Security Risk Category
Browser Security Risks — Page 3
Published vulnerability pages connected to Browser. Each page keeps one canonical URL and focused remediation guidance.
215 published Browser risks
Browser risks
Showing 73–108 of 215 published risks.
CVE-2026-14906 in Firefox for iOS
Pages with malicious titles could potentially allow saved PDF content to overwrite PDF files or bundled content within the Firefox for iOS application sandbox. This vulnerability was fixed in Firefox for iOS 152.4.
Updated Jul 15, 2026
CVE-2026-62197 in OpenClaw
OpenClaw before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accepts blocked WebSocket URLs. Attackers with lower-trust access can reach network destinations that should have been blocked by OpenClaw policy when the affected feature is enabled.
Updated Jul 15, 2026
CVE-2026-15718 in Firefox
We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6.
Updated Jul 15, 2026
CVE-2026-15719 in Firefox
We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6.
Updated Jul 15, 2026
CVE-2026-50521 in Microsoft Edge Chromium
Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
Updated Jul 14, 2026
CVE-2026-14381 in Google Chrome WebAppInstalls
Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Updated Jul 14, 2026
CVE-2026-14382 in Google Chrome ANGLE
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Updated Jul 14, 2026
CVE-2026-14383 in Google Chrome V8
Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Updated Jul 14, 2026
CVE-2026-14384 in Google Chrome ANGLE
Out of bounds read in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Updated Jul 14, 2026
CVE-2026-14385 in Google Chrome ANGLE
Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Updated Jul 14, 2026
CVE-2026-14386 in Google Chrome ANGLE
Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
Updated Jul 14, 2026
CVE-2026-14387 in Google Chrome Skia
Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Updated Jul 14, 2026
CVE-2026-14388 in Google Chrome ANGLE
Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Updated Jul 14, 2026
CVE-2026-14389 in Google Chrome Skia
Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Updated Jul 14, 2026
CVE-2026-14390 in Google Chrome ANGLE
Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Updated Jul 14, 2026
CVE-2026-14391 in Google Chrome ANGLE
Integer overflow in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Updated Jul 14, 2026
CVE-2026-14392 in Google Chrome Tint
Out of bounds write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Updated Jul 14, 2026
CVE-2026-14393 in Google Chrome V8
Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Updated Jul 14, 2026
CVE-2026-14394 in Google Chrome V8
Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
Updated Jul 14, 2026
CVE-2026-14395 in Google Chrome V8
Out of bounds write in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
Updated Jul 14, 2026
CVE-2026-14396 in Google Chrome ANGLE
Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Updated Jul 14, 2026
CVE-2026-14397 in Google Chrome ANGLE
Out of bounds write in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Updated Jul 14, 2026
CVE-2026-14398 in Google Chrome ANGLE
Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Updated Jul 14, 2026
CVE-2026-14399 in Google Chrome Dawn
Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Updated Jul 14, 2026
CVE-2026-14400 in Google Chrome ANGLE
Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Updated Jul 14, 2026
CVE-2026-14401 in Google Chrome ANGLE
Insufficient validation of untrusted input in ANGLE in Google Chrome on Android prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Updated Jul 14, 2026
CVE-2026-14402 in Google Chrome ANGLE
Uninitialized Use in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
Updated Jul 14, 2026
CVE-2026-14403 in Google Chrome V8
Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
Updated Jul 14, 2026
CVE-2026-14404 in Google Chrome PDFium
Inappropriate implementation in PDFium in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI spoofing via a crafted PDF file. (Chromium security severity: Medium)
Updated Jul 14, 2026
CVE-2026-14405 in Google Chrome V8
Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
Updated Jul 14, 2026
CVE-2026-14406 in Google Chrome V8
Out of bounds read in V8 in Google Chrome prior to 150.0.7871.46 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. (Chromium security severity: Medium)
Updated Jul 14, 2026
CVE-2026-14407 in Google Chrome V8
Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Updated Jul 14, 2026
CVE-2026-14408 in Google Chrome Dawn
Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Updated Jul 14, 2026
CVE-2026-14409 in Google Chrome V8
Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
Updated Jul 14, 2026
CVE-2026-14410 in Google Chrome Skia
Inappropriate implementation in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Updated Jul 14, 2026
CVE-2026-14411 in Google Chrome ANGLE
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Updated Jul 14, 2026
