Use after free in WebView in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Chromium: CVE-2026-9876 Use after free in WebGL
Chromium: CVE-2026-16424 Use after free in GPU
Chromium: CVE-2026-13852 Insufficient validation of untrusted input in WebAppInstalls
Use after free in WebView in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Chromium: CVE-2026-12442 Use after free in Passwords
Chromium: CVE-2026-12452 Use after free in Downloads
Chromium: CVE-2026-13870 Use after free in WebView
Chromium: CVE-2026-13885 Use after free in Skia
Chromium: CVE-2026-14005 Use after free in Omnibox
Chromium: CVE-2026-17677 Inappropriate implementation in ANGLE
Buffer overflow in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
Chromium: CVE-2026-7905 Insufficient validation of untrusted input in Media
Use after free in WebMIDI in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Chromium: CVE-2026-10020 Insufficient validation of untrusted input in Skia
Chromium: CVE-2026-9889 Out of bounds read and write in Dawn
Chromium: CVE-2026-9888 Use after free in WebView
Chromium: CVE-2026-9898 Insufficient validation of untrusted input in GPU
Chromium: CVE-2026-11647 Use after free in Printing
Chromium: CVE-2026-14428 Insufficient validation of untrusted input in Dawn
Chromium: CVE-2026-17722 Object lifecycle issue in WebView
Use after free in Resources in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Improper input validation in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Improper input validation in Input in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Chromium: CVE-2026-7913 Insufficient policy enforcement in DevTools
Chromium: CVE-2026-13927 Insufficient validation of untrusted input in UI
Chromium: CVE-2026-14114 Inappropriate implementation in WebAppInstalls
Chromium: CVE-2026-17741 Insufficient validation of untrusted input in WebView
Chromium: CVE-2026-13282 Use after free in AdFilter