← All tracked CVEs
Updated 08:00
last 30 days
933 fixed within SLA
| CVE | Status | Severity | Summary | Release | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|---|
| Fixed within SLA | Medium | Insufficient input validation in Chrome Payments pre-151.0.7922.72 enables UI spoofing from compromised renderer | secure-packages-26.05 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome iOS pre-151.0.7922.72: Untrusted input validation flaw enables remote navigation restrictions bypass | secure-packages-26.05 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Blink cross-origin data leak via crafted HTML in Chrome before 151.0.7922.72 | secure-packages-26.05 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome DevTools SOP bypass via crafted HTML before 151.0.7922.72; remote attacker, Medium | secure-packages-26.05 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | High | Insufficient DevTools input validation in Chrome allows privilege escalation via crafted extension (<151.0.7922.72) | secure-packages-26.05 | Aug 5, 2026 | Aug 20, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | ANGLE uninitialized use in Chrome <151.0.7922.72 enables cross-origin data leak via crafted HTML page | secure-packages-26.05 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | High | Chrome Mac Audio use-after-free enables sandbox escape pre-151.0.7922.72 via crafted HTML | secure-packages-26.05 | Aug 5, 2026 | Aug 20, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Pre-151.0.7922.72 Chrome Loader leaks cross-origin data via crafted HTML | secure-packages-26.05 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome iOS prior to 151.0.7922.72 Omnibox spoofing via crafted HTML (incorrect security UI) | secure-packages-26.05 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome Isolated Web Apps allowed remote bypass of navigation restrictions via crafted HTML pre-151.0.7922.72 | secure-packages-26.05 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Google Chrome Site Isolation bypass before 151.0.7922.72 via crafted HTML page | secure-packages-26.05 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome Autofill flaw pre-151.0.7922.72 enables remote cross-origin data leak via crafted HTML | secure-packages-26.05 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Receiver policy bypass in Chrome pre-151.0.7922.72 enables sandbox escape from compromised renderer via crafted HTML | secure-packages-26.05 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | PresentationAPI in Chrome <151.0.7922.72 leaked cross-origin data via crafted HTML page | secure-packages-26.05 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | High | Insufficient input validation in Chrome Variations pre-151.0.7922.72 allows heap corruption by privileged network attacker | secure-packages-26.05 | Aug 5, 2026 | Aug 20, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Google Chrome Cast input validation flaw leaks cross-origin data via crafted HTML | secure-packages-26.05 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | WebGL out-of-bounds read in Chrome pre-151.0.7922.72 allows remote memory disclosure | secure-packages-26.05 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Skia uninitialized use in Chrome <151.0.7922.72 leaks cross-origin data via crafted HTML | secure-packages-26.05 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome Mac Media out-of-bounds read allows sandbox escape after renderer compromise pre-151.0.7922.72 | secure-packages-26.05 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Insufficient untrusted input validation in Chrome Cast enables cross-origin data leak via crafted HTML (pre-151.0.7922.72) | secure-packages-26.05 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Critical | WebSockets input validation flaw enables sandbox escape from compromised renderer in Chrome <151.0.7922.72 | secure-packages-26.05 | Aug 5, 2026 | Aug 12, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Android Chrome WebView untrusted input validation flaw leaks cross-origin data via compromised renderer pre-151.0.7922.72 | secure-packages-26.05 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | FedCM SOP bypass in Chrome prior to 151.0.7922.72 via crafted HTML page | secure-packages-26.05 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome for iOS <151.0.7922.72 cross-origin data leak via crafted HTML page | secure-packages-26.05 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome iOS <151.0.7922.72 UXSS from insufficient validation of untrusted network input | secure-packages-26.05 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome pre-151.0.7922.72 Presentation policy flaw enables remote navigation bypass via crafted HTML | secure-packages-26.05 