Where
-Infinity
0
Severity
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Out of bounds read in Video in Google Chrome on ChromeOS prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

First published (updated )
Severity
8.3
Input Validation
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Chromium: CVE-2026-11675 Insufficient validation of untrusted input in Skia

1 / 3
Source: Microsoft
First published (updated )
Severity
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Chromium: CVE-2026-14421 Uninitialized Use in Dawn

1 / 3
Source: Microsoft
First published (updated )
Severity
8.3
Buffer Overflow
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Chromium: CVE-2026-12019 Out of bounds write  Codecs

1 / 3
Source: Microsoft
First published (updated )
Severity
9.6
Buffer Overflow
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Chromium: CVE-2026-17680 Heap buffer overflow in Color

1 / 3
Source: Microsoft
First published (updated )
Severity
5.3
Integer Overflow
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

Chromium: CVE-2026-11668 Uninitialized Use in Codecs

1 / 3
Source: Microsoft
First published (updated )
Severity
4.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Chromium: CVE-2026-11667 Out of bounds read in WebRTC

1 / 3
Source: Microsoft
First published (updated )
Severity
4.2
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L

Chromium: CVE-2026-13986 Inappropriate implementation in Media UI

1 / 3
Source: Microsoft
First published (updated )
Severity
6.5
Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Chromium: CVE-2026-14103 Use after free in SSL

1 / 3
Source: Microsoft
First published (updated )
Severity
5.3
EPSS
0.18%
Input Validation
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

Chromium: CVE-2026-9985 Insufficient validation of untrusted input in Media

1 / 3
Source: Microsoft
First published (updated )
Severity
8.1
Use After Free
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Chromium: CVE-2026-13779 Use after free in Chromoting

1 / 3
Source: Microsoft
First published (updated )
Severity
3.3
Input Validation
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Chromium: CVE-2026-13942 Insufficient validation of untrusted input in Video Capture

1 / 3
Source: Microsoft
First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

Insufficient validation of untrusted input in CameraCapture in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low)

First published (updated )
Severity
8.6
AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:U/AU:Y/R:A/V:D/RE:M/U:Amber

An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. By presenting a certificate for any domain issued by a trusted Certificate Authority, the attacker can capture sensitive device information.

The Prisma Access Agent on macOS, Windows, Linux and iOS are not affected.

1 / 2
Source: MITRE
First published (updated )
Severity
5.9
Infoleak
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Chromium: CVE-2026-14062 Inappropriate implementation in Views

1 / 3
Source: Microsoft
First published (updated )
Severity
8.8
EPSS
0.12%
Input Validation
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Chromium: CVE-2026-7992 Insufficient validation of untrusted input in UI

1 / 3
Source: Microsoft
First published (updated )
Severity
7.5
EPSS
0.27%
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Chromium: CVE-2026-9117 Type Confusion in GFX

1 / 3
Source: Microsoft
First published (updated )
Severity
8.8
Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Chromium: CVE-2026-11028 Use after free in Media

1 / 3
Source: Microsoft
First published (updated )
Severity
4.3
EPSS
0.03%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Chromium: CVE-2026-7946 Insufficient policy enforcement in WebUI

1 / 3
Source: Microsoft
First published (updated )
Severity
4.3
EPSS
0.15%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Chromium: CVE-2026-8576 Inappropriate implementation in CORS

1 / 3
Source: Microsoft
First published (updated )
Severity
7.5
EPSS
0.19%
Buffer Overflow
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Chromium: CVE-2026-9122 Out of bounds read in GPU

1 / 3
Source: Microsoft
First published (updated )
Severity
8.3
EPSS
0.21%
Integer Overflow
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Chromium: CVE-2026-8534 Integer overflow in GPU

1 / 3
Source: Microsoft
First published (updated )
Severity
5.3
EPSS
0.19%
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

Chromium: CVE-2026-8535 Out of bounds read in Media

1 / 3
Source: Microsoft
First published (updated )
Severity
8.3
EPSS
0.12%
Use After Free
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Chromium: CVE-2026-8001 Use after free in Printing

1 / 3
Source: Microsoft
First published (updated )
Severity
8.8
EPSS
0.04%
Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Chromium: CVE-2026-7363 Use after free in Canvas

1 / 3
Source: Microsoft
First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Chromium: CVE-2025-10201 Inappropriate implementation in Mojo

1 / 3
Source: Microsoft
First published (updated )
Severity
8.8
Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Chromium: CVE-2025-12438 Use after free in Ozone

1 / 3
Source: Microsoft
First published (updated )
Severity
6.1
EPSS
0.01%
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the garaged stylus devices allows a physical attacker to bypass the lock screen and access user files by removing the stylus while the device is closed and using the screen capture feature.

First published (updated )
Severity
9.8
EPSS
0.02%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Permissions Bypass in Extension Management in Google ChromeOS 16181.27.0 on managed Chrome devices allows a local attacker to disable extensions and access Developer Mode, including loading additional extensions via exploiting vulnerabilities using the ExtHang3r and ExtPrint3r tools.

First published (updated )
Severity
7.4
EPSS
0.01%
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Privilege Escalation in MiniOS in Google ChromeOS (16063.45.2 and potentially others) on enrolled devices allows a local attacker to gain root code execution via exploiting a debug shell (VT3 console) accessible through specific key combinations during developer mode entry and MiniOS access, even when developer mode is blocked by device policy or Firmware Write Protect (FWMP).

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203