CVE-2026-18002
- EPSS 0.2%
- Veröffentlicht 30.07.2026 00:26:03
- Zuletzt bearbeitet 03.08.2026 15:59:21
Insufficient validation of untrusted input in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security s...
CVE-2026-17999
- EPSS 0.15%
- Veröffentlicht 30.07.2026 00:26:02
- Zuletzt bearbeitet 03.08.2026 13:45:08
Race in PictureInPicture in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-18000
- EPSS 0.15%
- Veröffentlicht 30.07.2026 00:26:02
- Zuletzt bearbeitet 03.08.2026 13:45:21
Insufficient policy enforcement in USB in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-17996
- EPSS 0.09%
- Veröffentlicht 30.07.2026 00:26:01
- Zuletzt bearbeitet 03.08.2026 13:48:34
Inappropriate implementation in Browser in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Low)
CVE-2026-17997
- EPSS 0.13%
- Veröffentlicht 30.07.2026 00:26:01
- Zuletzt bearbeitet 03.08.2026 13:48:15
Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-17998
- EPSS 0.12%
- Veröffentlicht 30.07.2026 00:26:01
- Zuletzt bearbeitet 03.08.2026 13:47:56
Incorrect security UI in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)
CVE-2026-17994
- EPSS 0.18%
- Veröffentlicht 30.07.2026 00:26:00
- Zuletzt bearbeitet 03.08.2026 13:45:01
Inappropriate implementation in Media in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-17995
- EPSS 0.24%
- Veröffentlicht 30.07.2026 00:26:00
- Zuletzt bearbeitet 03.08.2026 13:48:51
Out of bounds read in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-17992
- EPSS 0.26%
- Veröffentlicht 30.07.2026 00:25:59
- Zuletzt bearbeitet 03.08.2026 13:49:18
Uninitialized Use in Skia in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
- EPSS 0.1%
- Veröffentlicht 30.07.2026 00:25:59
- Zuletzt bearbeitet 31.07.2026 04:17:14
Race in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Low)