Chromium: CVE-2026-16424 Use after free in GPU
Incorrect reference resolution in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Buffer overflow in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-19146 Uninitialized Use in GPU
Race condition in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a co-installed app. (Chromium security severity: High)
Chromium: CVE-2026-17722 Object lifecycle issue in WebView
Chromium: CVE-2026-13852 Insufficient validation of untrusted input in WebAppInstalls
Chromium: CVE-2026-12442 Use after free in Passwords
Chromium: CVE-2026-12469 Uninitialized Use in GPU
Chromium: CVE-2026-14428 Insufficient validation of untrusted input in Dawn
Chromium: CVE-2026-17860 Insufficient validation of untrusted input in Mobile
Chromium: CVE-2026-17866 Type Confusion in Tab
Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
Chromium: CVE-2026-13282 Use after free in AdFilter
Chromium: CVE-2026-17953 Insufficient policy enforcement in WebView
Improper input validation in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
UI misrepresentation in FullScreen in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)
Chromium: CVE-2026-17808 Uninitialized Use in WebGL
Chromium: CVE-2026-78977 Uninitialized resource in GPU
Chromium: CVE-2026-12452 Use after free in Downloads
Use after free in WebMIDI in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Chromium: CVE-2026-14005 Use after free in Omnibox
Chromium: CVE-2026-17802 Side-channel information leakage in GPU
Chromium: CVE-2026-13997 Incorrect security UI in Extensions
Chromium: CVE-2026-13994 Inappropriate implementation in Credential Management
Chromium: CVE-2026-14129 Incorrect security UI in PreviewTab
Chromium: CVE-2026-17677 Inappropriate implementation in ANGLE
Chromium: CVE-2026-17793 Inappropriate implementation in Messages
Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)