Skip to content
← All tracked CVEs

Updated 06:00

Medium severity

Medium45d SLA

Our service-level agreement (SLA) gives a medium vulnerability a fix within 45 days of publication. 446 CVEs are tracked here: open, or fixed in the last 30 days.

Status
CVEStatusSummaryReleaseClock startedDeadlineFixedTime to fix
Fixed within SLAIncorrect security UI allows Omnibox spoofing via crafted HTML on Chrome iOS <151.0.7922.72secure-packages-25.11Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAIsolated Web Apps in Chrome <151.0.7922.72 allow remote bypass of navigation restrictions via crafted HTMLsecure-packages-25.11Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLARemote Site Isolation bypass in Google Chrome <151.0.7922.72 via crafted HTML pagesecure-packages-25.11Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAGoogle Chrome Autofill cross-origin data leak via crafted HTML page pre-151.0.7922.72secure-packages-25.11Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAPolicy bypass in Chrome Receiver enables sandbox escape via crafted HTML (pre-151.0.7922.72)secure-packages-25.11Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAInappropriate PresentationAPI implementation leaks cross-origin data in Chrome before 151.0.7922.72secure-packages-25.11Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAChrome Cast insufficient input validation (<151.0.7922.72) leaks cross-origin data via crafted HTMLsecure-packages-25.11Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAChrome <151.0.7922.72 WebGL out-of-bounds read allows remote memory disclosure via crafted HTMLsecure-packages-25.11Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLASkia uninitialized use enables cross-origin data leak via crafted HTML in Chrome <151.0.7922.72secure-packages-25.11Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAChrome Mac pre-151.0.7922.72 Media OOB read enables sandbox escape after renderer compromisesecure-packages-25.11Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAChrome Cast input validation flaw leaks cross-origin data via crafted HTML (pre-151.0.7922.72) (Medium severity)secure-packages-25.11Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAInsufficient WebView input validation in Android Chrome leaks cross-origin data after renderer compromisesecure-packages-25.11Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAChrome FedCM same-origin policy bypass by remote attacker via crafted HTML prior to 151.0.7922.72secure-packages-25.11Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAGoogle Chrome on iOS before 151.0.7922.72 leaks cross-origin data via crafted HTML pagesecure-packages-25.11Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAChrome iOS <151.0.7922.72 UXSS via insufficient validation of untrusted network inputsecure-packages-25.11Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAInsufficient policy enforcement in Chrome Presentation pre-151.0.7922.72 allows remote navigation bypass via crafted HTMLsecure-packages-25.11Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAChrome pre-151.0.7922.72 Extensions security UI flaw enables UI spoofing via crafted extensionsecure-packages-25.11Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLABlink SOP bypass via crafted HTML in Chrome before 151.0.7922.72secure-packages-25.11Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLASide-channel leak in Chrome Media exposes cross-origin data via crafted HTML (pre-151.0.7922.72)secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome iOS <151.0.7922.72: Insufficient policy enforcement allows remote UI spoofing via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAInsufficient input validation in Chrome DevTools pre-151.0.7922.72 allows navigation bypass via malicious filesecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAGoogle Chrome for iOS prior to 151.0.7922.72 UI spoofing via crafted HTML pagesecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome Passwords pre-151.0.7922.72 enables remote UI spoofing via malicious network trafficsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome Passwords pre-151.0.7922.72 untrusted input validation flaw enables remote UI spoofing via malicious network trafficsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAGoogle Chrome Settings bug before 151.0.7922.72 allowed remote UI spoofing via malicious trafficsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAInput implementation flaw in Chrome Android <151.0.7922.72 enables remote UI spoofing via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAGoogle Lens in Chrome <151.0.7922.72 enables UI spoofing via crafted HTML after renderer compromisesecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAGoogle Chrome WebXR info disclosure from process memory via crafted HTML pre-151.0.7922.72secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAInsufficient Speech API policy in Chrome <151.0.7922.72 enables compromised renderer cross-origin data leaksecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAUI spoofing vulnerability in Chrome iOS <151.0.7922.72 via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAPre-151.0.7922.72 Chrome WebGL bug exposes process memory via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome Android pre-151.0.7922.72 PIP race enables remote domain spoofing via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome <151.0.7922.72: Incorrect Extensions security UI enables malicious extension UI spoofingsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome Mac pre-151.0.7922.72 local attacker bypasses navigation restrictions via malicious filesecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLARemote attacker could bypass navigation restrictions via Media in Chrome Android <151.0.7922.72secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLASkia uninitialized use in Chrome Windows leaks process memory via crafted HTML (pre-151.0.7922.72)secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome <151.0.7922.72 Navigation input validation flaw lets compromised renderer bypass restrictions via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome pre-151.0.7922.72 Bluetooth policy bug allows same-origin policy bypass via crafted HTML from compromised renderersecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAGoogle Chrome pre-151 Speech policy bug enables remote site isolation bypass via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAUI spoofing in Chrome Global Media Controls via crafted HTML before 151.0.7922.72secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAInsufficient input validation in Chrome Cast allowed same-origin policy bypass via crafted HTML pre-151.0.7922.72secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome Blink flaw lets remote attacker leak cross-origin data via crafted HTML pre-151.0.7922.72secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome WebCodecs side-channel exposes sensitive process memory via crafted HTML (pre-151.0.7922.72)secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAGoogle Chrome prior to 151.0.7922.72 CSS policy bypass leaks cross-origin data via crafted HTML pagesecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome Extensions policy flaw allows DAC bypass via crafted domains (pre-151.0.7922.72)secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome Mac IME pre-151.0.7922.72 flaw allows remote process memory disclosure via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome <151.0.7922.72 DevTools policy flaw lets local attacker bypass navigation restrictions via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAGoogle Chrome Mac Views flaw allows local memory disclosure via crafted HTML pre-151.0.7922.72secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome iOS pre-151.0.7922.72 permits UI spoofing via crafted HTML pagesecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome <151.0.7922.72 Passwords lacks input validation, enabling UI spoofing by privileged network attackersecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day