CVE-2026-7944
- EPSS 0.03%
- Veröffentlicht 06.05.2026 18:12:46
- Zuletzt bearbeitet 06.05.2026 23:32:48
Insufficient validation of untrusted input in Persistent Cache in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: M...
CVE-2026-7941
- EPSS 0.01%
- Veröffentlicht 06.05.2026 18:12:45
- Zuletzt bearbeitet 06.05.2026 23:33:34
Insufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 148.0.7778.96 allowed a local attacker to inject arbitrary scripts or HTML (UXSS) via a crafted Chrome Extension. (Chromium security severity: Medium)
CVE-2026-7942
- EPSS 0.03%
- Veröffentlicht 06.05.2026 18:12:45
- Zuletzt bearbeitet 06.05.2026 23:33:07
Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-7939
- EPSS 0.03%
- Veröffentlicht 06.05.2026 18:12:44
- Zuletzt bearbeitet 06.05.2026 23:33:57
Inappropriate implementation in SanitizerAPI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-7940
- EPSS 0.02%
- Veröffentlicht 06.05.2026 18:12:44
- Zuletzt bearbeitet 06.05.2026 23:33:48
Use after free in V8 in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Medium)
CVE-2026-7938
- EPSS 0.08%
- Veröffentlicht 06.05.2026 18:12:43
- Zuletzt bearbeitet 06.05.2026 23:34:05
Use after free in CSS in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-7937
- EPSS 0.02%
- Veröffentlicht 06.05.2026 18:12:42
- Zuletzt bearbeitet 06.05.2026 23:34:15
Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severit...
CVE-2026-7934
- EPSS 0.03%
- Veröffentlicht 06.05.2026 18:12:39
- Zuletzt bearbeitet 06.05.2026 23:34:43
Insufficient validation of untrusted input in Popup Blocker in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security sever...
CVE-2026-7935
- EPSS 0.06%
- Veröffentlicht 06.05.2026 18:12:39
- Zuletzt bearbeitet 06.05.2026 23:34:33
Inappropriate implementation in Speech in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-7936
- EPSS 0.03%
- Veröffentlicht 06.05.2026 18:12:39
- Zuletzt bearbeitet 06.05.2026 23:34:23
Object lifecycle issue in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)