CVE-2026-5898
- EPSS 0.03%
- Veröffentlicht 08.04.2026 21:20:58
- Zuletzt bearbeitet 13.04.2026 21:17:07
Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-5899
- EPSS 0.02%
- Veröffentlicht 08.04.2026 21:20:58
- Zuletzt bearbeitet 13.04.2026 21:16:57
Insufficient policy enforcement in History Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromi...
CVE-2026-5895
- EPSS 0.07%
- Veröffentlicht 08.04.2026 21:20:57
- Zuletzt bearbeitet 13.04.2026 21:18:01
Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. (Chromium security severity: Low)
CVE-2026-5896
- EPSS 0.03%
- Veröffentlicht 08.04.2026 21:20:57
- Zuletzt bearbeitet 13.04.2026 21:18:20
Policy bypass in Audio in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass sandbox download restrictions via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-5897
- EPSS 0.03%
- Veröffentlicht 08.04.2026 21:20:57
- Zuletzt bearbeitet 13.04.2026 21:17:16
Incorrect security UI in Downloads in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-5894
- EPSS 0.02%
- Veröffentlicht 08.04.2026 21:20:56
- Zuletzt bearbeitet 14.04.2026 17:06:45
Inappropriate implementation in PDF in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-5893
- EPSS 0.03%
- Veröffentlicht 08.04.2026 21:20:55
- Zuletzt bearbeitet 13.04.2026 21:17:51
Race in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-5892
- EPSS 0.03%
- Veröffentlicht 08.04.2026 21:20:54
- Zuletzt bearbeitet 14.04.2026 17:06:16
Insufficient policy enforcement in PWAs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to install a PWA without user consent via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-5890
- EPSS 0.03%
- Veröffentlicht 08.04.2026 21:20:53
- Zuletzt bearbeitet 16.04.2026 16:35:55
Race in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-5891
- EPSS 0.06%
- Veröffentlicht 08.04.2026 21:20:53
- Zuletzt bearbeitet 14.04.2026 11:44:52
Insufficient policy enforcement in browser UI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)