← All tracked CVEs
Updated 13:00
last 30 days
910 fixed within SLA
| CVE | Status | Severity | Summary | Release | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|---|
| Fixed within SLA | Medium | Chrome <151.0.7922.72 CSS bug enables UXSS via crafted HTML page | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Pre-151.0.7922.72 Chrome Payments bug leaks cross-origin data via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | PDFium use-after-free enables sandboxed RCE via crafted PDF in Chrome <151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome for iOS before 151.0.7922.72 allows UI spoofing via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | iOS Chrome <151.0.7922.72: insufficient policy enforcement enables HTML-based discretionary access control bypass | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Cryptographic flaw in WebAppInstalls allows local sandbox escape via crafted HTML in Android Chrome pre-151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Pre-151.0.7922.72 Chrome Passwords cross-origin data leak via crafted page, UI gestures | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Cast pre-151.0.7922.72 insufficient input validation leaks cross-origin data on LAN | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome <151.0.7922.72 WebXR out-of-bounds read enables remote memory disclosure | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome USB policy enforcement bug (<151.0.7922.72) allows remote privilege escalation via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Insufficient input validation in Chrome Dawn allows remote sandbox escape via crafted HTML page | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Type confusion in Tab allows sandbox escape post-renderer compromise in Chrome Android <151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Google Chrome Mac Crypto bug allows sandbox escape from compromised renderer via crafted HTML pre-151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome Mac Updater pre-151.0.7922.72 local OS-level privilege escalation via malicious file | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome Windows pre-151.0.7922.72: Local privilege escalation via malicious file | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome Windows Tracing use-after-free allows local privilege escalation via malicious file (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Insufficient input validation in Chrome Updater allows local privilege escalation via malicious file (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Low | Android Chrome <151.0.7922.72: Omnibox spoofing via malicious local file; insufficient input validation | secure-packages-26.05 | Aug 4, 2026 | Nov 2, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome <151.0.7922.72 favicon implementation leaks cross-origin data via crafted HTML page | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome WebNN uninitialized use on Windows <151.0.7922.72 leaks cross-origin data via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Network cross-origin data leak via crafted HTML before 151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Chrome Mac pre-151.0.7922.72 network flaw enables sandbox escape via crafted HTML after renderer compromise | secure-packages-26.05 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | DevTools race on Mac Chrome pre-151.0.7922.72 enables sandbox escape from compromised renderer | secure-packages-26.05 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome <151.0.7922.72 WebMCP policy flaw enables remote same-origin policy bypass via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome <151.0.7922.72 DevTools: compromised renderer injects script/HTML into privileged pages | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Media Router pre-151.0.7922.72 Same-Origin Policy bypass via crafted HTML by remote attacker | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Pre-151.0.7922.72 Chrome Autofill side-channel leak enables cross-origin exfiltration via compromised renderer | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Permissions bug pre-151.0.7922.72 enables same-origin policy bypass via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome iOS <151.0.7922.72 Omnibox spoofing via malicious network traffic | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Integer overflow in Google Chrome Codecs enables remote sandbox escape via crafted video pre-151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | ANGLE input validation flaw allows sandbox escape via crafted HTML in Chrome <151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Windows Media bug pre-151.0.7922.72 allows compromised renderer to bypass same-origin policy via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome <151.0.7922.72 CSS UXSS allows remote script/HTML injection via crafted page | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Pre-151.0.7922.72 Chrome Cast input validation allowed local attacker to leak cross-origin data | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome CSS flaw before 151.0.7922.72 leaks cross-origin data via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome iOS <151.0.7922.72 SOP bypass via crafted HTML requiring specific user gestures | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome iOS race allows remote UI spoofing via crafted HTML before 151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome Passwords UI flaw enables domain spoofing via crafted HTML (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | UI spoofing vulnerability in Chrome for iOS before 151.0.7922.72 via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome iOS pre-151.0.7922.72 incorrect security UI enables domain spoofing via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Chrome DevTools untrusted input validation flaw enables sandbox escape via crafted HTML (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome <151.0.7922.72 V8 use-after-free enables sandboxed remote code execution via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome for iOS <151.0.7922.72 allows remote UI spoofing via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Chrome Passwords validation flaw enables sandbox escape from compromised renderer via crafted HTML (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome Passwords pre-151.0.7922.72 cross-origin data leak via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Use-after-free in ANGLE allows sandbox escape in Google Chrome pre-151.0.7922.72 via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Insufficient validation of untrusted input in Chrome Passwords allows UI spoofing by compromised renderer | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome for iOS <151.0.7922.72 navigation restriction bypass via crafted HTML by remote attacker | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Passwords vulnerability pre-151.0.7922.72 leaks cross-origin data via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome for iOS <151.0.7922.72 allows UI spoofing via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day |