← All tracked CVEs
Updated 07:00
Medium severity
Medium45d SLAOur service-level agreement (SLA) gives a medium vulnerability a fix within 45 days of publication. 446 CVEs are tracked here: open, or fixed in the last 30 days.
| CVE | Status | Summary | Release | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|
| Fixed within SLA | WebXR uninitialized use leaks process memory in Chrome Android before 151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Mac Chrome Views bug allowed local process memory disclosure via crafted HTML prior to 151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome iOS <151.0.7922.72: Incorrect security UI allows remote HTML UI spoofing | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Incorrect security UI on Chrome Android pre-151.0.7922.72 enables domain spoofing via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome <151.0.7922.72 SVG bug allows cross-origin data leak via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Blink UXSS in Chrome <151.0.7922.72 allows remote script/HTML injection via crafted page | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome Android pre-151.0.7922.72 Session bug allows remote bypass of navigation restrictions via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Insufficient policy enforcement enables no-referrer bypass via crafted HTML in Chrome iOS <151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome Network vulnerability leaked cross-origin data via crafted HTML page pre-151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Google Chrome pre-151.0.7922.72 Views flaw enables remote UI spoofing via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Insufficient input validation in Chrome Payments allows UI spoofing via crafted HTML (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Policy bypass in Chrome MHTML before 151.0.7922.72 leaks cross-origin data | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Android Chrome WebView policy enforcement bug allows navigation bypass via crafted HTML before 151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Uninitialized GPU use in Chrome Android pre-151.0.7922.72 leaks cross-origin data via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome <151.0.7922.72 Dawn uninitialized use leaks process memory via crafted HTML when renderer compromised | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Insufficient Navigation input validation in Chrome <151.0.7922.72 allows UI spoofing post-renderer compromise | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome for iOS <151.0.7922.72 allows navigation restriction bypass via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Google Chrome <151.0.7922.72 parser flaw allows CSP bypass via crafted HTML page | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Cross-origin data leak via SVG side-channel in Google Chrome before 151.0.7922.72 using crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Omnibox URL spoofing in Chrome for iOS before 151.0.7922.72 via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Insufficient untrusted input validation in Chrome Passwords enables UI spoofing via network traffic (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome Android pre-151.0.7922.72 FullScreen flaw enables remote UI spoofing via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome DevTools vulnerability before 151.0.7922.72 enables bypass of navigation restrictions via crafted HTML with gestures | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome DevTools insufficient validation of untrusted input enabled navigation restriction bypass via crafted HTML pre-151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome DOMStorage vulnerability allowed remote cross-origin data leak via crafted HTML page pre-151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome Windows DataTransfer use-after-free leaks process memory via crafted HTML pre-151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome DevTools navigation restriction bypass via crafted HTML page (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Pre-151.0.7922.72 Chrome DevTools insufficient input validation lets remote attackers bypass navigation via malicious file | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome <151.0.7922.72 DataTransfer bug leaks cross-origin data via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome DevTools insufficient policy enforcement pre-151.0.7922.72 enables cross-origin data leak via malicious extension | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome DevTools insufficient input validation enables navigation bypass via crafted HTML and user gestures | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome Android Cast before 151.0.7922.72 allows same-origin policy bypass via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Google Chrome Enterprise pre-151.0.7922.72 policy flaw lets remote attackers bypass navigation restrictions via crafted domains | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome pre-151.0.7922.72 navigation input validation flaw enables renderer-based navigation restriction bypass | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome Mac pre-151.0.7922.72 Enterprise policy enforcement flaw allows local privilege escalation with physical access | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | iOS Chrome pre-151.0.7922.72 policy enforcement flaw lets remote bypass DAC via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Android Chrome WebView UI spoofing vulnerability before 151.0.7922.72 via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Skia side-channel leak in Chrome exposes process memory via crafted HTML (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Remote attacker bypasses navigation restrictions in iOS Chrome pre-151.0.7922.72 via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Insufficient SVG policy enforcement in Google Chrome <151.0.7922.72 enables cross-origin data leak via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Android Chrome NFC policy enforcement flaw allows remote cross-origin data leak pre-151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Insufficient untrusted input validation in Chrome Isolated Web Apps allows cross-origin data leak via network | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Pre-151.0.7922.72 Windows Chrome Printing input validation bug allows sandbox escape via crafted HTML post-renderer compromise | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome pre-151.0.7922.72 Network component side-channel leaks cross-origin data via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Google Chrome <151.0.7922.72 Bluetooth input validation bug allows renderer sandbox escape via HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome SurfaceCapture bug before 151.0.7922.72 lets remote attacker leak cross-origin data via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Android Chrome <151.0.7922.72 NFC policy flaw leaks cross-origin data via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chromecast in Chrome pre-151.0.7922.72 allows LAN script/HTML injection into privileged page | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome Android Sharing input validation flaw pre-151.0.7922.72 enables remote navigation bypass | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Remote cross-origin data leak in Chrome Enterprise Windows <151.0.7922.72 via malicious file | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day |