Chromium CVE-2026-91749: Use after free
Chromium: CVE-2026-17713 Insufficient validation of untrusted input in Accessibility
Chromium: CVE-2026-17701 Out of bounds read in ANGLE
Accessibility. A logic issue was addressed with improved checks.
Chromium CVE-2026-87564: Type confusion in V8
Chromium CVE-2026-87587: Use after free in V8
Chromium CVE-2026-87489: Memory corruption in V8
Chromium CVE-2026-87536: Use after free in V8
Chromium: CVE-2026-5883 Use after free in Media
Chromium: CVE-2026-17909 Insufficient validation of untrusted input in Isolated Web Apps
Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: High)
Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Chromium CVE-2026-91742: Confused deputy
Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)
Chromium CVE-2026-87491: Out of bounds write in V8
Chromium: CVE-2026-85046 Type confusion in V8
Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Chromium: CVE-2025-13223 Type Confusion in V8
Accessibility. A privacy issue was addressed by removing sensitive data.
Chromium: CVE-2026-2441 Use after free in CSS
Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social engineering to read memory outside the sandbox via a local program. (Chromium security severity: Medium)
Missing authorization in Storage in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: Medium)
Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)