Out of bounds read in Skia in Google Chrome prior to 155.0.8059.39 allowed a local attacker leveraging social engineering to potentially read memory via a crafted file. (Chromium security severity: Low)
Observable discrepancy in Scroll in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)
Observable discrepancy in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Missing authorization in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Chromium: CVE-2025-11219 Use after free in V8
Use of released resource in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Chromium CVE-2026-87576: Uninitialized resource in GPU
Chromium CVE-2026-87517: Race condition in Mobile
Chromium CVE-2026-93380: Race condition in FileSystem
Chromium CVE-2026-93378: Missing authorization in Storage
Chromium CVE-2026-95308: Integer overflow in Metrics
Chromium CVE-2026-95312: Information leak in Passwords
Chromium CVE-2026-95316: Unchecked return value in Performance
Chromium CVE-2026-95317: Incorrect authorization in MediaCapture
Chromium CVE-2026-95324: Uninitialized resource in GPU
Chromium CVE-2026-95302: Incorrect authorization in WebAPKs
Uninitialized resource in Media in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Chromium CVE-2026-95359: Uninitialized resource in GPU
Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Chromium: CVE-2026-78953 Missing authorization in SiteIsolation
Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)
Chromium CVE-2026-91747: Use after free
Chromium CVE-2026-91730: Incomplete cleanup
Chromium CVE-2026-91708: Race condition
Chromium CVE-2026-87647: Uninitialized resource in GPU
Chromium: CVE-2026-79255 Improper input validation in WebRTC
Chromium: CVE-2026-79203 Improper input validation in DevTools
Chromium: CVE-2026-79191 Incorrect authorization in SiteIsolation
Chromium: CVE-2026-79103 Incorrect reference resolution in Speech