← All tracked CVEs
Updated 11:00
last 30 days
933 fixed within SLA
| CVE | Status | Severity | Summary | Release | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|---|
| Fixed within SLA | Medium | Insufficient WebView input validation in Android Chrome leaks cross-origin data after renderer compromise | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | Chrome FedCM same-origin policy bypass by remote attacker via crafted HTML prior to 151.0.7922.72 | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome on iOS before 151.0.7922.72 leaks cross-origin data via crafted HTML page | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | Chrome iOS <151.0.7922.72 UXSS via insufficient validation of untrusted network input | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | Insufficient policy enforcement in Chrome Presentation pre-151.0.7922.72 allows remote navigation bypass via crafted HTML | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | Chrome pre-151.0.7922.72 Extensions security UI flaw enables UI spoofing via crafted extension | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | Blink SOP bypass via crafted HTML in Chrome before 151.0.7922.72 | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | High | FFmpeg 4.4–8.1.2 ADX decoder OOB read/write on mid-stream channel layout change | secure-packages-25.11 | Jul 29, 2026 | Aug 13, 2026 | Aug 5, 2026 | 7 days | |
| Fixed within SLA | High | FFmpeg 0.6.3–8.1.2 RTP/ASF demuxer infinite loop DoS on crafted stream | secure-packages-25.11 | Jul 29, 2026 | Aug 13, 2026 | Aug 5, 2026 | 7 days | |
| Fixed within SLA | High | FFmpeg 0.7.1–8.1.2 S/PDIF muxer out-of-bounds read via crafted DTS core_size | secure-packages-25.11 | Jul 29, 2026 | Aug 13, 2026 | Aug 5, 2026 | 7 days | |
| Fixed within SLA | High | FFmpeg 4.4–8.1.2 NVDEC nvdec.c double-free allows memory corruption via crafted video | secure-packages-25.11 | Jul 29, 2026 | Aug 13, 2026 | Aug 5, 2026 | 7 days | |
| Fixed within SLA | High | FFmpeg 8.0–8.1.2 Vulkan HEVC decoder stack buffer overflow via oversized vps_num_hrd_parameters causing RCE | secure-packages-25.11 | Jul 29, 2026 | Aug 13, 2026 | Aug 5, 2026 | 7 days | |
| Fixed within SLA | High | FFmpeg 2.1–8.1.2 VobSub demuxer heap overflow via crafted .sub/.idx stream IDs | secure-packages-25.11 | Jul 29, 2026 | Aug 13, 2026 | Aug 5, 2026 | 7 days | |
| Fixed within SLA | Critical | glibc scanf %mc width >1024 triggers 1-byte heap overflow in v2.7-2.43 | secure-packages-26.05 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Side-channel leak in Chrome Media exposes cross-origin data via crafted HTML (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome <151.0.7922.72 Dawn use-after-free enables sandboxed RCE via crafted HTML, low severity | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome iOS <151.0.7922.72: Insufficient policy enforcement allows remote UI spoofing via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Insufficient input validation in Chrome DevTools pre-151.0.7922.72 allows navigation bypass via malicious file | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome for iOS prior to 151.0.7922.72 UI spoofing via crafted HTML page | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome <151.0.7922.72: PDFium use-after-free enables sandboxed code execution via crafted PDF | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Low | Chrome for iOS <151.0.7922.72 exposes process memory to local physical attacker | secure-packages-26.05 | Aug 4, 2026 | Nov 2, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Passwords pre-151.0.7922.72 enables remote UI spoofing via malicious network traffic | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Passwords pre-151.0.7922.72 untrusted input validation flaw enables remote UI spoofing via malicious network traffic | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome Settings bug before 151.0.7922.72 allowed remote UI spoofing via malicious traffic | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Input implementation flaw in Chrome Android <151.0.7922.72 enables remote UI spoofing via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Google Lens in Chrome <151.0.7922.72 enables UI spoofing via crafted HTML after renderer compromise | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome WebXR info disclosure from process memory via crafted HTML pre-151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Insufficient Speech API policy in Chrome <151.0.7922.72 enables compromised renderer cross-origin data leak | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | UI spoofing vulnerability in Chrome iOS <151.0.7922.72 via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Chrome Google Lens insufficient input validation allows renderer sandbox escape via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Pre-151.0.7922.72 Chrome WebGL bug exposes process memory via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Low | Chrome Android USB policy flaw prior to 151.0.7922.72 leaks cross-origin data via compromised renderer | secure-packages-26.05 | Aug 4, 2026 | Nov 2, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Android pre-151.0.7922.72 PIP race enables remote domain spoofing via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome <151.0.7922.72: Incorrect Extensions security UI enables malicious extension UI spoofing | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Low | Chrome Passwords <151.0.7922.72 cross-origin data leak via renderer-compromised crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Nov 2, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Mac pre-151.0.7922.72 local attacker bypasses navigation restrictions via malicious file | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Remote out-of-bounds memory read in Chrome Dawn via crafted HTML before 151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Remote attacker could bypass navigation restrictions via Media in Chrome Android <151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Race in Chrome Updater on Windows allows local privilege escalation pre-151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Skia uninitialized use in Chrome Windows leaks process memory via crafted HTML (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Chrome <151.0.7922.72 AI input validation bug enables sandbox escape from compromised renderer via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Chrome WebAuthn input validation flaw allows sandbox escape via PDF (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome <151.0.7922.72 V8 type confusion allows sandboxed code execution via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome <151.0.7922.72 Navigation input validation flaw lets compromised renderer bypass restrictions via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Chrome Notifications validation flaw enables sandbox escape via crafted PDF after renderer compromise (pre-151) | secure-packages-26.05 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome pre-151.0.7922.72 Bluetooth policy bug allows same-origin policy bypass via crafted HTML from compromised renderer | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome pre-151 Speech policy bug enables remote site isolation bypass via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Low | Chrome Android <151.0.7922.72 cross-origin data leak via crafted HTML, local attacker | secure-packages-26.05 | Aug 4, 2026 | Nov 2, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | UI spoofing in Chrome Global Media Controls via crafted HTML before 151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Insufficient input validation in Chrome Cast allowed same-origin policy bypass via crafted HTML pre-151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day |