Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Chromium: CVE-2026-84354 Incorrect authorization in FileSystem
Chromium: CVE-2026-84356 UI misrepresentation in FullScreen
Chromium: CVE-2026-84357 Improper input validation in Omnibox
Chromium: CVE-2026-84347 Use after free in WebRTC
Chromium: CVE-2026-84348 Information leak in MediaCapture
Chromium: CVE-2026-84349 Use after free in Browser
Chromium: CVE-2026-84359 Information leak in Skia
Chromium: CVE-2026-84329 Confused deputy in CredentialProvider
Chromium: CVE-2026-84334 Incorrect authorization in Chromoting
Chromium: CVE-2026-84335 Incorrect authorization in TabStrip
Chromium: CVE-2026-84353 Use after free in Shared Tab Groups
Chromium: CVE-2026-78959 Improper handling of case sensitivity in FileSystem
Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data via a co-installed app. (Chromium security severity: Medium)
Chromium: CVE-2026-78941 Information leak in Core
Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data via a co-installed app. (Chromium security severity: Medium)
Chromium: CVE-2026-78892 Incorrect authorization in Chromoting
Chromium: CVE-2026-79289 Improper control of a resource through its lifetime in Workers
Chromium: CVE-2026-79198 Use after free in Platform
Chromium: CVE-2026-79202 Use after free in Chromecast
Chromium: CVE-2026-79224 Use after free in Chromecast
Chromium: CVE-2026-79230 Improper input validation in ANGLE
Buffer overflow in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Chromium: CVE-2026-79235 Use after free in WebGL
Chromium: CVE-2026-79240 Out of bounds write in ANGLE
Chromium: CVE-2026-79244 Use after free in Animation
Chromium: CVE-2026-79263 Race condition in Extensions
Chromium: CVE-2026-79266 Use after free in DevTools