VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,695 CVE recordsPage 711 of 1313 · EPSS data 2026.08.12
ReviewHigh
CVE-2026-11169

Google Chrome, chrome, macos

Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted XML file. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-11167

Google Chrome, chrome, android

Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-11165

Google Chrome, chrome, iphone os

Use after free in WebMIDI in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-11164

Google Chrome, chrome, macos

Use after free in Blink in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-11163

Google Chrome, chrome, android

Use after free in Messages in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-11158

Google Chrome, chrome, macos

Insufficient validation of untrusted input in Downloads in Google Chrome on Mac prior to 149.0.7827.53 allowed a local attacker to potentially perform a sandbox escape via a crafted AppleScript command. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-11154

Google Chrome, chrome, macos

Use after free in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-11153

Google Chrome, chrome, macos

Side-channel information leakage in Forms in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-11152

Google Chrome, chrome, macos

Object lifecycle issue in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-11151

Google Chrome, chrome, macos

Insufficient validation of untrusted input in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-11149

Google Chrome, chrome, macos

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-11147

Google Chrome, chrome, windows

Use after free in WebML in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-11146

Google Chrome, chrome, macos

Insufficient validation of untrusted input in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-11144

Google Chrome, chrome, macos

Use after free in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-11136

Google Chrome, chrome, macos

Use after free in Canvas in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.