Back to search

Google

Chrome

Google web browser with frequent stable-channel releases.

Current version
Last checked: 2026-09-04

152

Release date
August 25, 2026
Security status
100 high-severity CVEs tracked in the last 90 days. Current version not affected.

Source

endoflife.date

Public release notes are linked for the latest stored release.

Release history

See the latest published releases stored for this product.

Version Published Notes
152 2026-08-25 Release Notes
151 2026-07-28 Release Notes
150 2026-06-30 Release Notes
149 2026-06-02 Release Notes
148 2026-05-05 Release Notes
147 2026-04-07 Release Notes
146 2026-03-10 Release Notes

Vulnerability tracking

versionPing monitors CVEs for this product. Matching CVEs are listed below. We only display CVEs with a CVSS score of 7.0 or higher that were published within the last 90 days.

Affected status is inferred from published affected version ranges where available. Always verify against the vendor advisory before making production decisions.

CVE Severity Published Status Summary
CVE-2026-85047 CRITICAL (9.6) 2026-09-03 Current versionnot affected

Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.82 - Up to (excluding) 152.0.7977.82
CVE-2026-85051 HIGH (8.8) 2026-09-03 Current versionnot affected

Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • From (including) 152.0.7977.82 - Up to (excluding) 152.0.7977.82
CVE-2026-85049 HIGH (8.8) 2026-09-03 Current versionnot affected

Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • From (including) 152.0.7977.82 - Up to (excluding) 152.0.7977.82
CVE-2026-85042 CRITICAL (9.6) 2026-09-03 Current versionnot affected

Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • From (including) 152.0.7977.82 - Up to (excluding) 152.0.7977.82
CVE-2026-85053 HIGH (8.8) 2026-09-03 Current versionnot affected

Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • From (including) 152.0.7977.82 - Up to (excluding) 152.0.7977.82
CVE-2026-85050 CRITICAL (9.6) 2026-09-03 Current versionnot affected

Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • From (including) 152.0.7977.82 - Up to (excluding) 152.0.7977.82
CVE-2026-85045 HIGH (7.5) 2026-09-03 Current versionnot affected

Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • From (including) 152.0.7977.82 - Up to (excluding) 152.0.7977.82
CVE-2026-85048 HIGH (8.3) 2026-09-03 Current versionnot affected

Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • From (including) 152.0.7977.82 - Up to (excluding) 152.0.7977.82
CVE-2026-85043 CRITICAL (9.1) 2026-09-03 Current versionnot affected

Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: High)

Affected versions
  • From (including) 152.0.7977.82 - Up to (excluding) 152.0.7977.82
CVE-2026-85046 HIGH (8.8) 2026-09-03 Current versionnot affected

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • From (including) 152.0.7977.82 - Up to (excluding) 152.0.7977.82
CVE-2026-84350 HIGH (8.8) 2026-09-01 Current versionnot affected

Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Low)

Affected versions
  • From (including) 152.0.7977.75 - Up to (excluding) 152.0.7977.75
CVE-2026-84335 HIGH (8.3) 2026-09-01 Current versionnot affected

Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.75 - Up to (excluding) 152.0.7977.75
CVE-2026-84334 HIGH (8.1) 2026-09-01 Current versionnot affected

Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.75 - Up to (excluding) 152.0.7977.75
CVE-2026-84347 HIGH (8.8) 2026-09-01 Current versionnot affected

Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.75 - Up to (excluding) 152.0.7977.75
CVE-2026-84325 CRITICAL (9.8) 2026-09-01 Current versionnot affected

Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High)

Affected versions
  • From (including) 152.0.7977.75 - Up to (excluding) 152.0.7977.75
CVE-2026-84351 HIGH (8.3) 2026-09-01 Current versionnot affected

Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • From (including) 152.0.7977.75 - Up to (excluding) 152.0.7977.75
CVE-2026-84333 CRITICAL (9.6) 2026-09-01 Current versionnot affected

Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • From (including) 152.0.7977.75 - Up to (excluding) 152.0.7977.75
CVE-2026-84326 HIGH (8.8) 2026-09-01 Current versionnot affected

Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • From (including) 152.0.7977.75 - Up to (excluding) 152.0.7977.75
CVE-2026-84349 HIGH (8.3) 2026-09-01 Current versionnot affected

