← All tracked CVEs
Updated 14:00
last 30 days
910 fixed within SLA
| CVE | Status | Severity | Summary | Release | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|---|
| Fixed within SLA | Medium | Chrome CSS bug before 151.0.7922.72 enables UXSS via crafted HTML page | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Low | Chrome for iOS <151.0.7922.72 cross-origin data leak via crafted HTML and UI gestures Medium severity | secure-packages-26.05 | Aug 4, 2026 | Nov 2, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Android <151.0.7922.72 Passwords policy bug allows discretionary access control bypass via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Insufficient ServiceWorker policy enforcement enabled same-origin policy bypass in Google Chrome pre-151.0.7922.72 via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome <151.0.7922.72 WebXR policy enforcement flaw enables same-origin policy bypass | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome iOS race condition allows remote UI spoofing via crafted HTML pre-151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome before 151.0.7922.72 extension policy flaw enables bypass of navigation restrictions | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome pre-151.0.7922.72 Autofill policy flaw leaked cross-origin data via crafted pages | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome <151.0.7922.72 WebAppInstalls vulnerability allows remote UI spoofing via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Remote UXSS via crafted HTML in Chrome <151.0.7922.72 Network component | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Pre-151.0.7922.72 Chrome ReportingAndNEL cross-origin data leak via crafted HTML page | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Android Chrome Speech policy enforcement bug enables compromised renderer privilege escalation via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome GuestView insufficient policy enforcement enables cross-origin data leak pre-151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | iOS Chrome input validation flaw bypasses navigation restrictions via crafted HTML, pre-151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Policy enforcement flaw allows navigation bypass in Chrome for iOS <151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome <151.0.7922.72 DigitalCredentials flaw enables remote UI spoofing via crafted HTML page | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Use-after-free in Chrome ANGLE on Windows allows sandbox escape via crafted HTML (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Dawn uninitialized use leaks cross-origin data via crafted HTML, pre-151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Extensions input validation bug enables sandbox escape via crafted HTML after renderer compromise (<151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | WebGL uninitialized use leaks cross-origin data in Chrome Android before 151.0.7922.72 via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome V8 use-after-free enables sandboxed RCE via crafted HTML before 151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome Extensions pre-151.0.7922.72 input validation flaw enables renderer sandbox escape | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Insufficient Glic policy enforcement in Chrome Android <151.0.7922.72 allows remote navigation bypass via HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Use-after-free in Chrome Media enables sandbox escape via crafted HTML (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Chrome pre-151 Save to Drive input validation bug enabling renderer sandbox escape via crafted PDF | secure-packages-26.05 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | ANGLE out-of-bounds read/write allows remote attacker sandbox escape via crafted HTML in Chrome <151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Pre-151.0.7922.72 Chrome MediaRecording bug leaks process memory via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Safe Browsing input validation bug pre-151.0.7922.72 enables DAC bypass via malicious file | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome WebXR side-channel leak exposes process memory via crafted HTML (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Insufficient input validation enables Chrome Android pre-151.0.7922.72 Omnibox spoofing via crafted HTML after renderer compromise | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Remote UI spoofing via crafted HTML in Chrome Android Messages pre-151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Windows ANGLE uninitialized use leaks process memory via crafted HTML pre-151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome prior to 151.0.7922.72 extension flaw allows malicious extensions to leak cross-origin data | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Use-after-free in Chrome Extensions pre-151.0.7922.72 enables sandboxed arbitrary code execution | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Low | Android Chrome Clipboard validation flaw prior to 151.0.7922.72 leaks cross-origin data locally | secure-packages-26.05 | Aug 4, 2026 | Nov 2, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome WebProtect bug pre-151.0.7922.72 lets compromised renderer leak cross-origin data via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome <151.0.7922.72 GPU bug allows cross-origin data leak after renderer compromise via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome pre-151.0.7922.72 NoStatePrefetch side-channel allowed remote cross-origin data leaks via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome <151.0.7922.72 Codecs uninitialized use leaks memory via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Dawn heap buffer overflow in Chrome <151.0.7922.72 enables potential remote sandbox escape via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Skia uninitialized use allows cross-origin data leak via crafted HTML (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Autofill vulnerability pre-151.0.7922.72: remote cross-origin data leak via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Use-after-free in Chrome Views on Mac pre-151.0.7922.72 enables remote heap corruption via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Google Chrome AdFilter sandbox RCE via crafted HTML before 151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome pre-151.0.7922.72 ANGLE use-after-free allows remote sandbox escape via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Insufficient input validation in Chrome Android Payments enables UI spoofing via compromised renderer | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Mac GPU use-after-free allows sandbox escape from compromised renderer via crafted HTML (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Skia out-of-bounds read enables sandbox escape after renderer compromise, Chrome <151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome Linux File Input vulnerability enables remote sandbox escape via crafted HTML (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Payments insufficient policy enforcement allows cross-origin data leak via crafted HTML page | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day |