CVE-2026-17888
- EPSS 0.16%
- Veröffentlicht 30.07.2026 00:19:49
- Zuletzt bearbeitet 03.08.2026 17:36:09
Insufficient validation of untrusted input in WebUI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: Medium)
CVE-2026-17889
- EPSS 0.23%
- Veröffentlicht 30.07.2026 00:19:49
- Zuletzt bearbeitet 03.08.2026 17:36:05
Uninitialized Use in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-17890
- EPSS 0.17%
- Veröffentlicht 30.07.2026 00:19:49
- Zuletzt bearbeitet 03.08.2026 17:36:01
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security seve...
CVE-2026-17891
- EPSS 0.16%
- Veröffentlicht 30.07.2026 00:19:49
- Zuletzt bearbeitet 03.08.2026 13:46:40
Use after free in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-17884
- EPSS 0.28%
- Veröffentlicht 30.07.2026 00:19:48
- Zuletzt bearbeitet 03.08.2026 17:36:43
Object lifecycle issue in WebRTC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-17885
- EPSS 0.17%
- Veröffentlicht 30.07.2026 00:19:48
- Zuletzt bearbeitet 03.08.2026 17:36:35
Inappropriate implementation in Paint in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-17886
- EPSS 0.28%
- Veröffentlicht 30.07.2026 00:19:48
- Zuletzt bearbeitet 03.08.2026 17:36:24
Use after free in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-17887
- EPSS 0.3%
- Veröffentlicht 30.07.2026 00:19:48
- Zuletzt bearbeitet 03.08.2026 17:36:19
Use after free in TabStrip in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-17881
- EPSS 0.42%
- Veröffentlicht 30.07.2026 00:19:47
- Zuletzt bearbeitet 03.08.2026 17:37:06
Integer overflow in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-17882
- EPSS 0.19%
- Veröffentlicht 30.07.2026 00:19:47
- Zuletzt bearbeitet 03.08.2026 17:36:58
Policy bypass in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to bypass site isolation via a crafted Chrome Extension. (Chromium security severity: Medium)