Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
Chromium CVE-2026-91722: Use after free
Chromium CVE-2026-91725: Observable discrepancy
Chromium CVE-2026-91738: Improper input validation
Chromium CVE-2026-91714: Observable discrepancy
Missing authorization in AppManifest in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Chromium CVE-2026-91729: Use after free
Chromium CVE-2026-91737: Use after free
Chromium CVE-2026-91718: Use after free
Chromium CVE-2026-91716: Use after free
Chromium CVE-2026-91717: Missing authorization
Chromium CVE-2026-91733: Improper state validation
Chromium CVE-2026-91744: Race condition
Chromium CVE-2026-91734: Incorrect authorization
Chromium CVE-2026-91721: Use after free
Chromium CVE-2026-91749: Use after free
Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Chromium CVE-2026-87544: Incorrect authorization in Extensions
Chromium CVE-2026-87593: Information leak in Editing
Chromium CVE-2026-87477: Information leak in Core
Chromium CVE-2026-87551: Improper certificate validation in CORS
Chromium CVE-2026-87571: Improper certificate validation in Loader
Chromium CVE-2026-87602: Out of bounds read in ANGLE
Chromium CVE-2026-87461: Information leak in Core
Chromium CVE-2026-87490: Information leak in Transactions Platform
Chromium CVE-2026-87605: Missing authorization in Contacts
Chromium CVE-2026-87546: Incorrect type conversion or cast in Safebrowsing