CVE-2026-2318
- EPSS 0.03%
- Veröffentlicht 11.02.2026 18:08:03
- Zuletzt bearbeitet 13.02.2026 17:29:01
Inappropriate implementation in PictureInPicture in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Med...
CVE-2026-2315
- EPSS 0.03%
- Veröffentlicht 11.02.2026 18:08:02
- Zuletzt bearbeitet 13.02.2026 17:27:56
Inappropriate implementation in WebGPU in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
CVE-2026-2316
- EPSS 0.03%
- Veröffentlicht 11.02.2026 18:08:02
- Zuletzt bearbeitet 13.02.2026 17:28:37
Insufficient policy enforcement in Frames in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-2313
- EPSS 0.07%
- Veröffentlicht 11.02.2026 18:08:01
- Zuletzt bearbeitet 13.02.2026 17:27:42
Use after free in CSS in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2026-2314
- EPSS 0.05%
- Veröffentlicht 11.02.2026 18:08:01
- Zuletzt bearbeitet 13.02.2026 17:27:49
Heap buffer overflow in Codecs in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2026-1862
- EPSS 0.05%
- Veröffentlicht 03.02.2026 20:56:48
- Zuletzt bearbeitet 11.02.2026 18:48:26
Type Confusion in V8 in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2026-1861
- EPSS 0.03%
- Veröffentlicht 03.02.2026 20:56:47
- Zuletzt bearbeitet 11.02.2026 18:32:11
Heap buffer overflow in libvpx in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2026-1504
- EPSS 0.04%
- Veröffentlicht 27.01.2026 20:46:35
- Zuletzt bearbeitet 06.02.2026 17:45:56
Inappropriate implementation in Background Fetch API in Google Chrome prior to 144.0.7559.110 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
CVE-2026-0906
- EPSS 0.12%
- Veröffentlicht 20.01.2026 04:14:17
- Zuletzt bearbeitet 29.01.2026 20:27:23
Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-0907
- EPSS 0.12%
- Veröffentlicht 20.01.2026 04:14:17
- Zuletzt bearbeitet 29.01.2026 20:27:46
Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)