← All tracked CVEs
Updated 12:00
last 30 days
933 fixed within SLA
| CVE | Status | Severity | Summary | Release | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|---|
| Fixed within SLA | Medium | Chrome Blink flaw lets remote attacker leak cross-origin data via crafted HTML pre-151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Low | Chrome Android <151.0.7922.72 UI flaw enables cross-origin data leak via crafted page | secure-packages-26.05 | Aug 4, 2026 | Nov 2, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | V8 race condition in Chrome <151.0.7922.72 enables remote code execution in sandbox via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome WebCodecs side-channel exposes sensitive process memory via crafted HTML (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome prior to 151.0.7922.72 CSS policy bypass leaks cross-origin data via crafted HTML page | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Extensions policy flaw allows DAC bypass via crafted domains (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Mac IME pre-151.0.7922.72 flaw allows remote process memory disclosure via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome <151.0.7922.72 DevTools policy flaw lets local attacker bypass navigation restrictions via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome Mac Views flaw allows local memory disclosure via crafted HTML pre-151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome iOS pre-151.0.7922.72 permits UI spoofing via crafted HTML page | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome <151.0.7922.72 Frame implementation allows remote OOB memory access via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome <151.0.7922.72 Passwords lacks input validation, enabling UI spoofing by privileged network attacker | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Google Chrome Passwords prior to 151.0.7922.72 allows remote sandbox RCE via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | WebXR uninitialized use leaks process memory in Chrome Android before 151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Use-after-free in Chrome iOS pre-151.0.7922.72 enables remote heap corruption via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Mac Chrome Views bug allowed local process memory disclosure via crafted HTML prior to 151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome iOS <151.0.7922.72: Incorrect security UI allows remote HTML UI spoofing | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Incorrect security UI on Chrome Android pre-151.0.7922.72 enables domain spoofing via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome <151.0.7922.72 SVG bug allows cross-origin data leak via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Blink UXSS in Chrome <151.0.7922.72 allows remote script/HTML injection via crafted page | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Android pre-151.0.7922.72 Session bug allows remote bypass of navigation restrictions via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Insufficient policy enforcement enables no-referrer bypass via crafted HTML in Chrome iOS <151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Network vulnerability leaked cross-origin data via crafted HTML page pre-151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome pre-151.0.7922.72 Views flaw enables remote UI spoofing via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Low | Low-severity CORS flaw in Chrome <151.0.7922.72 enables cross-origin leak via compromised renderer | secure-packages-26.05 | Aug 4, 2026 | Nov 2, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome pre-151.0.7922.72 Scheduling flaw enables sandbox RCE via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Insufficient input validation in Chrome Payments allows UI spoofing via crafted HTML (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Policy bypass in Chrome MHTML before 151.0.7922.72 leaks cross-origin data | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Android Chrome WebView policy enforcement bug allows navigation bypass via crafted HTML before 151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome V8 pre-151.0.7922.72 allows sandbox code execution via malicious extension | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Google Chrome WebRTC heap buffer overflow enables remote out-of-bounds read via crafted HTML pre-151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome Mac Safe Browsing bug pre-151.0.7922.72 allows RCE via malicious file | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Uninitialized GPU use in Chrome Android pre-151.0.7922.72 leaks cross-origin data via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome V8 type confusion enables sandboxed code execution via malicious extension (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Chrome <151.0.7922.72 WebSockets use-after-free allows remote sandbox escape via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome <151.0.7922.72 Dawn uninitialized use leaks process memory via crafted HTML when renderer compromised | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Insufficient Navigation input validation in Chrome <151.0.7922.72 allows UI spoofing post-renderer compromise | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome for iOS <151.0.7922.72 allows navigation restriction bypass via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome <151.0.7922.72 parser flaw allows CSP bypass via crafted HTML page | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Cross-origin data leak via SVG side-channel in Google Chrome before 151.0.7922.72 using crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Omnibox URL spoofing in Chrome for iOS before 151.0.7922.72 via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Chrome Android PiP input validation bug enables sandbox escape post-renderer compromise via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Insufficient untrusted input validation in Chrome Passwords enables UI spoofing via network traffic (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Android pre-151.0.7922.72 FullScreen flaw enables remote UI spoofing via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome DevTools vulnerability before 151.0.7922.72 enables bypass of navigation restrictions via crafted HTML with gestures | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Heap buffer overflow in Chrome Codecs enables sandboxed RCE via crafted HTML (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome DevTools insufficient validation of untrusted input enabled navigation restriction bypass via crafted HTML pre-151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome DOMStorage vulnerability allowed remote cross-origin data leak via crafted HTML page pre-151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Windows DataTransfer use-after-free leaks process memory via crafted HTML pre-151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome DevTools navigation restriction bypass via crafted HTML page (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day |