Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-7984 — Google Chrome Use After Free in ReadingMode

Use after free in ReadingMode in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML …

linux_kernel chrome macos windows | Remote | Memory Corruption
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
4.3 MEDIUM
CVE-2026-7983 — Google Chrome Dawn Cross-Origin Read Vulnerability

Out of bounds read in Dawn in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

linux_kernel chrome macos windows | Remote | Information Disclosure
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
6.5 MEDIUM
CVE-2026-7982 — Google Chrome WebCodecs Uninitialized Use Information Disclosure

Uninitialized Use in WebCodecs in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium sec…

linux_kernel chrome macos windows | Remote | Information Disclosure
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
6.5 MEDIUM
CVE-2026-7981 — Google Chrome Codecs Out-of-Bounds Read

Out of bounds read in Codecs in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a malicious file. (Chromium security…

linux_kernel chrome macos windows | Remote | Information Disclosure
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
8.8 HIGH
CVE-2026-7980 — Google Chrome WebAudio Use-After-Free Remote Code Execution Vulnerability

Use after free in WebAudio in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

linux_kernel chrome macos windows | Remote | Memory Corruption
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
4.3 MEDIUM
CVE-2026-7979 — Google Chrome Media Cross-Origin Data Leak Vulnerability

Inappropriate implementation in Media in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

linux_kernel chrome macos windows | Remote | Information Disclosure
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
8.1 HIGH
CVE-2026-7978 — Google Chrome Mac OS Privilege Escalation Vulnerability

Inappropriate implementation in Companion in Google Chrome on Mac prior to 148.0.7778.96 allowed a remote attacker to perform OS-level privilege escalation via malicious network traffic. (Chromium se…

chrome macos | Remote | Misconfiguration
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
6.3 MEDIUM
CVE-2026-7977 — Google Chrome Canvas Same-Origin Policy Bypass Vulnerability

Inappropriate implementation in Canvas in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

linux_kernel chrome macos windows | Remote | Misconfiguration
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
7.5 HIGH
CVE-2026-7976 — Google Chrome Use-After-Free Vulnerability in Views

Use after free in Views in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Ch…

linux_kernel chrome macos windows | Remote | Memory Corruption
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
8.3 HIGH
CVE-2026-7975 — Google Chrome DevTools Use-After-Free Sandbox Escape

Use after free in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. …

linux_kernel chrome macos windows | Remote | Memory Corruption
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
8.8 HIGH
CVE-2026-7974 — Google Chrome Blink Use-After-Free Vulnerability

Use after free in Blink in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

linux_kernel chrome macos windows | Remote | Memory Corruption
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
8.8 HIGH
CVE-2026-7973 — Google Chrome Dawn Integer Overflow Vulnerability

Integer overflow in Dawn in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Med…

chrome windows | Remote | Memory Corruption
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
4.3 MEDIUM
CVE-2026-7972 — Google Chrome GPU Uninitialized Use Remote Code Execution

Uninitialized Use in GPU in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium securi…

Remote | Information Disclosure
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
6.3 MEDIUM
CVE-2026-7971 — Google Chrome ORB Site Isolation Bypass

Inappropriate implementation in ORB in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

Remote | Misconfiguration
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
8.3 HIGH
CVE-2026-7970 — Google Chrome TopChrome Use-After-Free Vulnerability

Use after free in TopChrome in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.…

Remote | Memory Corruption
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
4.3 MEDIUM
CVE-2026-7969 — Google Chrome Same Origin Policy Bypass Vulnerability

Integer overflow in Network in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium …

Remote | Information Disclosure
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
3.1 LOW
CVE-2026-7968 — Google Chrome CORS Input Validation Bypass

Insufficient validation of untrusted input in CORS in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafte…

Remote | Misconfiguration
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
8.3 HIGH
CVE-2026-7967 — Google Chrome Navigation Sandbox Escalation

Insufficient validation of untrusted input in Navigation in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox es…

Remote | Misconfiguration
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
3.1 LOW
CVE-2026-7966 — Google Chrome SiteIsolation HTML Injection

Insufficient validation of untrusted input in SiteIsolation in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a c…

Remote | Misconfiguration
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
3.1 LOW
CVE-2026-7965 — Google Chrome DevTools Cross-Origin Data Leak Vulnerability

Insufficient validation of untrusted input in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a craft…

Remote | Information Disclosure
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
Showing 20 of 5923 Results