CVE-2026-7871
published 2026-06-30CVE-2026-7871: IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets…
PriorityP260critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.69%
51.2th percentile
IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets, data, and system integrity.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | langflow_oss | 1.0.0 – 1.10.0 | — |
| langflow | langflow | 1.0.0 – 1.10.0 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets, data, and system integrity.
ghsa_unreviewed·2026-06-30
CVE-2026-7871 [CRITICAL] CWE-502 IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets, data, and system integrity.
IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets, data, and system integrity.
Red Hat
chromium-browser: angle: Chromium: Sandbox escape via out-of-bounds write in ANGLE
vendor_redhat·2026-07-21·CVSS 8.3
CVE-2026-16413 [HIGH] CWE-787 chromium-browser: angle: Chromium: Sandbox escape via out-of-bounds write in ANGLE
chromium-browser: angle: Chromium: Sandbox escape via out-of-bounds write in ANGLE
Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
A flaw was found in ANGLE, a component of Chromium. A remote attacker who has compromised the renderer process could exploit an out-of-bounds write vulnerability by crafting a malicious HTML page. This could potentially allow the attacker to escape the sandbox, leading to further system compromise.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Out of support scope
Package: webkitgtk3 (Red Hat Enterprise Linux 7) - Not affected
Package: webkitgtk4 (Red Hat Enterprise
Red Hat
chromium-browser: chromium-browser: Use after free in UI
vendor_redhat·2026-07-14·CVSS 7.5
CVE-2026-15777 [HIGH] CWE-825 chromium-browser: chromium-browser: Use after free in UI
chromium-browser: chromium-browser: Use after free in UI
Use after free in UI in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
An use after free flaw was found in the UI component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=532929679
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Red Hat
chromium-browser: chromium-browser: Use after free in Views
vendor_redhat·2026-07-08·CVSS 8.8
CVE-2026-15129 [HIGH] CWE-825 chromium-browser: chromium-browser: Use after free in Views
chromium-browser: chromium-browser: Use after free in Views
Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
An use after free flaw was found in the Views component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=524045160
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Red Hat
chromium-browser: Use after free in Extensions
vendor_redhat·2026-06-30·CVSS 8.1
CVE-2026-13774 [HIGH] CWE-825 chromium-browser: Use after free in Extensions
chromium-browser: Use after free in Extensions
Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Critical)
An use after free flaw was found in the Extensions component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=506558270
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Red Hat
chromium-browser: chromium-browser: Out of bounds read in ANGLE
vendor_redhat·2026-06-30·CVSS 6.5
CVE-2026-14384 [MEDIUM] CWE-125 chromium-browser: chromium-browser: Out of bounds read in ANGLE
chromium-browser: chromium-browser: Out of bounds read in ANGLE
Out of bounds read in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
An out of bounds read flaw was found in the ANGLE component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=497543485
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Red Hat
chromium-browser: Insufficient policy enforcement in Bluetooth
vendor_redhat·2026-06-30·CVSS 8.8
CVE-2026-13903 [HIGH] CWE-266 chromium-browser: Insufficient policy enforcement in Bluetooth
chromium-browser: Insufficient policy enforcement in Bluetooth
Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
An insufficient policy enforcement flaw was found in the Bluetooth component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=503912196
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Red Hat
chromium-browser: Inappropriate implementation in Enterprise
vendor_redhat·2026-06-30·CVSS 5.3
CVE-2026-14112 [MEDIUM] CWE-312 chromium-browser: Inappropriate implementation in Enterprise
