Accessibility. An authorization issue was addressed with improved state management.
Chromium: CVE-2025-10585 Type Confusion in V8
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in January 2015.
Chromium: CVE-2024-7971 Type confusion in V8
Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Chromium: CVE-2022-3075 Insufficient data validation in Mojo
Chromium: CVE-2023-2136 Integer overflow in Skia
Chromium: CVE-2023-6345 Integer overflow in Skia
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Chromium: CVE-2024-0519 Out of bounds memory access in V8
Chromium: CVE-2024-7965 Inappropriate implementation in V8
Chromium: CVE-2023-4762 Type Confusion in V8
Chromium: CVE-2025-5419 Out of bounds read and write in V8
Chromium: CVE-2025-5068 Use after free in Blink
Accessibility. A logic issue was addressed with improved checks.
Chromium: CVE-2025-13223 Type Confusion in V8
Accessibility. A privacy issue was addressed by removing sensitive data.
Chromium: CVE-2026-2441 Use after free in CSS
Chromium: CVE-2026-3909 Out of bounds write in Skia
Chromium: CVE-2026-3910 Inappropriate implementation in V8
Chromium: CVE-2026-5281 Use after free in Dawn
Chromium: CVE-2023-4863 Heap buffer overflow in WebP
Chromium: CVE-2026-11645 Out of bounds memory access in V8
Internet Explorer Memory Corruption Vulnerability
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7200, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.
Chromium: CVE-2023-5217 Heap buffer overflow in vp8 encoding in libvpx
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7201, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.
Chromium: CVE-2023-2033 Type Confusion in V8
Chromium: CVE-2023-3079 Type Confusion in V8