to visit or render crafted content.
306) Integer overflow (CVE-ID: CVE-2026-79223)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to crash the browser.
The vulnerability exists due to a integer overflow in Chromium in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.
307) Type Confusion (CVE-ID: CVE-2026-79045)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a type confusion error within the V8 component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a type confusion error and crash the browser.
308) Use-after-free (CVE-ID: CVE-2026-79197)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to use-after-free error in V8 in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.
309) Off-by-one (CVE-ID: CVE-2026-79148)
CWE-ID: CWE-193 - Off-by-one Error
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an off-by-one error in DevTools when processing user-supplied input. A remote attacker can trigger the flaw to cause a denial of service.
User interaction is required to reach the vulnerable browser component.
310) Information disclosure (CVE-ID: CVE-2026-79125)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in XR when rendering content. A remote attacker can entice a victim to access crafted web content to disclose sensitive information.
User interaction is required.
311) Improper access control (CVE-ID: CVE-2026-79207)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in Passwords when handling browser password data. A remote attacker can trigger access to password-related data to disclose sensitive information.
User interaction is required.
312) Race condition (CVE-ID: CVE-2026-79017)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a race condition in Extensions when processing extension-related operations. A remote attacker can trigger a race condition to cause a denial of service.
User interaction is required.
313) Input validation error (CVE-ID: CVE-2026-79105)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in Mobile when processing user-supplied input. A remote attacker can induce the victim to interact with crafted content to cause a denial of service.
User interaction is required.
314) Improper access control (CVE-ID: CVE-2026-79225)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization restrictions.
The vulnerability exists due to improper access control in Browser when handling browser actions. A remote attacker can perform unauthorized actions to bypass authorization restrictions.
User interaction is required.
315) Incorrect authorization (CVE-ID: CVE-2026-79021)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to improper access control in InterestGroups when handling browser functionality. A remote attacker can trigger the vulnerable functionality to bypass authorization checks.
316) Improper Authorization (CVE-ID: CVE-2026-79133)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to improper access control in Forms when handling form-related operations. A remote attacker can trigger crafted interaction with the browser to bypass authorization checks.
User interaction is required.
317) Improper access control (CVE-ID: CVE-2026-79179)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to improper access control in DOM when rendering web content. A remote attacker can craft malicious web content to bypass authorization checks.
User interaction is required to visit or render crafted web content.
318) Improper access control (CVE-ID: CVE-2026-79152)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to improper access control in CustomTabs when handling crafted web content. A remote attacker can cause the victim to interact with crafted content to bypass authorization checks.
User interaction is required for exploitation.
319) Information disclosure (CVE-ID: CVE-2026-78981)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in Mobile when rendering content. A remote attacker can trick the victim into rendering crafted content to disclose sensitive information.
User interaction is required.
320) Improper access control (CVE-ID: CVE-2026-78957)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the mobile component when rendering content. A remote attacker can entice a victim to access crafted content to disclose sensitive information.
User interaction is required.
321) Improper access control (CVE-ID: CVE-2026-79126)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass intended proxy functionality.
The vulnerability exists due to improper access control in Proxy when handling browser network operations. A remote attacker can induce the browser to use the proxy functionality in an unintended way to bypass intended proxy functionality.
User interaction is required to trigger the issue.
322) Race condition (CVE-ID: CVE-2026-78915)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a race condition in Enterprise when processing browser operations. A remote attacker can trigger a race condition to execute arbitrary code.
User interaction is required.
323) Input validation error (CVE-ID: CVE-2026-79253)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in Network when handling network input. A remote attacker can send specially crafted input to cause a denial of service.
User interaction is required.
324) Input validation error (CVE-ID: CVE-2026-79260)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in Cookies when processing cookie data. A remote attacker can provide specially crafted cookie data to cause a denial of service.
User interaction is required.
325) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-79254)
CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to incorrect reference resolution in CustomTabs when handling crafted web content. A remote attacker can trick the victim into opening crafted content to disclose sensitive information.
User interaction is required.
326) Use of uninitialized resource (CVE-ID: CVE-2026-78914)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uninitialized resource use in Skia when rendering content. A remote attacker can trick the victim into opening crafted web content to cause a denial of service.
User interaction is required to render crafted content.
327) Use-after-free (CVE-ID: CVE-2026-78964)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to use-after-free error in Sync in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.
Remediation
Install update from vendor's website.
