Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
UI misrepresentation in FullScreen in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)
Incorrect authorization in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Race condition in Permissions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Race condition in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a co-installed app. (Chromium security severity: High)
Chromium: CVE-2026-78977 Uninitialized resource in GPU
Chromium: CVE-2026-79055 Information leak in Sharing
Buffer overflow in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Incorrect reference resolution in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Improper input validation in Input in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Improper input validation in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
Use after free in Resources in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVE-2026-19146 Uninitialized Use in GPU
Chromium: CVE-2026-17802 Side-channel information leakage in GPU
Chromium: CVE-2026-17767 Insufficient validation of untrusted input in WebView
Chromium: CVE-2026-17953 Insufficient policy enforcement in WebView
Chromium: CVE-2026-17808 Uninitialized Use in WebGL
Chromium: CVE-2026-17741 Insufficient validation of untrusted input in WebView
Chromium: CVE-2026-17731 Inappropriate implementation in Autofill
Chromium: CVE-2026-17866 Type Confusion in Tab
Chromium: CVE-2026-17722 Object lifecycle issue in WebView
Chromium: CVE-2026-17860 Insufficient validation of untrusted input in Mobile
Chromium: CVE-2026-17901 Inappropriate implementation in Sharing
Chromium: CVE-2026-17793 Inappropriate implementation in Messages
Chromium: CVE-2026-17677 Inappropriate implementation in ANGLE
Chromium: CVE-2026-13282 Use after free in AdFilter
Chromium: CVE-2026-16424 Use after free in GPU
Use after free in WebView in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Chromium: CVE-2026-9876 Use after free in WebGL