CVE-2026-3928
- EPSS 0.02%
- Veröffentlicht 11.03.2026 22:04:10
- Zuletzt bearbeitet 17.03.2026 13:10:14
Insufficient policy enforcement in Extensions in Google Chrome prior to 146.0.7680.71 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Medium...
CVE-2026-3929
- EPSS 0.03%
- Veröffentlicht 11.03.2026 22:04:10
- Zuletzt bearbeitet 13.03.2026 15:41:23
Side-channel information leakage in ResourceTiming in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-3926
- EPSS 0.09%
- Veröffentlicht 11.03.2026 22:04:09
- Zuletzt bearbeitet 13.03.2026 15:41:12
Out of bounds read in V8 in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-3927
- EPSS 0.03%
- Veröffentlicht 11.03.2026 22:04:09
- Zuletzt bearbeitet 13.03.2026 20:15:11
Incorrect security UI in PictureInPicture in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-3924
- EPSS 0.12%
- Veröffentlicht 11.03.2026 22:04:08
- Zuletzt bearbeitet 13.03.2026 15:41:03
use after free in WindowDialog in Google Chrome prior to 146.0.7680.71 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVE-2026-3925
- EPSS 0.02%
- Veröffentlicht 11.03.2026 22:04:08
- Zuletzt bearbeitet 13.03.2026 20:15:58
Incorrect security UI in LookalikeChecks in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-3923
- EPSS 0.11%
- Veröffentlicht 11.03.2026 22:04:07
- Zuletzt bearbeitet 13.03.2026 15:42:16
Use after free in WebMIDI in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2026-3921
- EPSS 0.12%
- Veröffentlicht 11.03.2026 22:04:06
- Zuletzt bearbeitet 13.03.2026 15:42:29
Use after free in TextEncoding in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2026-3922
- EPSS 0.12%
- Veröffentlicht 11.03.2026 22:04:06
- Zuletzt bearbeitet 13.03.2026 15:42:22
Use after free in MediaStream in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2026-3919
- EPSS 0.03%
- Veröffentlicht 11.03.2026 22:04:05
- Zuletzt bearbeitet 13.03.2026 15:43:22
Use after free in Extensions in Google Chrome prior to 146.0.7680.71 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)