Skip to content
← All tracked CVEs

Updated 08:00

Medium severity

Medium45d SLA

Our service-level agreement (SLA) gives a medium vulnerability a fix within 45 days of publication. 446 CVEs are tracked here: open, or fixed in the last 30 days.

Status
CVEStatusSummaryReleaseClock startedDeadlineFixedTime to fix
Fixed within SLAInappropriate ORB implementation in Chrome pre-151.0.7922.72 leaks cross-origin data via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome pre-151.0.7922.72 DataTransfer flaw leaks cross-origin data via crafted page/UI gesturessecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAInsufficient input validation in Chrome Mac Updater allows sandbox escape from compromised renderersecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAWebXR vulnerability leaks Chrome process memory via crafted HTML (pre-151.0.7922.72)secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLA<151.0.7922.72 Chrome Android ANGLE use-after-free allows sandbox escape via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome DevTools insufficient input validation enables sandbox escape via crafted HTML from compromised renderersecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAWebXR uninitialized use in Chrome <151.0.7922.72 leaks cross-origin data via HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome Paint cross-origin data leak via crafted HTML before 151.0.7922.72secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLARemote attacker could bypass same-origin policy in Headless Chrome <151.0.7922.72 via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome <151.0.7922.72 extension policy flaw allows site isolation bypass via malicious extensionsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome Autofill cross-origin data leak via crafted HTML page prior to 151.0.7922.72secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome Autofill cross-origin data leak via crafted HTML (pre-151.0.7922.72)secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome <151.0.7922.72 CSS bug enables UXSS via crafted HTML pagesecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAPre-151.0.7922.72 Chrome Payments bug leaks cross-origin data via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome for iOS before 151.0.7922.72 allows UI spoofing via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAiOS Chrome <151.0.7922.72: insufficient policy enforcement enables HTML-based discretionary access control bypasssecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLACryptographic flaw in WebAppInstalls allows local sandbox escape via crafted HTML in Android Chrome pre-151.0.7922.72secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAPre-151.0.7922.72 Chrome Passwords cross-origin data leak via crafted page, UI gesturessecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome Cast pre-151.0.7922.72 insufficient input validation leaks cross-origin data on LANsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAType confusion in Tab allows sandbox escape post-renderer compromise in Chrome Android <151.0.7922.72secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAGoogle Chrome <151.0.7922.72 favicon implementation leaks cross-origin data via crafted HTML pagesecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome WebNN uninitialized use on Windows <151.0.7922.72 leaks cross-origin data via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome Network cross-origin data leak via crafted HTML before 151.0.7922.72secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome <151.0.7922.72 WebMCP policy flaw enables remote same-origin policy bypass via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome <151.0.7922.72 DevTools: compromised renderer injects script/HTML into privileged pagessecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome Media Router pre-151.0.7922.72 Same-Origin Policy bypass via crafted HTML by remote attackersecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAPre-151.0.7922.72 Chrome Autofill side-channel leak enables cross-origin exfiltration via compromised renderersecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome Permissions bug pre-151.0.7922.72 enables same-origin policy bypass via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome iOS <151.0.7922.72 Omnibox spoofing via malicious network trafficsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome Windows Media bug pre-151.0.7922.72 allows compromised renderer to bypass same-origin policy via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome <151.0.7922.72 CSS UXSS allows remote script/HTML injection via crafted pagesecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAPre-151.0.7922.72 Chrome Cast input validation allowed local attacker to leak cross-origin datasecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome CSS flaw before 151.0.7922.72 leaks cross-origin data via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome iOS <151.0.7922.72 SOP bypass via crafted HTML requiring specific user gesturessecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome iOS race allows remote UI spoofing via crafted HTML before 151.0.7922.72secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAGoogle Chrome Passwords UI flaw enables domain spoofing via crafted HTML (pre-151.0.7922.72)secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAUI spoofing vulnerability in Chrome for iOS before 151.0.7922.72 via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome iOS pre-151.0.7922.72 incorrect security UI enables domain spoofing via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome for iOS <151.0.7922.72 allows remote UI spoofing via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAGoogle Chrome Passwords pre-151.0.7922.72 cross-origin data leak via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAInsufficient validation of untrusted input in Chrome Passwords allows UI spoofing by compromised renderersecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome for iOS <151.0.7922.72 navigation restriction bypass via crafted HTML by remote attackersecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome Passwords vulnerability pre-151.0.7922.72 leaks cross-origin data via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAGoogle Chrome for iOS <151.0.7922.72 allows UI spoofing via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome CSS bug before 151.0.7922.72 enables UXSS via crafted HTML pagesecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome Android <151.0.7922.72 Passwords policy bug allows discretionary access control bypass via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAInsufficient ServiceWorker policy enforcement enabled same-origin policy bypass in Google Chrome pre-151.0.7922.72 via crafted HTMLsecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome <151.0.7922.72 WebXR policy enforcement flaw enables same-origin policy bypasssecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome iOS race condition allows remote UI spoofing via crafted HTML pre-151.0.7922.72secure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAChrome before 151.0.7922.72 extension policy flaw enables bypass of navigation restrictionssecure-packages-26.05Aug 4, 2026Sep 18, 2026Aug 4, 2026same day