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Google Chrome pre-151 Extensions UI security flaw enables malicious extension-based UI spoofing | secure-packages-26.05 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Blink same-origin policy bypass in Chrome before 151.0.7922.72 via crafted HTML | secure-packages-26.05 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | High | Chrome Network input validation flaw enables sandbox escape from compromised renderer via HTML | secure-packages-26.05 | Aug 7, 2026 | Aug 22, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | Medium | Site Isolation bypass in Chrome <151.0.7922.72 via crafted HTML after renderer compromise | secure-packages-26.05 | Aug 7, 2026 | Sep 21, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | High | High severity V8 use-after-free enables sandboxed RCE via crafted HTML in Chrome <151.0.7922.72 | secure-packages-26.05 | Aug 7, 2026 | Aug 22, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | High | Chrome <151.0.7922.72 Navigation use-after-free enables sandbox escape via crafted HTML | secure-packages-26.05 | Aug 7, 2026 | Aug 22, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | Critical | Critical Chrome Ozone use-after-free enables remote sandbox escape via crafted HTML before 151.0.7922.72 | secure-packages-26.05 | Aug 7, 2026 | Aug 14, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | Critical | Critical ANGLE input validation flaw enables sandbox escape via crafted HTML (Chrome <151.0.7922.72) | secure-packages-26.05 | Aug 7, 2026 | Aug 14, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | High | Race in macOS Chrome Updater allows local privilege escalation before 151.0.7922.72 via malicious file | secure-packages-26.05 | Aug 7, 2026 | Aug 22, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | High | Skia use-after-free enables sandbox escape via crafted HTML in Chrome <151.0.7922.72 | secure-packages-26.05 | Aug 7, 2026 | Aug 22, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | Critical | Use-after-free in Views enables sandbox escape on Chrome before 151.0.7922.72 via crafted HTML | secure-packages-26.05 | Aug 7, 2026 | Aug 14, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | High | Use-after-free in Chrome Compositing allows sandbox escape from compromised renderer via HTML (pre-151.0.7922.72) | secure-packages-26.05 | Aug 7, 2026 | Aug 22, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | High | FFmpeg ADX decoder OOB read/write on mid-stream extradata channel change (v4.4–8.1.2) | secure-packages-rolling | Jul 29, 2026 | Aug 13, 2026 | Aug 11, 2026 | 13 days | |
| Fixed within SLA | High | FFmpeg 0.6.3–8.1.2 RTP/ASF demuxer infinite loop DoS in rtp_asf_fix_header | secure-packages-rolling | Jul 29, 2026 | Aug 13, 2026 | Aug 11, 2026 | 13 days | |
| Fixed within SLA | High | FFmpeg 0.7.1–8.1.2 S/PDIF muxer out-of-bounds read via crafted DTS core_size | secure-packages-rolling | Jul 29, 2026 | Aug 13, 2026 | Aug 11, 2026 | 13 days | |
| Fixed within SLA | High | FFmpeg 4.4–8.1.2 NVDEC double-free enables memory corruption via crafted video files | secure-packages-rolling | Jul 29, 2026 | Aug 13, 2026 | Aug 11, 2026 | 13 days | |
| Fixed within SLA | High | FFmpeg 8.0-8.1.2 Vulkan HEVC decoder stack buffer overflow enables remote code execution | secure-packages-rolling | Jul 29, 2026 | Aug 13, 2026 | Aug 11, 2026 | 13 days | |
| Fixed within SLA | High | FFmpeg 2.1-8.1.2 VobSub demuxer heap overflow from .sub/.idx with excessive stream IDs | secure-packages-rolling | Jul 29, 2026 | Aug 13, 2026 | Aug 11, 2026 | 13 days | |
| Fixed within SLA | Medium | Partial IO fetch leaves canceled flags set, blocking ublk io_uring cancel completion | secure-packages-rolling | Jul 27, 2026 | Sep 10, 2026 | Aug 11, 2026 | 15 days | |
| Fixed within SLA | Medium | powerpc/64s race between move_pages PMD migration and munmap hits VM_BUG_ON in pmdp_huge_get_and_clear_full | secure-packages-rolling | Jul 27, 2026 | Sep 10, 2026 | Aug 11, 2026 | 15 days | |
| Fixed within SLA | High | Use-after-free when querying offloaded BPF map/prog due to netns teardown race | secure-packages-rolling | Jul 27, 2026 | Aug 11, 2026 | Aug 11, 2026 | 15 days | |
| Fixed within SLA | Medium | ice: race between ice_free_tx_tstamp_ring and ice_tx_map causes NULL deref | secure-packages-rolling | Jul 16, 2026 | Aug 30, 2026 | Aug 11, 2026 | 26 days | |
| Fixed within SLA | Medium | ice: Potential NULL dereference in ice_set_ringparam() error path with TXTIME flag set | secure-packages-rolling | Jul 16, 2026 | Aug 30, 2026 | Aug 11, 2026 | 26 days | |
| Fixed within SLA | Medium | ublk I/O cancellation may never complete due to stale per-IO canceled flag after partial fetch | secure-packages-26.05 | Jul 27, 2026 | Sep 10, 2026 | Aug 11, 2026 | 15 days |