← All tracked CVEs
Updated 05:00
Critical severity
Critical7d SLAOur service-level agreement (SLA) gives a critical vulnerability a fix within 7 days of publication. 100 CVEs are tracked here: open, or fixed in the last 30 days.
| CVE | Status | Summary | Release | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|
| Fixed within SLA | Critical Dawn buffer overflow allows remote code execution outside sandbox on Android Chrome <151.0.7922.169 | secure-packages-rolling | Aug 24, 2026 | Aug 31, 2026 | Aug 25, 2026 | 1 day | |
| Fixed within SLA | Chrome Android Dawn buffer overflow enables remote code execution outside sandbox pre-151.0.7922.169 via crafted HTML | secure-packages-26.05 | Aug 25, 2026 | Sep 1, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | Linux kernel netfs potential tearing and i_size_seqcount corruption updating remote_i_size/zero_point without i_lock | secure-packages-rolling | Aug 18, 2026 | Aug 25, 2026 | Aug 25, 2026 | 6 days | |
| Fixed within SLA | Linux kernel netfs potential tearing in remote_i_size/zero_point risking i_size_seqcount corruption | secure-packages-26.05 | Aug 19, 2026 | Aug 26, 2026 | Aug 19, 2026 | same day | |
| Fixed within SLA | Netfs: Tearing in remote_i_size/zero_point may corrupt i_size_seqcount | secure-packages-25.11 | Aug 18, 2026 | Aug 25, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | UAF in netfs_unlock_abandoned_read_pages and netfs_unlock_read_folio after request progress cleared | secure-packages-25.11 | Aug 12, 2026 | Aug 19, 2026 | Aug 18, 2026 | 6 days | |
| Fixed within SLA | Use-after-free in Chrome Payments allows remote sandbox escape via crafted HTML pre-151.0.7922.109 | secure-packages-26.05 | Aug 11, 2026 | Aug 18, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | Use-after-free in Chrome Media on Windows pre-151.0.7922.109 enables remote sandbox escape via crafted HTML | secure-packages-26.05 | Aug 11, 2026 | Aug 18, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | Critical WebGL use-after-free allows remote sandbox escape in Android Chrome <151.0.7922.109 | secure-packages-26.05 | Aug 11, 2026 | Aug 18, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | Google Chrome WebAuthn use-after-free allows remote sandbox escape via crafted HTML (pre-151.0.7922.109) | secure-packages-26.05 | Aug 11, 2026 | Aug 18, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | Insufficient Chrome Codecs input validation enables remote sandbox escape via crafted HTML (pre-151.0.7922.109) | secure-packages-26.05 | Aug 11, 2026 | Aug 18, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | ANGLE out-of-bounds write in Chrome Android pre-151.0.7922.109 enables remote sandbox escape | secure-packages-26.05 | Aug 11, 2026 | Aug 18, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | Critical use-after-free in Google Chrome Aura on Linux <151.0.7922.109 enables remote sandbox escape | secure-packages-26.05 | Aug 11, 2026 | Aug 18, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | Use-after-free in Google Chrome Payments enables sandbox escape via crafted HTML (pre-151.0.7922.109) | secure-packages-25.11 | Aug 10, 2026 | Aug 17, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | Use-after-free in Chrome Media on Windows enables remote sandbox escape (pre-151.0.7922.109) | secure-packages-25.11 | Aug 10, 2026 | Aug 17, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | WebGL use-after-free in Chrome Android enables remote sandbox escape pre-151.0.7922.109 | secure-packages-25.11 | Aug 10, 2026 | Aug 17, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | High-severity WebAuthn use-after-free in Google Chrome <151.0.7922.109 enables remote sandbox escape via crafted HTML page | secure-packages-25.11 | Aug 10, 2026 | Aug 17, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | Chrome pre-151.0.7922.109 Codecs validation flaw allows remote sandbox escape via crafted HTML, high severity | secure-packages-25.11 | Aug 10, 2026 | Aug 17, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | Critical OOB write in ANGLE on Chrome Android before 151.0.7922.109 enabling sandbox escape via HTML | secure-packages-25.11 | Aug 10, 2026 | Aug 17, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | Aura UAF enables remote sandbox escape via crafted HTML in Chrome Linux <151.0.7922.109 | secure-packages-25.11 | Aug 10, 2026 | Aug 17, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | Use-after-free in Chrome Payments allows remote sandbox escape via crafted HTML (pre-151.0.7922.109) | secure-packages-rolling | Aug 10, 2026 | Aug 17, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | Chrome Windows <151.0.7922.109 Media use-after-free enables remote sandbox escape via HTML | secure-packages-rolling | Aug 10, 2026 | Aug 17, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | Use-after-free in Chrome Android WebGL enables remote sandbox escape (pre-151.0.7922.109) | secure-packages-rolling | Aug 10, 2026 | Aug 17, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | Use-after-free in Chrome WebAuthn pre-151.0.7922.109 allows remote sandbox escape via HTML | secure-packages-rolling | Aug 10, 2026 | Aug 17, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | Insufficient input validation in Chrome Codecs pre-151.0.7922.109 allows remote sandbox escape via HTML | secure-packages-rolling | Aug 10, 2026 | Aug 17, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | Critical ANGLE out-of-bounds write enables sandbox escape via crafted HTML in Chrome Android <151.0.7922.109 | secure-packages-rolling | Aug 10, 2026 | Aug 17, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | Critical UAF in Chrome Aura on Linux enables remote sandbox escape via crafted HTML pre-151.0.7922.109 | secure-packages-rolling | Aug 10, 2026 | Aug 17, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | Critical Chrome Ozone use-after-free enables remote sandbox escape via crafted HTML (pre-151.0.7922.72) | secure-packages-25.11 | Aug 10, 2026 | Aug 17, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | ANGLE input validation flaw in Chrome <151.0.7922.72 enables remote sandbox escape via crafted HTML | secure-packages-25.11 | Aug 10, 2026 | Aug 17, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | Critical use-after-free in Chrome Views enables sandbox escape from compromised renderer prior to 151.0.7922.72 | secure-packages-25.11 | Aug 10, 2026 | Aug 17, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | Tint implementation flaw in Chrome Mac before 151.0.7922.72 allows sandbox escape via crafted HTML | secure-packages-rolling | Aug 5, 2026 | Aug 12, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Chrome <151.0.7922.72 WebSocket input validation bug enables sandbox escape from compromised renderer | secure-packages-rolling | Aug 5, 2026 | Aug 12, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Critical use-after-free in Chrome Ozone pre-151.0.7922.72 enables remote crafted-HTML sandbox escape | secure-packages-rolling | Aug 7, 2026 | Aug 14, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | Critical ANGLE input validation flaw enables remote sandbox escape via crafted HTML in Chrome <151.0.7922.72 | secure-packages-rolling | Aug 7, 2026 | Aug 14, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | Chrome <151.0.7922.72: Views use-after-free enables sandbox escape via crafted HTML | secure-packages-rolling | Aug 7, 2026 | Aug 14, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | Pre-151.0.7922.72 Chrome for Mac Tint flaw enabled remote sandbox escape via HTML | secure-packages-26.05 | Aug 5, 2026 | Aug 12, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | WebSockets input validation flaw enables sandbox escape from compromised renderer in Chrome <151.0.7922.72 | secure-packages-26.05 | Aug 5, 2026 | Aug 12, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Critical Chrome Ozone use-after-free enables remote sandbox escape via crafted HTML before 151.0.7922.72 | secure-packages-26.05 | Aug 7, 2026 | Aug 14, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | Critical ANGLE input validation flaw enables sandbox escape via crafted HTML (Chrome <151.0.7922.72) | secure-packages-26.05 | Aug 7, 2026 | Aug 14, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | Use-after-free in Views enables sandbox escape on Chrome before 151.0.7922.72 via crafted HTML | secure-packages-26.05 | Aug 7, 2026 | Aug 14, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | secure-packages-rolling | Aug 10, 2026 | Aug 17, 2026 | Aug 11, 2026 | 1 day | ||
| Fixed within SLA | nfsd setlease failure frees layout stid without idr_remove, causing IDR dangling pointer dereference | secure-packages-25.11 | Aug 4, 2026 | Aug 11, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | Use-after-free in pNFS pnfs_update_layout() tracepoint after freeing lo with pnfs_put_layout_hdr | secure-packages-rolling | Aug 4, 2026 | Aug 11, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | 9p p9_client_walk error drops oldfid reference when clone=false, causing UAF/refcount underflow | secure-packages-rolling | Aug 4, 2026 | Aug 11, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | Use-after-free via IDR leak and uninitialized delayed_work on nfsd layout setlease failure | secure-packages-rolling | Aug 4, 2026 | Aug 11, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | NFSD: SECINFO_NO_NAME decode leaves stale sin_exp; exp_put called after truncated XDR | secure-packages-rolling | Aug 4, 2026 | Aug 11, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | Tint implementation flaw in Google Chrome on Mac <151.0.7922.72 enabling sandbox escape via crafted HTML | secure-packages-25.11 | Aug 5, 2026 | Aug 12, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Chrome WebSockets input validation flaw enables sandbox escape from compromised renderer via crafted HTML (pre-151.0.7922.72) | secure-packages-25.11 | Aug 5, 2026 | Aug 12, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | glibc scanf %mc width >1024 triggers 1-byte heap overflow in v2.7-2.43 | secure-packages-26.05 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome Google Lens insufficient input validation allows renderer sandbox escape via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day |