chromium-browser: Inappropriate implementation in Enterprise
Inappropriate implementation in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
An inappropriate implementation flaw was found in the Enterprise component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=513713946
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Red Hat
chromium-browser: Side-channel information leakage in CSS
vendor_redhat·2026-06-30·CVSS 6.5
CVE-2026-14085 [MEDIUM] CWE-205 chromium-browser: Side-channel information leakage in CSS
chromium-browser: Side-channel information leakage in CSS
Side-channel information leakage in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
A side-channel information leakage flaw was found in the CSS component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=513155863
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Red Hat
chromium-browser: Uninitialized Use in Dawn
vendor_redhat·2026-06-30·CVSS 8.8
CVE-2026-13825 [HIGH] CWE-824 chromium-browser: Uninitialized Use in Dawn
chromium-browser: Uninitialized Use in Dawn
Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
An uninitialized use flaw was found in the Dawn component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=513209610
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Red Hat
chromium-browser: Insufficient validation of untrusted input in HTML
vendor_redhat·2026-06-30·CVSS 6.1
CVE-2026-14083 [MEDIUM] CWE-79 chromium-browser: Insufficient validation of untrusted input in HTML
chromium-browser: Insufficient validation of untrusted input in HTML
Insufficient validation of untrusted input in HTML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)
An insufficient validation of untrusted input flaw was found in the HTML component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=513128322
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Red Hat
chromium-browser: Incorrect security UI in SplitView
vendor_redhat·2026-06-30·CVSS 4.2
CVE-2026-14030 [MEDIUM] CWE-1021 chromium-browser: Incorrect security UI in SplitView
chromium-browser: Incorrect security UI in SplitView
Inappropriate implementation in SplitView in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)
An incorrect security ui flaw was found in the SplitView component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=488762971
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Red Hat
chromium-browser: Type Confusion in Dawn
vendor_redhat·2026-06-30·CVSS 9.8
CVE-2026-13776 [CRITICAL] CWE-843 chromium-browser: Type Confusion in Dawn
chromium-browser: Type Confusion in Dawn
Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
A type confusion flaw was found in the Dawn component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=513012139
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Red Hat
chromium-browser: Inappropriate implementation in WebXR
vendor_redhat·2026-06-30·CVSS 4.3
CVE-2026-14034 [MEDIUM] CWE-358 chromium-browser: Inappropriate implementation in WebXR
chromium-browser: Inappropriate implementation in WebXR
Inappropriate implementation in WebXR in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
An inappropriate implementation flaw was found in the WebXR component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=496368832
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Red Hat
chromium-browser: Policy bypass in StorageAccessAPI
vendor_redhat·2026-06-30·CVSS 6.5
CVE-2026-14156 [MEDIUM] CWE-346 chromium-browser: Policy bypass in StorageAccessAPI
chromium-browser: Policy bypass in StorageAccessAPI
Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)
A policy bypass flaw was found in the StorageAccessAPI component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=518247789
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Red Hat
chromium-browser: chromium-browser: Incorrect security UI in WebAppInstalls
vendor_redhat·2026-06-30·CVSS 6.5
CVE-2026-14381 [MEDIUM] CWE-1021 chromium-browser: chromium-browser: Incorrect security UI in WebAppInstalls
chromium-browser: chromium-browser: Incorrect security UI in WebAppInstalls
Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
An incorrect security ui flaw was found in the WebAppInstalls component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=407283320
