Security Risk Category

Browser Security Risks — Page 3

Published vulnerability pages connected to Browser. Each page keeps one canonical URL and focused remediation guidance.

215 published Browser risks

Browser risks

Showing 73–108 of 215 published risks.

mediumEPSS 0.002

CVE-2026-14906 in Firefox for iOS

Pages with malicious titles could potentially allow saved PDF content to overwrite PDF files or bundled content within the Firefox for iOS application sandbox. This vulnerability was fixed in Firefox for iOS 152.4.

CVE-2026-14906browserinput-validationfile-uploadfile-write

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-62197 in OpenClaw

OpenClaw before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accepts blocked WebSocket URLs. Attackers with lower-trust access can reach network destinations that should have been blocked by OpenClaw policy when the affected feature is enabled.

CVE-2026-62197npmbrowserapi-securityauthorization-bypass

Updated Jul 15, 2026

medium

CVE-2026-15718 in Firefox

We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6.

CVE-2026-15718browserinput-validation

Updated Jul 15, 2026

medium

CVE-2026-15719 in Firefox

We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6.

CVE-2026-15719browserinput-validation

Updated Jul 15, 2026

highEPSS 0.008

CVE-2026-50521 in Microsoft Edge Chromium

Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

CVE-2026-50521browsermicrosoftremote-code-executionmemory-corruption

Updated Jul 14, 2026

medium

CVE-2026-14381 in Google Chrome WebAppInstalls

Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14381browserweb-applicationinput-validationauthentication-bypass

Updated Jul 14, 2026

criticalEPSS 0.003

CVE-2026-14382 in Google Chrome ANGLE

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14382browserremote-code-executioninput-validation

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14383 in Google Chrome V8

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14383browserremote-code-executioninput-validationmemory-corruption

Updated Jul 14, 2026

mediumEPSS 0.003

CVE-2026-14384 in Google Chrome ANGLE

Out of bounds read in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14384browserwindowsinformation-disclosurememory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14385 in Google Chrome ANGLE

Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14385browsermemory-corruption

Updated Jul 14, 2026

mediumEPSS 0.003

CVE-2026-14386 in Google Chrome ANGLE

Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14386browserinformation-disclosurememory-corruption

Updated Jul 14, 2026

criticalEPSS 0.003

CVE-2026-14387 in Google Chrome Skia

Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14387browserremote-code-executioninput-validation

Updated Jul 14, 2026

mediumEPSS 0.003

CVE-2026-14388 in Google Chrome ANGLE

Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14388browserinformation-disclosurememory-corruption

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-14389 in Google Chrome Skia

Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14389browserremote-code-executioninput-validation

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-14390 in Google Chrome ANGLE

Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14390browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-14391 in Google Chrome ANGLE

Integer overflow in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14391browserwindowsinput-validationinformation-disclosure

Updated Jul 14, 2026

criticalEPSS 0.003

CVE-2026-14392 in Google Chrome Tint

Out of bounds write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14392browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14393 in Google Chrome V8

Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14393browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-14394 in Google Chrome V8

Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-14394browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14395 in Google Chrome V8

Out of bounds write in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-14395browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-14396 in Google Chrome ANGLE

Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14396browserinformation-disclosurememory-corruption

Updated Jul 14, 2026

criticalEPSS 0.003

CVE-2026-14397 in Google Chrome ANGLE

Out of bounds write in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14397browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-14398 in Google Chrome ANGLE

Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-14398browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-14399 in Google Chrome Dawn

Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14399browserinformation-disclosurememory-corruption

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-14400 in Google Chrome ANGLE

Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14400browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-14401 in Google Chrome ANGLE

Insufficient validation of untrusted input in ANGLE in Google Chrome on Android prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14401browserremote-code-executioninput-validation

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-14402 in Google Chrome ANGLE

Uninitialized Use in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14402browserwindowsinformation-disclosurememory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14403 in Google Chrome V8

Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-14403browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-14404 in Google Chrome PDFium

Inappropriate implementation in PDFium in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI spoofing via a crafted PDF file. (Chromium security severity: Medium)

CVE-2026-14404browserinput-validation

Updated Jul 14, 2026

criticalEPSS 0.003

CVE-2026-14405 in Google Chrome V8

Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-14405browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-14406 in Google Chrome V8

Out of bounds read in V8 in Google Chrome prior to 150.0.7871.46 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. (Chromium security severity: Medium)

CVE-2026-14406browserinformation-disclosurememory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14407 in Google Chrome V8

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14407browserremote-code-executioninput-validationmemory-corruption

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-14408 in Google Chrome Dawn

Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14408browserinformation-disclosurememory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14409 in Google Chrome V8

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-14409browserremote-code-executioninput-validation

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-14410 in Google Chrome Skia

Inappropriate implementation in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-14410browserinput-validation

Updated Jul 14, 2026

criticalEPSS 0.003

CVE-2026-14411 in Google Chrome ANGLE

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14411browserremote-code-executioninput-validation

Updated Jul 14, 2026