References
- https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html
- https://issues.chromium.org/issues/496807874
- https://crbug.com/516427761
- https://crbug.com/516764384
- https://crbug.com/516777082
- https://crbug.com/516988476
- https://crbug.com/517518019
- https://crbug.com/518006007
- https://crbug.com/522082472
- https://crbug.com/523704817
- https://crbug.com/532921800
- https://issues.chromium.org/issues/532617619
- https://crbug.com/508638064
- https://crbug.com/498885920
- https://crbug.com/500311587
- https://crbug.com/501892500
- https://crbug.com/513261751
- https://crbug.com/515470739
- https://crbug.com/515473074
- https://crbug.com/516947491
- https://crbug.com/517515945
- https://crbug.com/517519352
- https://crbug.com/517527943
- https://crbug.com/517548647
- https://crbug.com/517550232
- https://crbug.com/517736936
- https://crbug.com/517742721
- https://crbug.com/517959443
- https://crbug.com/521285077
- https://crbug.com/521502218
- https://crbug.com/521942358
- https://crbug.com/522294538
- https://crbug.com/523095011
- https://crbug.com/523266585
- https://crbug.com/523296105
- https://crbug.com/523714535
- https://crbug.com/523717796
- https://crbug.com/523723064
- https://crbug.com/523738212
- https://crbug.com/524698525
- https://crbug.com/525683797
- https://crbug.com/528397177
- https://crbug.com/529509587
- https://crbug.com/529991907
- https://crbug.com/532904047
- https://crbug.com/532914190
- https://crbug.com/532988552
- https://crbug.com/534468209
- https://crbug.com/534591074
- https://crbug.com/535379043
- https://crbug.com/535876894
- https://crbug.com/536428615
- https://crbug.com/536444272
- https://crbug.com/536505721
- https://crbug.com/536531630
- https://crbug.com/536532605
- https://crbug.com/536568319
- https://crbug.com/536606137
- https://crbug.com/536626343
- https://crbug.com/536636648
- https://crbug.com/536659904
- https://crbug.com/536681676
- https://crbug.com/537109028
- https://crbug.com/537233963
- https://crbug.com/537835609
- https://crbug.com/540430406
- https://crbug.com/540870921
- https://crbug.com/543707066
- https://crbug.com/545767601
- https://crbug.com/545820931
- https://crbug.com/546670199
- https://crbug.com/548340637
- https://crbug.com/495021566
- https://crbug.com/40057398
- https://crbug.com/536913431
- https://crbug.com/495579602
- https://crbug.com/495998981
- https://crbug.com/496195129
- https://crbug.com/496292729
- https://crbug.com/496395158
- https://crbug.com/496401361
- https://crbug.com/497017869
- https://crbug.com/497095313
- https://crbug.com/497205529
- https://crbug.com/497269030
- https://crbug.com/497338168
- https://crbug.com/497456156
- https://crbug.com/497538341
- https://crbug.com/497637694
- https://crbug.com/497646947
- https://crbug.com/497839983
- https://crbug.com/497854976
- https://crbug.com/497869284
- https://crbug.com/497940451
- https://crbug.com/497948894
- https://crbug.com/497957278
- https://crbug.com/498327743
- https://crbug.com/498328139
- https://crbug.com/498367544
- https://crbug.com/499007248
- https://crbug.com/499068536
- https://crbug.com/499423269
- https://crbug.com/500038021
- https://crbug.com/500492844
- https://crbug.com/501331457
- https://crbug.com/501437087
- https://crbug.com/501572758
- https://crbug.com/501590191
- https://crbug.com/501594511
- https://crbug.com/501604761
- https://crbug.com/501637242
- https://crbug.com/501661601
- https://crbug.com/501759192
- https://crbug.com/501799770
- https://crbug.com/502082953
- https://crbug.com/502101200
- https://crbug.com/502109333
- https://crbug.com/502139081
- https://crbug.com/502232151
- https://crbug.com/502344135
- https://crbug.com/502488051
- https://crbug.com/502805441
- https://crbug.com/502888857
- https://crbug.com/502918844
- https://crbug.com/503013378
- https://crbug.com/503472696
- https://crbug.com/503585863
- https://crbug.com/503624894
- https://crbug.com/503847023
- https://crbug.com/504226770
- https://crbug.com/504356442
- https://crbug.com/504633668
- https://crbug.com/505951430
- https://crbug.com/505967344
- https://crbug.com/505991181
- https://crbug.com/507483993
- https://crbug.com/511260796
- https://crbug.com/511736672
- https://crbug.com/511794959
- https://crbug.com/511804361
- https://crbug.com/511806043
- https://crbug.com/511819962
- https://crbug.com/511822878
- https://crbug.com/512971896
- https://crbug.com/513048462
- https://crbug.com/513049445
- https://crbug.com/513119757
- https://crbug.com/513192145
- https://crbug.com/513222422
- https://crbug.com/513287677
- https://crbug.com/513392351
- https://crbug.com/513607252
- https://crbug.com/513608317
- https://crbug.com/513608831
- https://crbug.com/513719741
- https://crbug.com/513737209
- https://crbug.com/513745793
- https://crbug.com/513760788
- https://crbug.com/513786555
- https://crbug.com/513834155
- https://crbug.com/513836495
- https://crbug.com/513841856
- https://crbug.com/513850062
