| CVE-2026-13938 | 8.8 | high | google / chrome | Integer overflow in Fonts in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform an out of b | 67d ago |
| CVE-2026-13928 | 8.8 | high | google / chrome | Insufficient validation of untrusted input in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote | 67d ago |
| CVE-2026-13918 | 8.8 | high | google / chrome | Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to poten | 67d ago |
| CVE-2026-13915 | 8.8 | high | google / chrome | Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who conv | 67d ago |
| CVE-2026-13903 | 8.8 | high | google / chrome | Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to | 67d ago |
| CVE-2026-13899 | 8.8 | high | google / chrome | Use after free in HTML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code | 67d ago |
| CVE-2026-13898 | 8.8 | high | google / chrome | Use after free in Cast Receiver in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbit | 67d ago |
| CVE-2026-13897 | 8.8 | high | google / chrome | Insufficient policy enforcement in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to | 67d ago |
| CVE-2026-13888 | 8.8 | high | google / chrome | Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrar | 67d ago |
| CVE-2026-13885 | 8.8 | high | google / chrome | Use after free in Skia in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to execute arb | 67d ago |
| CVE-2026-13884 | 8.8 | high | google / chrome | Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a local attacker to execute arbitra | 67d ago |
| CVE-2026-13870 | 8.8 | high | google / chrome | Use after free in WebView in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to execute | 67d ago |
| CVE-2026-13850 | 8.8 | high | google / chrome | Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowe | 67d ago |
| CVE-2026-13848 | 8.8 | high | google / chrome | Use after free in Forms in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary cod | 67d ago |
| CVE-2026-13845 | 8.8 | high | google / chrome | Use after free in DOM in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code | 67d ago |
| CVE-2026-13835 | 8.8 | high | google / chrome | Inappropriate implementation in XML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potential | 67d ago |
| CVE-2026-13830 | 8.8 | high | google / chrome | Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute | 67d ago |
| CVE-2026-13825 | 8.8 | high | google / chrome | Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit | 67d ago |
| CVE-2026-13821 | 8.8 | high | google / chrome | Use after free in Canvas in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary co | 67d ago |
| CVE-2026-13817 | 8.8 | high | google / chrome | Insufficient validation of untrusted input in Glic in Google Chrome prior to 150.0.7871.47 allowed a remote attack | 67d ago |
| CVE-2026-13815 | 8.8 | high | google / chrome | Use after free in Blink in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary cod | 67d ago |
| CVE-2026-13811 | 8.8 | high | google / chrome | Use after free in IME in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code | 67d ago |
| CVE-2026-13805 | 8.8 | high | google / chrome | Use after free in GFX in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker to execute arbitrar | 67d ago |
| CVE-2026-13788 | 8.8 | high | google / chrome | Use after free in Fullscreen in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to execu | 67d ago |
| CVE-2026-13786 | 8.8 | high | google / chrome | Use after free in Ozone in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary cod | 67d ago |
| CVE-2026-13784 | 8.8 | high | google / chrome | Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to | 67d ago |
| CVE-2026-13783 | 8.8 | high | google / chrome | Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to | 67d ago |
| CVE-2026-13777 | 8.8 | high | google / chrome | Insufficient validation of untrusted input in iOSWeb in Google Chrome on iOS prior to 150.0.7871.47 allowed a remo | 67d ago |
| CVE-2026-13038 | 8.8 | high | google / chrome | Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.197 allowed a remote attacker to execut | 73d ago |
| CVE-2026-13036 | 8.8 | high | google / chrome | Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary co | 73d ago |
| CVE-2026-13035 | 8.8 | high | google / chrome | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to execute a | 73d ago |
