Out of bounds write in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Chromium: CVE-2026-9875 Out of bounds read in WebGL
Chromium: CVE-2026-13032 Use after free in WebGL
Chromium: CVE-2026-17713 Insufficient validation of untrusted input in Accessibility
Use after free in Sessions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Medium)
Out of bounds memory access in WebGL in Google Chrome on Android prior to 146.0.7680.153 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Chromium: CVE-2026-12448 Inappropriate implementation in WebView
Use after free in Media in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Chromium: CVE-2026-9892 Inappropriate implementation in Skia
Chromium: CVE-2026-9977 Insufficient validation of untrusted input in WebShare
Chromium: CVE-2026-11671 Use after free in Navigation
Chromium: CVE-2026-12010 Heap buffer overflow GPU
Chromium: CVE-2026-12031 Inappropriate implementation Views
Chromium: CVE-2026-12028 Use after free GPU
Chromium: CVE-2026-12438 Inappropriate implementation in WebView
Chromium: CVE-2026-17663 Insufficient validation of untrusted input in GPU
CVE-2026-19137 Use after free in WebGL
Buffer overflow in ANGLE in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 148.0.7778.216 allowed a local attacker to execute arbitrary code via a malicious file. (Chromium security severity: High)
Chromium: CVE-2026-13037 Use after free in WebView
Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a co-installed app. (Chromium security severity: Medium)
Chromium: CVE-2026-13936 Inappropriate implementation in Passwords
Chromium: CVE-2026-17999 Incorrect security UI in PictureInPicture
Incorrect reference resolution in Core in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)
Improper input validation in Autofill in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)
Chromium: CVE-2026-13030 Uninitialized Use in GPU
Inappropriate implementation in Input in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
Chromium: CVE-2026-7941 Insufficient validation of untrusted input in Mobile
Chromium: CVE-2026-9919 Out of bounds read in WebGL