Out of bounds read in Video in Google Chrome on ChromeOS prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
Chromium: CVE-2026-11675 Insufficient validation of untrusted input in Skia
Chromium: CVE-2026-14421 Uninitialized Use in Dawn
Chromium: CVE-2026-12019 Out of bounds write Codecs
Chromium: CVE-2026-17680 Heap buffer overflow in Color
Chromium: CVE-2026-11668 Uninitialized Use in Codecs
Chromium: CVE-2026-11667 Out of bounds read in WebRTC
Chromium: CVE-2026-13986 Inappropriate implementation in Media UI
Chromium: CVE-2026-14103 Use after free in SSL
Chromium: CVE-2026-9985 Insufficient validation of untrusted input in Media
Chromium: CVE-2026-13779 Use after free in Chromoting
Chromium: CVE-2026-13942 Insufficient validation of untrusted input in Video Capture
Insufficient validation of untrusted input in CameraCapture in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low)
An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. By presenting a certificate for any domain issued by a trusted Certificate Authority, the attacker can capture sensitive device information.
The Prisma Access Agent on macOS, Windows, Linux and iOS are not affected.
Chromium: CVE-2026-14062 Inappropriate implementation in Views
Chromium: CVE-2026-7992 Insufficient validation of untrusted input in UI
Chromium: CVE-2026-9117 Type Confusion in GFX
Chromium: CVE-2026-11028 Use after free in Media
Chromium: CVE-2026-7946 Insufficient policy enforcement in WebUI
Chromium: CVE-2026-8576 Inappropriate implementation in CORS
Chromium: CVE-2026-9122 Out of bounds read in GPU
Chromium: CVE-2026-8534 Integer overflow in GPU
Chromium: CVE-2026-8535 Out of bounds read in Media
Chromium: CVE-2026-8001 Use after free in Printing
Chromium: CVE-2026-7363 Use after free in Canvas
Chromium: CVE-2025-10201 Inappropriate implementation in Mojo
Chromium: CVE-2025-12438 Use after free in Ozone
An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the garaged stylus devices allows a physical attacker to bypass the lock screen and access user files by removing the stylus while the device is closed and using the screen capture feature.
Permissions Bypass in Extension Management in Google ChromeOS 16181.27.0 on managed Chrome devices allows a local attacker to disable extensions and access Developer Mode, including loading additional extensions via exploiting vulnerabilities using the ExtHang3r and ExtPrint3r tools.
Privilege Escalation in MiniOS in Google ChromeOS (16063.45.2 and potentially others) on enrolled devices allows a local attacker to gain root code execution via exploiting a debug shell (VT3 console) accessible through specific key combinations during developer mode entry and MiniOS access, even when developer mode is blocked by device policy or Firmware Write Protect (FWMP).