CVE-2026-17854
- EPSS 0.19%
- Veröffentlicht 30.07.2026 00:19:39
- Zuletzt bearbeitet 03.08.2026 19:40:34
Insufficient policy enforcement in WebMCP in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-17848
- EPSS 0.25%
- Veröffentlicht 30.07.2026 00:19:38
- Zuletzt bearbeitet 03.08.2026 19:40:56
Integer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium)
CVE-2026-17849
- EPSS 0.2%
- Veröffentlicht 30.07.2026 00:19:38
- Zuletzt bearbeitet 31.07.2026 21:21:16
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via malicious network traffic. (Chromium security severity: Medium)
CVE-2026-17850
- EPSS 0.24%
- Veröffentlicht 30.07.2026 00:19:38
- Zuletzt bearbeitet 03.08.2026 19:40:48
Inappropriate implementation in Permissions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-17844
- EPSS 0.12%
- Veröffentlicht 30.07.2026 00:19:37
- Zuletzt bearbeitet 03.08.2026 17:39:21
Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed an attacker on the local network segment to leak cross-origin data via malicious network traffic. (Chromium security severity: Medium)
CVE-2026-17845
- EPSS 0.18%
- Veröffentlicht 30.07.2026 00:19:37
- Zuletzt bearbeitet 03.08.2026 19:41:15
Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-17846
- EPSS 0.19%
- Veröffentlicht 30.07.2026 00:19:37
- Zuletzt bearbeitet 03.08.2026 19:41:09
Inappropriate implementation in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-17847
- EPSS 0.28%
- Veröffentlicht 30.07.2026 00:19:37
- Zuletzt bearbeitet 03.08.2026 19:41:00
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-17840
- EPSS 0.24%
- Veröffentlicht 30.07.2026 00:19:36
- Zuletzt bearbeitet 03.08.2026 19:04:34
Incorrect security UI in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-17841
- EPSS 0.17%
- Veröffentlicht 30.07.2026 00:19:36
- Zuletzt bearbeitet 03.08.2026 20:17:14
Race in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)