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Red Hat
chromium-browser: Inappropriate implementation in WebAppInstalls
vendor_redhat·2026-06-30·CVSS 4.2
CVE-2026-14138 [MEDIUM] CWE-1021 chromium-browser: Inappropriate implementation in WebAppInstalls
chromium-browser: Inappropriate implementation in WebAppInstalls
Inappropriate implementation in WebAppInstalls in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
An inappropriate implementation flaw was found in the WebAppInstalls component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=514071775
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-14125 webkitgtk: Uninitialized Use in ANGLE [epel-all]
bugzilla·2026-09-24·CVSS 6.5
CVE-2026-14125 [MEDIUM] CVE-2026-14125 webkitgtk: Uninitialized Use in ANGLE [epel-all]
CVE-2026-14125 webkitgtk: Uninitialized Use in ANGLE [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
Bugzilla
CVE-2026-16413 CVE-2026-16414 CVE-2026-16415 CVE-2026-16416 CVE-2026-16417 CVE-2026-16418 CVE-2026-16419 CVE-2026-16420 CVE-2026-16421 CVE-2026-16422 CVE-2026-16423 CVE-2026-16424 chromium: various fl
bugzilla·2026-07-28·CVSS 8.3
CVE-2026-16413 [HIGH] CVE-2026-16413 CVE-2026-16414 CVE-2026-16415 CVE-2026-16416 CVE-2026-16417 CVE-2026-16418 CVE-2026-16419 CVE-2026-16420 CVE-2026-16421 CVE-2026-16422 CVE-2026-16423 CVE-2026-16424 chromium: various fl
CVE-2026-16413 CVE-2026-16414 CVE-2026-16415 CVE-2026-16416 CVE-2026-16417 CVE-2026-16418 CVE-2026-16419 CVE-2026-16420 CVE-2026-16421 CVE-2026-16422 CVE-2026-16423 CVE-2026-16424 chromium: various flaws [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacke
Bugzilla
CVE-2026-13029 chromium: chromium-browser: Use after free in Web Authentication [epel-all]
bugzilla·2026-07-24·CVSS 7.5
CVE-2026-13029 [HIGH] CVE-2026-13029 chromium: chromium-browser: Use after free in Web Authentication [epel-all]
CVE-2026-13029 chromium: chromium-browser: Use after free in Web Authentication [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Use after free in Web Authentication in Google Chrome prior to 149.0.7827.197 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
Discussion:
Fixed in chromium-150.0.7871.128
Bugzilla
CVE-2026-15775 chromium-browser: chromium-browser: Insufficient policy enforcement in V8
bugzilla·2026-07-14·CVSS 6.5
CVE-2026-15775 [MEDIUM] CVE-2026-15775 chromium-browser: chromium-browser: Insufficient policy enforcement in V8
CVE-2026-15775 chromium-browser: chromium-browser: Insufficient policy enforcement in V8
Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
Bugzilla
CVE-2026-15773 chromium-browser: chromium-browser: Use after free in Core
bugzilla·2026-07-14·CVSS 9.6
CVE-2026-15773 [CRITICAL] CVE-2026-15773 chromium-browser: chromium-browser: Use after free in Core
CVE-2026-15773 chromium-browser: chromium-browser: Use after free in Core
Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Bugzilla
CVE-2026-15765 chromium-browser: chromium-browser: Use after free in Ozone
bugzilla·2026-07-14·CVSS 7.5
CVE-2026-15765 [HIGH] CVE-2026-15765 chromium-browser: chromium-browser: Use after free in Ozone
CVE-2026-15765 chromium-browser: chromium-browser: Use after free in Ozone
Use after free in Ozone in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Bugzilla
CVE-2026-15131 chromium-browser: chromium-browser: Insufficient data validation in Navigation
bugzilla·2026-07-08·CVSS 4.3
CVE-2026-15131 [MEDIUM] CVE-2026-15131 chromium-browser: chromium-browser: Insufficient data validation in Navigation
CVE-2026-15131 chromium-browser: chromium-browser: Insufficient data validation in Navigation
Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Bugzilla
CVE-2026-14085 chromium-browser: Side-channel information leakage in CSS
bugzilla·2026-07-01·CVSS 6.5
CVE-2026-14085 [MEDIUM] CVE-2026-14085 chromium-browser: Side-channel information leakage in CSS
CVE-2026-14085 chromium-browser: Side-channel information leakage in CSS
Side-channel information leakage in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Bugzilla
CVE-2026-13796 chromium-browser: Integer overflow in Chromecast
bugzilla·2026-07-01·CVSS 9.6
CVE-2026-13796 [CRITICAL] CVE-2026-13796 chromium-browser: Integer overflow in Chromecast