| CVE-2026-13033 | 8.8 | high | google / chrome | Out of bounds read and write in Blink>InterestGroups in Google Chrome prior to 149.0.7827.197 allowed a remote att | 73d ago |
| CVE-2026-13031 | 8.8 | high | google / chrome | Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary co | 73d ago |
| CVE-2026-13027 | 8.8 | high | google / chrome | Use after free in FileSystem in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to potentially exp | 73d ago |
| CVE-2026-13026 | 8.8 | high | google / chrome | Use after free in Digital Credentials in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to | 73d ago |
| CVE-2026-12466 | 8.8 | high | google / chrome | Heap buffer overflow in WebRTC in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to ex | 80d ago |
| CVE-2026-12452 | 8.8 | high | google / chrome | Use after free in Downloads in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to poten | 80d ago |
| CVE-2026-12448 | 8.8 | high | google / chrome | Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attac | 80d ago |
| CVE-2026-12447 | 8.8 | high | google / chrome | Heap buffer overflow in WebRTC in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbit | 80d ago |
| CVE-2026-12443 | 8.8 | high | google / chrome | Use after free in Web Authentication in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute | 80d ago |
| CVE-2026-12442 | 8.8 | high | google / chrome | Use after free in Passwords in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to execu | 80d ago |
| CVE-2026-12441 | 8.8 | high | google / chrome | Use after free in File Input in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker to potent | 80d ago |
| CVE-2026-12439 | 8.8 | high | google / chrome | Use after free in Digital Credentials in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to potent | 80d ago |
| CVE-2026-0164 | 8.8 | high | google / android | In Modem, there is a possible out of bounds write due to a missing bounds check. | 81d ago |
| CVE-2026-0162 | 8.8 | high | google / android | In ParsePayloads of AudioSdpParser.cpp, there is a possible memory corruption due to type confusion. | 81d ago |
| CVE-2026-0161 | 8.8 | high | google / android | In numberOfReportBlocks of RtpSession.cpp, there is a possible out of bounds write due to an integer overflow. | 81d ago |
| CVE-2026-0160 | 8.8 | high | google / android | In TextRtpPayloadDecoderNode::DecodeT140 of TextRtpPayloadDecoderNode.cpp, there is a possible out of bounds write | 81d ago |
| CVE-2026-0154 | 8.8 | high | google / android | In Modem, there is a possible way to trigger a modem crash during a SIP REFER request due to memory corruption. | 81d ago |
| CVE-2026-0151 | 8.8 | high | google / android | In IntfGraphCreate of intfgraph.c, there is a possible out of bounds write due to an integer overflow. | 81d ago |
| CVE-2026-0149 | 8.8 | high | google / android | In RtpSession::rtpSendRtcpPacket, there is a possible OOB write due to a heap buffer overflow. | 81d ago |
| CVE-2026-0148 | 8.8 | high | google / android | In multiple functions of VideoRtpPayloadDecoderNode.cpp, there is a possible out of bounds write due to an integer | 81d ago |
| CVE-2026-0147 | 8.8 | high | google / android | In __mfc_core_nal_q_get_dec_metadata_sei_nal of mfc_core_nal_q.c, there is a possible out of bounds write due to a | 81d ago |
| CVE-2026-0146 | 8.8 | high | google / android | In mfc_core_get_dec_metadata_sei_nal of mfc_core_reg_api.c, there is a possible out of bounds write due to a missin | 81d ago |
| CVE-2026-0139 | 8.8 | high | google / android | In Modem, there is a possible out of bounds write due to a missing bounds check. | 81d ago |
| CVE-2026-0132 | 8.8 | high | google / android | In Modem, there is a possible out of bounds write due to a heap buffer overflow. | 81d ago |
| CVE-2026-12035 | 8.8 | high | google / chrome | Use after free in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to potential | 86d ago |
| CVE-2026-12020 | 8.8 | high | google / chrome | Use after free in Autofill in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker to potentiall | 86d ago |
| CVE-2026-12018 | 8.8 | high | google / chrome | Inappropriate implementation in Mojo in Google Chrome on Windows prior to 149.0.7827.115 allowed a local attacker | 86d ago |
| CVE-2026-12007 | 8.8 | high | google / chrome | Use after free in Core in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to execute ar | 86d ago |
| CVE-2026-11699 | 8.8 | high | google / chrome | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potential | 89d ago |