Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: High)
Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Chromium: CVE-2026-84350 Use after free in TabStrip
Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Chromium: CVE-2026-84354 Incorrect authorization in FileSystem
Chromium: CVE-2026-84355 Incorrect authorization in Navigation
Chromium: CVE-2026-84356 UI misrepresentation in FullScreen
Chromium: CVE-2026-84357 Improper input validation in Omnibox
Chromium: CVE-2026-84358 Improper privilege management in Downloads
Chromium: CVE-2026-84347 Use after free in WebRTC
Chromium: CVE-2026-84348 Information leak in MediaCapture
Chromium: CVE-2026-84349 Use after free in Browser
Chromium: CVE-2026-84359 Information leak in Skia
Chromium: CVE-2026-84323 Missing authorization in FileSystem
Chromium: CVE-2026-84324 Use after free in Proxy
Chromium: CVE-2026-84325 Improper input validation in DataTransfer
Chromium: CVE-2026-84326 Uninitialized resource in V8
Chromium: CVE-2026-84328 Missing authorization in FileSystem
Chromium: CVE-2026-84329 Confused deputy in CredentialProvider
Chromium: CVE-2026-84331 Incorrect authorization in Actor