Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-19170 Use after free in WebGL
Chromium: CVE-2026-17940 Insufficient validation of untrusted input in Picture-in-Picture
Chromium: CVE-2026-17726 Integer overflow in WebGL
Chromium: CVE-2026-17681 Insufficient validation of untrusted input in Web Authentication
Chromium: CVE-2026-13872 Insufficient validation of untrusted input in WebAppInstalls
Chromium: CVE-2026-13851 Insufficient validation of untrusted input in WebAppInstalls