See how google compares to other vendors in security performance
In returnOutputBufferLocked of DeprecatedCamera3StreamSplitter.cpp, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Uninitialized resource in Media in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Chromium CVE-2026-93378: Missing authorization in Storage
Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)
Chromium CVE-2026-93380: Race condition in FileSystem
Chromium CVE-2026-91730: Incomplete cleanup
Chromium CVE-2026-91708: Race condition
Chromium CVE-2026-91747: Use after free
Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Chromium CVE-2026-87614: Incorrect authorization in ServiceWorker
Chromium CVE-2026-87531: Information leak in CORS
Chromium CVE-2026-87451: Information leak in Downloads
Chromium CVE-2026-87452: Incorrect authorization in GPU
Chromium CVE-2026-87521: Information leak in WebMCP
Chromium CVE-2026-87539: Observable discrepancy in Network
Chromium CVE-2026-87576: Uninitialized resource in GPU
Chromium CVE-2026-87652: Incorrect authorization in PushAPI
Chromium CVE-2026-87485: Incorrect authorization in CORS
Chromium CVE-2026-87442: Confused deputy in Prerender
Chromium CVE-2026-87456: Uninitialized resource in Media
Chromium CVE-2026-87434: Missing authorization in CORS
Chromium CVE-2026-87611: Missing authorization in FileSystem
Chromium CVE-2026-87657: Use after free in V8
Chromium CVE-2026-87498: Missing authorization in WebUI
Chromium CVE-2026-87647: Uninitialized resource in GPU
Chromium CVE-2026-87517: Race condition in Mobile
Chromium CVE-2026-87525: Out of bounds read in Chromoting
In setTo of ResourceTypes.cpp, there is a possible out-of-bounds heap read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
In getehtoperationchannelwidth of ieee80211common.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.