CVE-2026-13796 chromium-browser: Integer overflow in Chromecast
Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Bugzilla
CVE-2026-14018 chromium-browser: Use after free in Updater
bugzilla·2026-07-01·CVSS 7.8
CVE-2026-14018 [HIGH] CVE-2026-14018 chromium-browser: Use after free in Updater
CVE-2026-14018 chromium-browser: Use after free in Updater
Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)
Bugzilla
CVE-2026-14114 chromium-browser: Inappropriate implementation in WebAppInstalls
bugzilla·2026-07-01·CVSS 7.5
CVE-2026-14114 [HIGH] CVE-2026-14114 chromium-browser: Inappropriate implementation in WebAppInstalls
CVE-2026-14114 chromium-browser: Inappropriate implementation in WebAppInstalls
Inappropriate implementation in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium security severity: Low)
Bugzilla
CVE-2026-14015 chromium-browser: Inappropriate implementation in WebRTC
bugzilla·2026-07-01·CVSS 6.5
CVE-2026-14015 [MEDIUM] CVE-2026-14015 chromium-browser: Inappropriate implementation in WebRTC
CVE-2026-14015 chromium-browser: Inappropriate implementation in WebRTC
Race in WebRTC in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Bugzilla
CVE-2026-14406 chromium-browser: chromium-browser: Out of bounds read in V8
bugzilla·2026-07-01·CVSS 5.9
CVE-2026-14406 [MEDIUM] CVE-2026-14406 chromium-browser: chromium-browser: Out of bounds read in V8
CVE-2026-14406 chromium-browser: chromium-browser: Out of bounds read in V8
Out of bounds read in V8 in Google Chrome prior to 150.0.7871.46 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. (Chromium security severity: Medium)
Bugzilla
CVE-2026-13866 chromium-browser: Insufficient validation of untrusted input in Input
bugzilla·2026-07-01·CVSS 6.5
CVE-2026-13866 [MEDIUM] CVE-2026-13866 chromium-browser: Insufficient validation of untrusted input in Input
CVE-2026-13866 chromium-browser: Insufficient validation of untrusted input in Input
Inappropriate implementation in Input in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Bugzilla
CVE-2026-14145 chromium-browser: Inappropriate implementation in CSS
bugzilla·2026-07-01·CVSS 6.1
CVE-2026-14145 [MEDIUM] CVE-2026-14145 chromium-browser: Inappropriate implementation in CSS
CVE-2026-14145 chromium-browser: Inappropriate implementation in CSS
Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)
Bugzilla
CVE-2026-14431 chromium-browser: chromium-browser: Type Confusion in V8
bugzilla·2026-07-01·CVSS 8.8
CVE-2026-14431 [HIGH] CVE-2026-14431 chromium-browser: chromium-browser: Type Confusion in V8
CVE-2026-14431 chromium-browser: chromium-browser: Type Confusion in V8
Type Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Bugzilla
CVE-2026-14025 chromium-browser: Use after free in Views
bugzilla·2026-07-01·CVSS 8.8
CVE-2026-14025 [HIGH] CVE-2026-14025 chromium-browser: Use after free in Views
CVE-2026-14025 chromium-browser: Use after free in Views
Use after free in Views in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
Bugzilla
CVE-2026-13798 chromium-browser: Heap buffer overflow in Chromecast
bugzilla·2026-07-01·CVSS 9.6
CVE-2026-13798 [CRITICAL] CVE-2026-13798 chromium-browser: Heap buffer overflow in Chromecast
CVE-2026-13798 chromium-browser: Heap buffer overflow in Chromecast
Heap buffer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Bugzilla
CVE-2026-14404 chromium-browser: chromium-browser: Inappropriate implementation in PDFium
bugzilla·2026-07-01·CVSS 6.5
CVE-2026-14404 [MEDIUM] CVE-2026-14404 chromium-browser: chromium-browser: Inappropriate implementation in PDFium
CVE-2026-14404 chromium-browser: chromium-browser: Inappropriate implementation in PDFium
Inappropriate implementation in PDFium in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI spoofing via a crafted PDF file. (Chromium security severity: Medium)
Bugzilla
CVE-2026-13828 chromium-browser: Inappropriate implementation in Enterprise
bugzilla·2026-07-01·CVSS 6.5
CVE-2026-13828 [MEDIUM] CVE-2026-13828 chromium-browser: Inappropriate implementation in Enterprise
CVE-2026-13828 chromium-browser: Inappropriate implementation in Enterprise
Inappropriate implementation in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
2026-06-30
Published