Skip to content
← All tracked CVEs

Updated 07:00

Medium severity

Medium45d SLA

Our service-level agreement (SLA) gives a medium vulnerability a fix within 45 days of publication. 446 CVEs are tracked here: open, or fixed in the last 30 days.

Status
CVEStatusSummaryReleaseClock startedDeadlineFixedTime to fix
Fixed within SLAWebXR uninitialized use leaks process memory in Chrome Android before 151.0.7922.72secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMac Chrome Views bug allowed local process memory disclosure via crafted HTML prior to 151.0.7922.72secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome iOS <151.0.7922.72: Incorrect security UI allows remote HTML UI spoofingsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAIncorrect security UI on Chrome Android pre-151.0.7922.72 enables domain spoofing via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome <151.0.7922.72 SVG bug allows cross-origin data leak via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLABlink UXSS in Chrome <151.0.7922.72 allows remote script/HTML injection via crafted pagesecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome Android pre-151.0.7922.72 Session bug allows remote bypass of navigation restrictions via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAInsufficient policy enforcement enables no-referrer bypass via crafted HTML in Chrome iOS <151.0.7922.72secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome Network vulnerability leaked cross-origin data via crafted HTML page pre-151.0.7922.72secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAGoogle Chrome pre-151.0.7922.72 Views flaw enables remote UI spoofing via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAInsufficient input validation in Chrome Payments allows UI spoofing via crafted HTML (pre-151.0.7922.72)secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAPolicy bypass in Chrome MHTML before 151.0.7922.72 leaks cross-origin datasecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAAndroid Chrome WebView policy enforcement bug allows navigation bypass via crafted HTML before 151.0.7922.72secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAUninitialized GPU use in Chrome Android pre-151.0.7922.72 leaks cross-origin data via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome <151.0.7922.72 Dawn uninitialized use leaks process memory via crafted HTML when renderer compromisedsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAInsufficient Navigation input validation in Chrome <151.0.7922.72 allows UI spoofing post-renderer compromisesecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome for iOS <151.0.7922.72 allows navigation restriction bypass via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAGoogle Chrome <151.0.7922.72 parser flaw allows CSP bypass via crafted HTML pagesecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLACross-origin data leak via SVG side-channel in Google Chrome before 151.0.7922.72 using crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAOmnibox URL spoofing in Chrome for iOS before 151.0.7922.72 via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAInsufficient untrusted input validation in Chrome Passwords enables UI spoofing via network traffic (pre-151.0.7922.72)secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome Android pre-151.0.7922.72 FullScreen flaw enables remote UI spoofing via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome DevTools vulnerability before 151.0.7922.72 enables bypass of navigation restrictions via crafted HTML with gesturessecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome DevTools insufficient validation of untrusted input enabled navigation restriction bypass via crafted HTML pre-151.0.7922.72secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome DOMStorage vulnerability allowed remote cross-origin data leak via crafted HTML page pre-151.0.7922.72secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome Windows DataTransfer use-after-free leaks process memory via crafted HTML pre-151.0.7922.72secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome DevTools navigation restriction bypass via crafted HTML page (pre-151.0.7922.72)secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAPre-151.0.7922.72 Chrome DevTools insufficient input validation lets remote attackers bypass navigation via malicious filesecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome <151.0.7922.72 DataTransfer bug leaks cross-origin data via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome DevTools insufficient policy enforcement pre-151.0.7922.72 enables cross-origin data leak via malicious extensionsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome DevTools insufficient input validation enables navigation bypass via crafted HTML and user gesturessecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome Android Cast before 151.0.7922.72 allows same-origin policy bypass via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAGoogle Chrome Enterprise pre-151.0.7922.72 policy flaw lets remote attackers bypass navigation restrictions via crafted domainssecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome pre-151.0.7922.72 navigation input validation flaw enables renderer-based navigation restriction bypasssecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome Mac pre-151.0.7922.72 Enterprise policy enforcement flaw allows local privilege escalation with physical accesssecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAiOS Chrome pre-151.0.7922.72 policy enforcement flaw lets remote bypass DAC via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAAndroid Chrome WebView UI spoofing vulnerability before 151.0.7922.72 via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLASkia side-channel leak in Chrome exposes process memory via crafted HTML (pre-151.0.7922.72)secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLARemote attacker bypasses navigation restrictions in iOS Chrome pre-151.0.7922.72 via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAInsufficient SVG policy enforcement in Google Chrome <151.0.7922.72 enables cross-origin data leak via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAAndroid Chrome NFC policy enforcement flaw allows remote cross-origin data leak pre-151.0.7922.72secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAInsufficient untrusted input validation in Chrome Isolated Web Apps allows cross-origin data leak via networksecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAPre-151.0.7922.72 Windows Chrome Printing input validation bug allows sandbox escape via crafted HTML post-renderer compromisesecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome pre-151.0.7922.72 Network component side-channel leaks cross-origin data via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAGoogle Chrome <151.0.7922.72 Bluetooth input validation bug allows renderer sandbox escape via HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome SurfaceCapture bug before 151.0.7922.72 lets remote attacker leak cross-origin data via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAAndroid Chrome <151.0.7922.72 NFC policy flaw leaks cross-origin data via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChromecast in Chrome pre-151.0.7922.72 allows LAN script/HTML injection into privileged pagesecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome Android Sharing input validation flaw pre-151.0.7922.72 enables remote navigation bypasssecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLARemote cross-origin data leak in Chrome Enterprise Windows <151.0.7922.72 via malicious filesecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day