← All tracked CVEs
Updated 06:00
Medium severity
Medium45d SLAOur service-level agreement (SLA) gives a medium vulnerability a fix within 45 days of publication. 446 CVEs are tracked here: open, or fixed in the last 30 days.
| CVE | Status | Summary | Release | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|
| Fixed within SLA | Incorrect security UI allows Omnibox spoofing via crafted HTML on Chrome iOS <151.0.7922.72 | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Isolated Web Apps in Chrome <151.0.7922.72 allow remote bypass of navigation restrictions via crafted HTML | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Remote Site Isolation bypass in Google Chrome <151.0.7922.72 via crafted HTML page | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Google Chrome Autofill cross-origin data leak via crafted HTML page pre-151.0.7922.72 | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Policy bypass in Chrome Receiver enables sandbox escape via crafted HTML (pre-151.0.7922.72) | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Inappropriate PresentationAPI implementation leaks cross-origin data in Chrome before 151.0.7922.72 | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Chrome Cast insufficient input validation (<151.0.7922.72) leaks cross-origin data via crafted HTML | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Chrome <151.0.7922.72 WebGL out-of-bounds read allows remote memory disclosure via crafted HTML | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Skia uninitialized use enables cross-origin data leak via crafted HTML in Chrome <151.0.7922.72 | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Chrome Mac pre-151.0.7922.72 Media OOB read enables sandbox escape after renderer compromise | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Chrome Cast input validation flaw leaks cross-origin data via crafted HTML (pre-151.0.7922.72) (Medium severity) | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Insufficient WebView input validation in Android Chrome leaks cross-origin data after renderer compromise | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Chrome FedCM same-origin policy bypass by remote attacker via crafted HTML prior to 151.0.7922.72 | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Google Chrome on iOS before 151.0.7922.72 leaks cross-origin data via crafted HTML page | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Chrome iOS <151.0.7922.72 UXSS via insufficient validation of untrusted network input | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Insufficient policy enforcement in Chrome Presentation pre-151.0.7922.72 allows remote navigation bypass via crafted HTML | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Chrome pre-151.0.7922.72 Extensions security UI flaw enables UI spoofing via crafted extension | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Blink SOP bypass via crafted HTML in Chrome before 151.0.7922.72 | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Side-channel leak in Chrome Media exposes cross-origin data via crafted HTML (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome iOS <151.0.7922.72: Insufficient policy enforcement allows remote UI spoofing via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Insufficient input validation in Chrome DevTools pre-151.0.7922.72 allows navigation bypass via malicious file | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Google Chrome for iOS prior to 151.0.7922.72 UI spoofing via crafted HTML page | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome Passwords pre-151.0.7922.72 enables remote UI spoofing via malicious network traffic | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome Passwords pre-151.0.7922.72 untrusted input validation flaw enables remote UI spoofing via malicious network traffic | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Google Chrome Settings bug before 151.0.7922.72 allowed remote UI spoofing via malicious traffic | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Input implementation flaw in Chrome Android <151.0.7922.72 enables remote UI spoofing via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Google Lens in Chrome <151.0.7922.72 enables UI spoofing via crafted HTML after renderer compromise | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Google Chrome WebXR info disclosure from process memory via crafted HTML pre-151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Insufficient Speech API policy in Chrome <151.0.7922.72 enables compromised renderer cross-origin data leak | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | UI spoofing vulnerability in Chrome iOS <151.0.7922.72 via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Pre-151.0.7922.72 Chrome WebGL bug exposes process memory via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome Android pre-151.0.7922.72 PIP race enables remote domain spoofing via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome <151.0.7922.72: Incorrect Extensions security UI enables malicious extension UI spoofing | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome Mac pre-151.0.7922.72 local attacker bypasses navigation restrictions via malicious file | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Remote attacker could bypass navigation restrictions via Media in Chrome Android <151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Skia uninitialized use in Chrome Windows leaks process memory via crafted HTML (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome <151.0.7922.72 Navigation input validation flaw lets compromised renderer bypass restrictions via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome pre-151.0.7922.72 Bluetooth policy bug allows same-origin policy bypass via crafted HTML from compromised renderer | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Google Chrome pre-151 Speech policy bug enables remote site isolation bypass via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | UI spoofing in Chrome Global Media Controls via crafted HTML before 151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Insufficient input validation in Chrome Cast allowed same-origin policy bypass via crafted HTML pre-151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome Blink flaw lets remote attacker leak cross-origin data via crafted HTML pre-151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome WebCodecs side-channel exposes sensitive process memory via crafted HTML (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Google Chrome prior to 151.0.7922.72 CSS policy bypass leaks cross-origin data via crafted HTML page | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome Extensions policy flaw allows DAC bypass via crafted domains (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome Mac IME pre-151.0.7922.72 flaw allows remote process memory disclosure via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome <151.0.7922.72 DevTools policy flaw lets local attacker bypass navigation restrictions via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Google Chrome Mac Views flaw allows local memory disclosure via crafted HTML pre-151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome iOS pre-151.0.7922.72 permits UI spoofing via crafted HTML page | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome <151.0.7922.72 Passwords lacks input validation, enabling UI spoofing by privileged network attacker | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day |