VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,735 CVE recordsPage 485 of 1316 · EPSS data 2026.08.12
ReviewCritical
CVE-2026-14097

Google Chrome, chrome, macos

Inappropriate implementation in WebAppInstalls in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-14095

Google Chrome, chrome, macos

Insufficient policy enforcement in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14094

Google Chrome, chrome, windows

Use after free in Installer in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-14093

Google Chrome, chrome, macos

Use after free in Cast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14091

Google Chrome, chrome, macos

Use after free in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14090

Google Chrome, chrome, chrome os

Insufficient validation of untrusted input in CameraCapture in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14087

Google Chrome, chrome, windows

Heap buffer overflow in WebNN in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14086

Google Chrome, chrome

Insufficient policy enforcement in HID in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14084

Google Chrome, chrome

Insufficient validation of untrusted input in Chromoting in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14078

Google Chrome, chrome

Insufficient validation of untrusted input in WebRTC in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14067

Google Chrome, chrome, iphone os

Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14064

Google Chrome, chrome, android

Use after free in PageInfo in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14060

Google Chrome, chrome, windows

Insufficient validation of untrusted input in Chromoting in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-14056

Google Chrome, chrome

Insufficient validation of untrusted input in Media in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-14055

Google Chrome, chrome, windows

Insufficient validation of untrusted input in Device Trust in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.