Use after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • From (including) 152.0.7977.75 - Up to (excluding) 152.0.7977.75
CVE-2026-84324 CRITICAL (9.0) 2026-09-01 Current versionnot affected

Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)

Affected versions
  • From (including) 152.0.7977.75 - Up to (excluding) 152.0.7977.75
CVE-2026-84354 CRITICAL (9.6) 2026-09-01 Current versionnot affected

Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • From (including) 152.0.7977.75 - Up to (excluding) 152.0.7977.75
CVE-2026-84352 CRITICAL (9.6) 2026-09-01 Current versionnot affected

Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Affected versions
  • From (including) 152.0.7977.75 - Up to (excluding) 152.0.7977.75
CVE-2026-84353 CRITICAL (9.6) 2026-09-01 Current versionnot affected

Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Affected versions
  • From (including) 152.0.7977.75 - Up to (excluding) 152.0.7977.75
CVE-2026-82072 HIGH (8.8) 2026-08-27 Current versionnot affected

Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 151.0.7922.72 - Up to (excluding) 151.0.7922.72
CVE-2026-78964 CRITICAL (9.6) 2026-08-25 Current versionnot affected

Use after free in Sync in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-78915 HIGH (7.5) 2026-08-25 Current versionnot affected

Race condition in Enterprise in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Low)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79152 CRITICAL (9.8) 2026-08-25 Current versionnot affected

Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to bypass web origin policy via a co-installed app. (Chromium security severity: Low)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79148 CRITICAL (9.1) 2026-08-25 Current versionnot affected

Off-by-one error in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially read memory inside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79197 HIGH (8.8) 2026-08-25 Current versionnot affected

Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79045 HIGH (8.8) 2026-08-25 Current versionnot affected

Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79223 HIGH (8.8) 2026-08-25 Current versionnot affected

Integer overflow in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory inside the sandbox via a crafted file. (Chromium security severity: Low)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79244 HIGH (8.8) 2026-08-25 Current versionnot affected

Use after free in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79056 CRITICAL (9.6) 2026-08-25 Current versionnot affected

Use after free in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-78956 HIGH (8.8) 2026-08-25 Current versionnot affected

Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79058 CRITICAL (9.1) 2026-08-25 Current versionnot affected

Missing authorization in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79090 CRITICAL (9.8) 2026-08-25 Current versionnot affected

Improper privilege management in Actor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79119 HIGH (8.8) 2026-08-25 Current versionnot affected

Use after free in PDF in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: Low)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-78950 HIGH (8.8) 2026-08-25 Current versionnot affected

Integer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79263 HIGH (8.1) 2026-08-25 Current versionnot affected

Race condition in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via crafted network traffic. (Chromium security severity: Low)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79266 HIGH (8.8) 2026-08-25 Current versionnot affected

Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79073 HIGH (8.8) 2026-08-25 Current versionnot affected

Improper state validation in Parser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79182 HIGH (8.8) 2026-08-25 Current versionnot affected

Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-78963 HIGH (8.8) 2026-08-25 Current versionnot affected

Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79139 HIGH (7.5) 2026-08-25 Current versionnot affected

Improper input validation in Media in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79033 HIGH (8.8) 2026-08-25 Current versionnot affected

Insufficient control flow management in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79227 HIGH (8.8) 2026-08-25 Current versionnot affected

Type confusion in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79097 HIGH (8.8) 2026-08-25 Current versionnot affected

Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-78901 HIGH (7.5) 2026-08-25 Current versionnot affected

Race condition in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-78913 HIGH (8.1) 2026-08-25 Current versionnot affected

Use after free in Chromoting in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79091 CRITICAL (9.6) 2026-08-25 Current versionnot affected

Use after free in Bluetooth in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-78951 CRITICAL (9.6) 2026-08-25 Current versionnot affected

Use after free in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79064 CRITICAL (9.6) 2026-08-25 Current versionnot affected

Use after free in Network in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79230 HIGH (8.8) 2026-08-25 Current versionnot affected

Improper input validation in ANGLE in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-78978 HIGH (8.8) 2026-08-25 Current versionnot affected

Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79245 HIGH (7.7) 2026-08-25 Current versionnot affected

Use after free in UI in Google Chrome prior to 152.0.7977.65 allowed a local attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-78944 HIGH (8.8) 2026-08-25 Current versionnot affected

Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79083 HIGH (7.5) 2026-08-25 Current versionnot affected

Improper enforcement of behavioral workflow in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-78983 HIGH (8.3) 2026-08-25 Current versionnot affected

Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-78892 HIGH (7.1) 2026-08-25 Current versionnot affected

Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a local attacker to bypass system access restrictions via a local program. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79008 HIGH (8.3) 2026-08-25 Current versionnot affected

Improper input validation in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-78905 HIGH (8.8) 2026-08-25 Current versionnot affected

Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79127 HIGH (8.8) 2026-08-25 Current versionnot affected

Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79020 HIGH (8.1) 2026-08-25 Current versionnot affected

Out of bounds read in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted media file. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-78906 HIGH (7.5) 2026-08-25 Current versionnot affected

Race condition in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79132 HIGH (8.3) 2026-08-25 Current versionnot affected

Improper input validation in Input in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79215 HIGH (8.8) 2026-08-25 Current versionnot affected

Integer overflow in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79226 HIGH (8.8) 2026-08-25 Current versionnot affected

Improper privilege management in Regional Capabilities in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-78910 HIGH (8.8) 2026-08-25 Current versionnot affected

Buffer overflow in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79057 HIGH (8.1) 2026-08-25 Current versionnot affected

Race condition in Start in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a co-installed app. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79231 HIGH (8.8) 2026-08-25 Current versionnot affected

Buffer overflow in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-78891 HIGH (8.8) 2026-08-25 Current versionnot affected

Buffer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79128 CRITICAL (9.6) 2026-08-25 Current versionnot affected

Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79140 CRITICAL (9.6) 2026-08-25 Current versionnot affected

Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-78909 CRITICAL (9.6) 2026-08-25 Current versionnot affected

Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-78990 HIGH (8.8) 2026-08-25 Current versionnot affected

Use after free in Compositing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-78937 CRITICAL (9.6) 2026-08-25 Current versionnot affected

Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79129 CRITICAL (9.6) 2026-08-25 Current versionnot affected

Use after free in Sessions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79210 HIGH (8.3) 2026-08-25 Current versionnot affected

Use after free in Audio in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-78985 CRITICAL (9.6) 2026-08-25 Current versionnot affected

Incorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79256 HIGH (8.3) 2026-08-25 Current versionnot affected

Externally controlled reference in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79109 HIGH (8.3) 2026-08-25 Current versionnot affected

Improper input validation in Printing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-78999 HIGH (8.3) 2026-08-25 Current versionnot affected

Improper privilege management in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-78945 CRITICAL (9.6) 2026-08-25 Current versionnot affected

Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79286 HIGH (7.4) 2026-08-25 Current versionnot affected

Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a co-installed app. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79071 HIGH (8.3) 2026-08-25 Current versionnot affected

Race condition in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79216 HIGH (7.5) 2026-08-25 Current versionnot affected

Buffer overflow in Blink in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79209 HIGH (8.8) 2026-08-25 Current versionnot affected

Type confusion in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79078 CRITICAL (9.6) 2026-08-25 Current versionnot affected

Use after free in FedCM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79236 HIGH (8.8) 2026-08-25 Current versionnot affected

Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-78952 HIGH (8.3) 2026-08-25 Current versionnot affected

Out of bounds write in Crashpad in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-78938 HIGH (8.8) 2026-08-25 Current versionnot affected

Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-78899 HIGH (8.8) 2026-08-25 Current versionnot affected

Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-78904 CRITICAL (9.6) 2026-08-25 Current versionnot affected

Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79027 HIGH (8.1) 2026-08-25 Current versionnot affected

Use after free in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via crafted network traffic. (Chromium security severity: High)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79026 CRITICAL (9.6) 2026-08-25 Current versionnot affected

Use after free in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: High)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79138 CRITICAL (9.6) 2026-08-25 Current versionnot affected

Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79275 CRITICAL (9.6) 2026-08-25 Current versionnot affected

Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79149 CRITICAL (9.6) 2026-08-25 Current versionnot affected

Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79131 CRITICAL (9.6) 2026-08-25 Current versionnot affected

Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65
CVE-2026-79198 HIGH (8.8) 2026-08-25 Current versionnot affected

Use after free in Platform in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • From (including) 152.0.7977.65 - Up to (excluding) 152.0.7977.65

585 further matching CVEs are not displayed. The table shows the 100 most relevant of 685, recently published first.