Uninitialized resource in Media in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Chromium CVE-2026-93378: Missing authorization in Storage
Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)
Chromium CVE-2026-93380: Race condition in FileSystem
Chromium CVE-2026-91730: Incomplete cleanup
Chromium CVE-2026-91708: Race condition
Chromium CVE-2026-91747: Use after free
Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Chromium CVE-2026-87614: Incorrect authorization in ServiceWorker
Chromium CVE-2026-87531: Information leak in CORS
Chromium CVE-2026-87451: Information leak in Downloads
Chromium CVE-2026-87452: Incorrect authorization in GPU
Chromium CVE-2026-87521: Information leak in WebMCP
Chromium CVE-2026-87539: Observable discrepancy in Network
Chromium CVE-2026-87576: Uninitialized resource in GPU
Chromium CVE-2026-87652: Incorrect authorization in PushAPI
Chromium CVE-2026-87485: Incorrect authorization in CORS
Chromium CVE-2026-87442: Confused deputy in Prerender
Chromium CVE-2026-87456: Uninitialized resource in Media
Chromium CVE-2026-87434: Missing authorization in CORS
Chromium CVE-2026-87611: Missing authorization in FileSystem
Chromium CVE-2026-87657: Use after free in V8
Chromium CVE-2026-87498: Missing authorization in WebUI
Chromium CVE-2026-87647: Uninitialized resource in GPU
Chromium CVE-2026-87517: Race condition in Mobile
Chromium CVE-2026-87525: Out of bounds read in Chromoting
Observable discrepancy in Scroll in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)
Use of released resource in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Chromium CVE-2026-95316: Unchecked return value in Performance