- https://crbug.com/513918923
- https://crbug.com/513923164
- https://crbug.com/514006744
- https://crbug.com/514017820
- https://crbug.com/514055709
- https://crbug.com/514069975
- https://crbug.com/514078852
- https://crbug.com/514439436
- https://crbug.com/514454739
- https://crbug.com/514508415
- https://crbug.com/514529599
- https://crbug.com/515477007
- https://crbug.com/516398679
- https://crbug.com/516665605
- https://crbug.com/516824665
- https://crbug.com/516899248
- https://crbug.com/516921259
- https://crbug.com/517045394
- https://crbug.com/517074167
- https://crbug.com/517095594
- https://crbug.com/517245017
- https://crbug.com/517364411
- https://crbug.com/517382613
- https://crbug.com/517398863
- https://crbug.com/517404644
- https://crbug.com/517467117
- https://crbug.com/517487890
- https://crbug.com/517550421
- https://crbug.com/517580738
- https://crbug.com/517606780
- https://crbug.com/517608454
- https://crbug.com/517634590
- https://crbug.com/517655953
- https://crbug.com/517697155
- https://crbug.com/517719358
- https://crbug.com/517746687
- https://crbug.com/517761566
- https://crbug.com/517772510
- https://crbug.com/517774971
- https://crbug.com/517910756
- https://crbug.com/518023156
- https://crbug.com/518035396
- https://crbug.com/518053893
- https://crbug.com/518062961
- https://crbug.com/518065628
- https://crbug.com/518078552
- https://crbug.com/518084889
- https://crbug.com/518094442
- https://crbug.com/519369088
- https://crbug.com/519984038
- https://crbug.com/520052954
- https://crbug.com/520117546
- https://crbug.com/520121111
- https://crbug.com/520179360
- https://crbug.com/520464738
- https://crbug.com/520481800
- https://crbug.com/520492291
- https://crbug.com/520504922
- https://crbug.com/520516462
- https://crbug.com/520542088
- https://crbug.com/522077127
- https://crbug.com/522351802
- https://crbug.com/522550059
- https://crbug.com/522791354
- https://crbug.com/522823211
- https://crbug.com/522957054
- https://crbug.com/523232966
- https://crbug.com/523557855
- https://crbug.com/523661149
- https://crbug.com/523716748
- https://crbug.com/524418836
- https://crbug.com/524520965
- https://crbug.com/524541667
- https://crbug.com/524822825
- https://crbug.com/525686865
- https://crbug.com/525689847
- https://crbug.com/532162132
- https://crbug.com/532182486
- https://crbug.com/532914769
- https://crbug.com/532917452
- https://crbug.com/532923954
- https://crbug.com/532957785
- https://crbug.com/533093250
- https://crbug.com/533917984
- https://crbug.com/535374213
- https://crbug.com/536428842
- https://crbug.com/536428988
- https://crbug.com/536444242
- https://crbug.com/536526176
- https://crbug.com/536662911
- https://crbug.com/537145191
- https://crbug.com/537846307
- https://crbug.com/538969297
- https://crbug.com/503048520
- https://crbug.com/497232609
- https://crbug.com/497256260
- https://crbug.com/497493136
- https://crbug.com/497499482
- https://crbug.com/497876969
- https://crbug.com/500484520
- https://crbug.com/501416859
- https://crbug.com/501881082
- https://crbug.com/502252964
- https://crbug.com/502514083
- https://crbug.com/503720291
- https://crbug.com/506539337
- https://crbug.com/513172858
- https://crbug.com/513361380
- https://crbug.com/513486883
- https://crbug.com/513688690
- https://crbug.com/513792983
- https://crbug.com/513969378
- https://crbug.com/514010111
- https://crbug.com/514038302
- https://crbug.com/514061923
- https://crbug.com/514408247
- https://crbug.com/516864349
- https://crbug.com/516950646
- https://crbug.com/517167020
- https://crbug.com/517394060
- https://crbug.com/517395590
- https://crbug.com/517540292
- https://crbug.com/517673944
- https://crbug.com/517718241
- https://crbug.com/518125889
- https://crbug.com/518249083
- https://crbug.com/519210950
- https://crbug.com/519229463
- https://crbug.com/519242511
- https://crbug.com/519246298
- https://crbug.com/519254827
- https://crbug.com/520002854
- https://crbug.com/520016142
- https://crbug.com/520781436
- https://crbug.com/522291712
- https://crbug.com/522304549
- https://crbug.com/522418913
- https://crbug.com/522803735
- https://crbug.com/523237735
- https://crbug.com/523313378
- https://crbug.com/523572877
- https://crbug.com/524864599
- https://crbug.com/525311654
- https://crbug.com/530816571
- https://crbug.com/531245718
- https://crbug.com/531297707
- https://crbug.com/532303080
- https://crbug.com/533001362
- https://crbug.com/533014006
- https://crbug.com/533021205
- https://crbug.com/533046298
- https://crbug.com/533059149
- https://crbug.com/533060125
- https://crbug.com/533075126
- https://crbug.com/533079345
- https://crbug.com/533083384
- https://crbug.com/533121405
- https://crbug.com/533123348
- https://crbug.com/533408915
- https://crbug.com/533418127
- https://crbug.com/533511921
- https://crbug.com/533511967
- https://crbug.com/534556413
- https://crbug.com/536166543
- https://crbug.com/539341100