← All tracked CVEs
Updated 07:01
241 fixed in the last 7 days
| CVE | Status | Severity | Summary | Distribution | Fixed |
|---|---|---|---|---|---|
| Fixed | Critical | Chrome Core use-after-free enables RCE outside sandbox via crafted HTML (pre-153.0.8010.47) | secure-packages-rolling | Sep 18, 2026 | |
| Fixed | Medium | Chrome Android pre-153.0.8010.47 missing auth lets co-installed app read sensitive data | secure-packages-rolling | Sep 18, 2026 | |
| Fixed | Critical | Use-after-free in Chrome Auth <153.0.8010.47 enables RCE outside sandbox via crafted HTML | secure-packages-rolling | Sep 18, 2026 | |
| Fixed | High | Chrome ServiceWorker type confusion enables remote sandbox RCE via crafted HTML (pre-153.0.8010.47) | secure-packages-rolling | Sep 18, 2026 | |
| Fixed | Medium | Google Chrome Fonts discrepancy before 153.0.8010.47 leaks sensitive data via crafted HTML, social engineering | secure-packages-rolling | Sep 18, 2026 | |
| Fixed | Medium | Chrome <153.0.8010.47 missing authorization enables UI spoofing from compromised renderer via crafted HTML | secure-packages-rolling | Sep 18, 2026 | |
| Fixed | High | Mac Chrome <153.0.8010.47 Extensions race allows code execution outside sandbox via crafted HTML | secure-packages-rolling | Sep 18, 2026 | |
| Fixed | High | Out-of-bounds write in Chrome ServiceWorker enables sandbox RCE via crafted HTML (<153.0.8010.47) | secure-packages-rolling | Sep 18, 2026 | |
| Fixed | Critical | Use-after-free in Chrome WebAppInstalls allows RCE outside sandbox via crafted HTML pre-153.0.8010.47 | secure-packages-rolling | Sep 18, 2026 | |
| Fixed | High | Chrome ServiceWorker type confusion pre-153.0.8010.47 enables remote sandbox RCE via crafted HTML | secure-packages-rolling | Sep 18, 2026 | |
| Fixed | Low | Google Chrome <153.0.8010.47 Network race enables cross-origin data leak via compromised renderer | secure-packages-rolling | Sep 18, 2026 | |
| Fixed | High | Race condition in Chrome macOS Extensions pre-153.0.8010.47 enables sandbox escape via UI interaction | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | Low | Skia use-after-free in Chrome <153.0.8010.47 enables compromised renderer cross-origin data exfiltration | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | Medium | Chrome pre-153.0.8010.47 Compositing integer overflow leaks cross-origin data via crafted HTML | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | High | Chrome V8 use-after-free pre-153.0.8010.47 enables sandboxed remote code execution via HTML | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | Medium | Chrome Mac pre-153.0.8010.47 PlatformIntegration race enables data exfiltration via crafted HTML after renderer compromise | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | High | Chrome before 153.0.8010.47 Core race condition enables sandbox-escape RCE via crafted HTML | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | High | Type confusion in Chrome CacheStorage allows sandbox RCE via crafted HTML (pre-153.0.8010.47) | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | Medium | Uninitialized resource in Skia allows cross-origin data exfiltration in Chrome before 153.0.8010.47 via crafted HTML | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | Medium | Chrome <153.0.8010.47 Transactions Platform missing authorization enables UI spoofing via compromised renderer and crafted HTML | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | Critical | ANGLE input validation flaw in Chrome <153.0.8010.47 enables remote code execution outside sandbox | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | High | Use-after-free in Chrome PDF allows sandboxed RCE via crafted HTML pre-153.0.8010.47 | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | High | Use-after-free in Chrome DOM before 153.0.8010.47 allows sandboxed RCE via crafted HTML | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | High | Chrome <153.0.8010.47 WebUI auth flaw enables RCE outside sandbox from compromised renderer | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | High | Windows Chrome Core auth bug pre-153.0.8010.47 allows local sandbox escape code execution | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | High | Chrome Skia state validation bug allows reading outside sandbox via crafted HTML (pre-153.0.8010.47) | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | High | Type confusion in Chrome Compositing allows sandboxed RCE via crafted HTML (pre-153.0.8010.47) | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | Low | GetUserMedia cleanup bug enables cross-origin data leak in Chrome before 153.0.8010.47 | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | Critical | Use-after-free in Chrome DigitalCredentials enables remote code execution outside sandbox via crafted HTML (pre-153.0.8010.47) | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | Critical | Chrome V8 integer overflow pre-153.0.8010.47 enables remote sandbox RCE via HTML | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | High | Incorrect Extensions reference resolution in Chrome for Mac pre-153.0.8010.47 enables sandbox RCE | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | Medium | Critical WebGL out-of-bounds read in Chrome Android <153.0.8010.47 enables remote sandbox memory disclosure | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | Medium | Google Chrome <153.0.8010.47 CSS discrepancy allows remote sensitive info leak via crafted HTML | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | High | Chrome Input use-after-free enables renderer-compromise sandbox escape RCE via crafted HTML (pre-153.0.8010.47) | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | High | Chrome Input use-after-free enables remote code execution outside sandbox via crafted HTML prior to 153.0.8010.47 | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | High | Critical use-after-free in Chrome Internals pre-153.0.8010.47 enables sandbox-escape RCE via crafted HTML | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | Medium | Uninitialized ANGLE resource in Chrome <153.0.8010.47 enables remote out-of-sandbox memory read via crafted HTML page | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | Critical | Chrome Core use-after-free before 153.0.8010.47 allows RCE outside sandbox via crafted HTML | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | Medium | Chrome Android <153.0.8010.47 missing authorization leaks sensitive data via local co-installed app | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | Critical | Chrome pre-153.0.8010.47 Auth use-after-free allows remote code execution outside sandbox | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | High | ServiceWorker type confusion permits sandboxed code execution via crafted HTML in Chrome <153.0.8010.47 | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | Medium | Google Chrome pre-153.0.8010.47 font rendering discrepancy allows crafted HTML sensitive data leak via social engineering | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | Medium | Missing authorization in Chrome before 153.0.8010.47 enables compromised renderer to spoof UI via crafted HTML | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | High | Google Chrome Mac Extensions race condition enables sandbox escape and RCE pre-153.0.8010.47 | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | High | Chrome ServiceWorker out-of-bounds write before 153.0.8010.47 allows sandboxed RCE via crafted HTML | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | Critical | Pre-153.0.8010.47 Chrome WebAppInstalls use-after-free allows RCE outside sandbox via crafted HTML | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | High | Chrome ServiceWorker type confusion allowed sandboxed RCE via crafted HTML (pre-153.0.8010.47) | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | Low | Chrome <153.0.8010.47 network race condition leaks cross-origin data from compromised renderer process | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | Critical | PLY 3.11 PyPI: Undocumented yacc() picklefile enables RCE via unsafe pickle deserialization | secure-packages-26.05 | Sep 18, 2026 | |
| Fixed | High | GitPython <3.1.60 ReDoS via Actor.name_email_regex on malformed commit author fields causing CPU exhaustion | secure-packages-26.05 | Sep 18, 2026 |