Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)
Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Low)
Out of bounds write in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Chromium: CVE-2026-84353 Use after free in Shared Tab Groups
Chromium: CVE-2026-84354 Incorrect authorization in FileSystem
Chromium: CVE-2026-79235 Use after free in WebGL
Chromium: CVE-2026-79148 Off-by-one error in DevTools
Chromium: CVE-2026-78904 Type confusion in ANGLE
Chromium: CVE-2026-78945 Use after free in Views
Chromium: CVE-2026-78964 Use after free in Sync
Chromium: CVE-2026-78989 Out of bounds read in ANGLE
Chromium: CVE-2026-78985 Incorrect reference resolution in FileSystem
Chromium: CVE-2026-79047 Use after free in Views
Chromium: CVE-2026-79026 Use after free in Extensions
Chromium: CVE-2026-79111 Improper input validation in Dawn
Chromium: CVE-2026-79128 Use after free in Views
Buffer overflow in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Chromium: CVE-2026-79150 Use after free in Views
Chromium: CVE-2026-79140 Use after free in Views
Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to bypass web origin policy via a co-installed app. (Chromium security severity: Low)
Use of uninitialized variable in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Chromium: CVE-2026-17738 Insufficient validation of untrusted input in Payments
CVE-2026-19175 Use after free in Payments
Chromium: CVE-2026-17652 Use after free in Views
Chromium: CVE-2026-17656 Use after free in Ozone
Chromium: CVE-2026-17847 Insufficient validation of untrusted input in ANGLE