CVE-2023-7011
- EPSS 0.11%
- Published 16.07.2024 23:15:11
- Last modified 26.12.2024 15:43:13
Inappropriate implementation in Picture in Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
CVE-2023-7012
- EPSS 0.06%
- Published 16.07.2024 23:15:11
- Last modified 26.12.2024 15:43:32
Insufficient data validation in Permission Prompts in Google Chrome prior to 117.0.5938.62 allowed an attacker who convinced a user to install a malicious app to potentially perform a sandbox escape via a malicious file. (Chromium security severity: ...
CVE-2023-7013
- EPSS 0.21%
- Published 16.07.2024 23:15:11
- Last modified 25.11.2024 19:15:07
Inappropriate implementation in Compositing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
CVE-2019-25154
- EPSS 0.36%
- Published 16.07.2024 23:15:10
- Last modified 21.11.2024 16:15:18
Inappropriate implementation in iframe in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
CVE-2020-36765
- EPSS 0.15%
- Published 16.07.2024 23:15:10
- Last modified 21.11.2024 05:30:15
Insufficient policy enforcement in Navigation in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2024-6775
- EPSS 0.7%
- Published 16.07.2024 22:15:07
- Last modified 26.12.2024 16:05:07
Use after free in Media Stream in Google Chrome prior to 126.0.6478.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High...
CVE-2024-6776
- EPSS 0.4%
- Published 16.07.2024 22:15:07
- Last modified 26.12.2024 16:05:20
Use after free in Audio in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2024-6777
- EPSS 0.05%
- Published 16.07.2024 22:15:07
- Last modified 26.12.2024 14:55:39
Use after free in Navigation in Google Chrome prior to 126.0.6478.182 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
CVE-2024-6778
- EPSS 13.67%
- Published 16.07.2024 22:15:07
- Last modified 26.12.2024 15:36:56
Race in DevTools in Google Chrome prior to 126.0.6478.182 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)
CVE-2024-6779
- EPSS 0.34%
- Published 16.07.2024 22:15:07
- Last modified 20.03.2025 21:15:22
Out of bounds memory access in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)