Skip to content
Threat Feed

CPE

Cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

16 briefs RSS
high advisory

Chromium V8 Engine Out-of-Bounds Memory Access Vulnerability

CVE-2026-0899 is an out-of-bounds memory access vulnerability in the Chromium V8 JavaScript engine that may result in memory corruption, process crashes, or arbitrary code execution.

Chromium vulnerability browser-security
1c
high threat

UNC3569 Exploitation of Sogou Input Method to Deploy GRAYRABBIT Backdoor

UNC3569 exploited a command-line argument injection flaw in Sogou Input Method to trigger an insecure Chromium component and execute the GRAYRABBIT backdoor.

Sogou Input Method UNC3569 backdoor exploitation cve-2026-51990 grayrabbit
1r 4t 1c 6i
critical threat

Active Exploitation of Google Chromium V8 Type Confusion Vulnerability

A type confusion vulnerability in the Google Chromium V8 engine is being actively exploited in the wild, allowing remote attackers to achieve arbitrary code execution within the sandbox environment via crafted HTML pages.

exploited Chromium V8 +8 vulnerability chromium browser-security
1t 2c updated
low advisory

Denial of Service Vulnerability in libtasn1

A vulnerability in the libtasn1 library tracked as CVE-2024-11111 allows a remote, anonymous attacker to cause a Denial of Service condition, potentially impacting applications that rely on the library for ASN.1 structure processing.

libtasn1
1c
critical advisory

Multiple Vulnerabilities in Google Chrome and Microsoft Edge

Multiple vulnerabilities in Google Chrome and Microsoft Edge allow remote, unauthenticated attackers to achieve arbitrary code execution, bypass sandbox protections, and perform information disclosure.

Chrome +9 vulnerability browser-security patch-management
1t 2c updated
critical advisory

Vulnerabilities in Nokogiri Vendored libxml2 and libxslt Libraries

Nokogiri versions prior to 1.13.2 bundle vulnerable libxml2 2.9.12 and libxslt 1.1.34 libraries, exposing applications to denial of service, memory disclosure, and potential code execution.

Nokogiri +2 vulnerability memory-corruption libxslt
3c
medium advisory

Privilege Escalation Vulnerability in SALTO ProAccess Space

An authenticated attacker can exploit CVE-2026-11889, a privilege escalation vulnerability in SALTO ProAccess Space versions prior to 6.13, to bypass authorization controls and access spaces outside their assigned partition within the same installation, provided the partitioning feature is enabled.

SALTO ProAccess Space <6.13 privilege-escalation ICS authorization-bypass
1t 1c
high advisory

Google Security Updates — July 2026

Roundup of Google security advisories published in July 2026.

golang.org/x/crypto/ssh +74 roundup
5c 41i updated
high advisory

Multiple Vulnerabilities in Google Chrome (CVE-2026-13774 through CVE-2026-13895)

Multiple vulnerabilities, including CVE-2026-13774 through CVE-2026-13895, have been discovered in Google Chrome, allowing an attacker to cause an unspecified security problem on affected Windows, Linux, and macOS systems by exploiting these flaws.

PoC Chrome +5 vulnerability patch-management browser google-chrome cve chromium v8 rce +1
5c 5i updated
medium advisory

Multiple Vulnerabilities in Microsoft Edge Allow Security Policy Bypass

Multiple vulnerabilities, including CVE-2026-10883, CVE-2026-10892, and others, have been discovered in Microsoft Edge versions prior to 149.0.4022.53, enabling an attacker to bypass security policies and potentially cause other unspecified security issues within the browser environment.

Microsoft Edge browser-vulnerability security-policy-bypass client-side-exploit microsoft-edge
2r 2t 5c 48i
high advisory

CVE-2026-7473: Arista EOS Incomplete Comparison Vulnerability Leading to Incorrect Packet Forwarding

Arista Extensible Operating System (EOS) contains CVE-2026-7473, an incomplete comparison vulnerability that allows a switch to incorrectly decapsulate and forward unexpected tunneled packets if their destination IP matches the switch's configured decapsulation IP, potentially leading to unauthorized network access or bypass of security controls.

PoC Extensible Operating System +4 vulnerability cve network-device infrastructure
2r 3t 3c updated
high advisory

Multiple Vulnerabilities in Microsoft Edge Allow for Privilege Escalation, Data Breach, and Security Policy Bypass

Multiple vulnerabilities in Microsoft Edge and Microsoft Edge for Android can allow an attacker to perform privilege escalation, cause a data breach, and bypass security policies.

Edge +1 vulnerability privilege-escalation data-breach security-policy-bypass
2r 1t 1c
high advisory

CVE-2026-7928 Use-After-Free Vulnerability in WebRTC

CVE-2026-7928 is a use-after-free vulnerability in the WebRTC component of Chromium, affecting Google Chrome and Microsoft Edge (Chromium-based) and potentially allowing for arbitrary code execution.

Edge +1 use-after-free webrtc chromium cve remote-code-execution
2r 4t 1c
high advisory

CVE-2026-7925 Use-After-Free Vulnerability in Chromium Chromoting

CVE-2026-7925 is a use-after-free vulnerability in the Chromoting component of Google Chrome, also affecting Microsoft Edge.

Chrome +1 use-after-free vulnerability chromoting
2r 1c
high advisory

Chromium Type Confusion Vulnerability in Accessibility (CVE-2026-7914)

CVE-2026-7914 is a type confusion vulnerability in the Accessibility component of Chromium, also affecting Microsoft Edge.

Chrome +1 cve-2026-7914 type confusion chromium
2r 2t 1c
high advisory

Chromium CVE-2026-7906 Use-After-Free in SVG

CVE-2026-7906 is a use-after-free vulnerability in the SVG component of Chromium, also affecting Microsoft Edge.

Chrome +1 chromium use-after-free svg cve-2026-7906
2r 1c