Google Vulnerabilities and Affected Products
Vulnerabilities associated with Chrome.
Products
Clear product- Chrome4,306 vulnerabilities
- Android1,376 vulnerabilities
- pixel56 vulnerabilities
- Chromium V839 vulnerabilities
- ChromeOS12 vulnerabilities
- android_kernel6 vulnerabilities
- AngularJS6 vulnerabilities
- Chromium6 vulnerabilities
- gRPC6 vulnerabilities
- MCP Toolbox for Databases (googleapis/mcp-toolbox)6 vulnerabilities
- mcp-toolbox5 vulnerabilities
- gVisor4 vulnerabilities
- Keras4 vulnerabilities
- Nearby3 vulnerabilities
- admob2 vulnerabilities
- Andrioid2 vulnerabilities
- Chromium Blink2 vulnerabilities
- Chromium Intents2 vulnerabilities
- Chromium Mojo2 vulnerabilities
- Chromium Skia2 vulnerabilities
- Fuchsia2 vulnerabilities
- libjxl2 vulnerabilities
- MCP Toolbox for Databases2 vulnerabilities
- Nest Wifi Pro2 vulnerabilities
- Omaha2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-19560HIGH | Generated title:Google Chrome Blink Use-After-Free VulnerabilityUse after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CWE-416Aug 11, 2026 | CVSS8.8v3.1 | EPSS0.344% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-19559HIGH | Generated title:Google Chrome HTML Use-After-Free Sandboxed Arbitrary Code ExecutionUse after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CWE-416Aug 11, 2026 | CVSS8.8v3.1 | EPSS0.344% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-19558HIGH | Generated title:Google Chrome Extensions Use-After-FreeUse after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High) CWE-416Aug 11, 2026 | CVSS7.5v3.1 | EPSS0.233% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-19557HIGH | Generated title:Google Chrome TabStrip Use-After-Free on MacUse after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CWE-416Aug 11, 2026 | CVSS8.3v3.1 | EPSS0.266% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-19556HIGH | Generated title:Google Chrome V8 Use-After-Free VulnerabilityUse after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CWE-416Aug 11, 2026 | CVSS8.8v3.1 | EPSS0.344% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-19177HIGH | Generated title:Google Chrome Insufficient Input Validation in UI Leading to Sandbox EscapeInsufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CWE-20Aug 6, 2026 | CVSS8.3v3.1 | EPSS0.357% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-19176HIGH | Generated title:Google Chrome Skia Use-After-Free VulnerabilityUse after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CWE-416Aug 6, 2026 | CVSS7.5v3.1 | EPSS0.4% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-19175CRITICAL | Generated title:Google Chrome Payments Use-After-Free VulnerabilityUse after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CWE-416Aug 6, 2026 | CVSS9.6v3.1 | EPSS0.295% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-19174HIGH | Generated title:Google Chrome V8 Integer Overflow Remote Code ExecutionInteger overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CWE-190Aug 6, 2026 | CVSS8.8v3.1 | EPSS0.353% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-19173HIGH | Generated title:Google Chrome Skia Out-of-Bounds Write Leading to Sandbox EscapeOut of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CWE-787Aug 6, 2026 | CVSS8.3v3.1 | EPSS0.267% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-19171CRITICAL | Generated title:Google Chrome Media Use-After-FreeUse after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CWE-416Aug 6, 2026 | CVSS9.6v3.1 | EPSS0.295% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Generated title:Google Chrome GPU Integer Overflow Leading to Cross-Origin Data LeakInteger overflow in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) CWE-190Aug 6, 2026 | CVSS3.1v3.1 | EPSS0.261% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-19166CRITICAL | Generated title:Google Chrome Web Authentication Use-After-FreeUse after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CWE-416Aug 6, 2026 | CVSS9.6v3.1 | EPSS0.336% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-19165HIGH | Generated title:Google Chrome Extensions Use-After-FreeUse after free in Extensions in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High) CWE-416Aug 6, 2026 | CVSS7.5v3.1 | EPSS0.234% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-19164CRITICAL | Generated title:Google Chrome Codecs Insufficient Input Validation Leading to Sandbox EscapeInsufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CWE-20Aug 6, 2026 | CVSS9.6v3.1 | EPSS0.295% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-19163HIGH | Generated title:Google Chrome Media Use-After-Free on WindowsUse after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CWE-416Aug 6, 2026 | CVSS8.3v3.1 | EPSS0.267% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-19162HIGH | Generated title:Google Chrome V8 Out-of-Bounds Write Remote Code ExecutionOut of bounds write in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CWE-787Aug 6, 2026 | CVSS8.8v3.1 | EPSS0.353% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Generated title:Google Chrome Skia Uninitialized Use Cross-Origin Data LeakUninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) CWE-457Aug 6, 2026 | CVSS3.1v3.1 | EPSS0.235% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Generated title:Google Chrome Skia Uninitialized Use Cross-Origin Data LeakUninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) CWE-457Aug 6, 2026 | CVSS3.1v3.1 | EPSS0.284% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-19159HIGH | Generated title:Google Chrome Views Use-After-Free VulnerabilityUse after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CWE-416Aug 6, 2026 | CVSS7.5v3.1 | EPSS0.335% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-19158HIGH | Generated title:Google Chrome Views Use-After-Free VulnerabilityUse after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CWE-416Aug 6, 2026 | CVSS7.5v3.1 | EPSS0.335% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-19156HIGH | Generated title:Google Chrome Heap Buffer Overflow in BaseHeap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High) CWE-122Aug 6, 2026 | CVSS7.5v3.1 | EPSS0.225% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-19155HIGH | Generated title:Google Chrome Payments Use-After-FreeUse after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CWE-416Aug 6, 2026 | CVSS8.3v3.1 | EPSS0.267% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-19153HIGH | Generated title:Google Chrome Insufficient Input Validation in Workers Leading to Site Isolation BypassInsufficient validation of untrusted input in Workers in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High) CWE-20Aug 6, 2026 | CVSS8.1v3.1 | EPSS0.291% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-19152HIGH | Generated title:Google Chrome Insufficient Policy Enforcement in Navigation Allows Sandbox EscapeInsufficient policy enforcement in Navigation in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CWE-693Aug 6, 2026 | CVSS8.3v3.1 | EPSS0.267% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |