VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,735 CVE recordsPage 488 of 1316 · EPSS data 2026.08.12
ReviewCritical
CVE-2026-13909

Google Chrome, chrome

Insufficient policy enforcement in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13903

Google Chrome, chrome

Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-13901

Google Chrome, chrome

Insufficient policy enforcement in Serial in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13899

Google Chrome, chrome

Use after free in HTML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13898

Google Chrome, chrome

Use after free in Cast Receiver in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13897

Google Chrome, chrome

Insufficient policy enforcement in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13891

Google Chrome, chrome, macos

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13888

Google Chrome, chrome, macos

Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13885

Google Chrome, chrome, android

Use after free in Skia in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13884

Google Chrome, chrome

Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a local attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-13883

Google Chrome, chrome, macos

Type Confusion in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-13882

Google Chrome, chrome, macos

Race in USB in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-13880

Google Chrome, chrome, macos

Use after free in USB in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-13878

Google Chrome, chrome, macos

Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-13872

Google Chrome, chrome, android

Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.