Security Risk Category

Browser Security Risks — Page 4

Published vulnerability pages connected to Browser. Each page keeps one canonical URL and focused remediation guidance.

215 published Browser risks

Browser risks

Showing 109–144 of 215 published risks.

highEPSS 0.002

CVE-2026-14412 in Google Chrome ANGLE

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14412browserremote-code-executioninput-validation

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-14413 in Google Chrome ANGLE

Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14413browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-14414 in Google Chrome Skia

Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14414browserinput-validationinformation-disclosurememory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14415 in Google Chrome V8

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-14415browserremote-code-executioninput-validationmemory-corruption

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-14416 in Google Chrome Dawn

Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-14416browserremote-code-executioninformation-disclosurememory-corruption

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-14417 in Google Chrome Dawn

Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-14417browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-14418 in Google Chrome ANGLE

Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14418browserinformation-disclosurememory-corruption

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-14419 in Google Chrome Skia

Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-14419browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

criticalEPSS 0.003

CVE-2026-14420 in Google Chrome Dawn

Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-14420browserremote-code-executioninformation-disclosurememory-corruption

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-14421 in Google Chrome Dawn

Uninitialized Use in Dawn in Google Chrome on ChromeOS prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14421browserinformation-disclosurememory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14422 in Google Chrome Tint

Out of bounds read and write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14422browserinformation-disclosurememory-corruption

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-14423 in Google Chrome Tint

Type Confusion in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14423browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-14424 in Google Chrome Dawn

Use after free in Dawn in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14424browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-14425 in Google Chrome ANGLE

Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14425browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-14426 in Google Chrome V8

Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14426browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-14427 in Google Chrome Skia

Heap buffer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-14427browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14428 in Google Chrome Dawn

Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14428browserinput-validationmemory-corruption

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-14429 in Google Chrome Skia

Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14429browserinput-validationmemory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14430 in Google Chrome V8

Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14430browserremote-code-executioninput-validationmemory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14431 in Google Chrome V8

Type Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14431browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-14432 in Google Chrome V8

Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14432browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

medium

CVE-2025-71385 Netdata Vulnerability

Netdata before 2.3.1 reflects the user-supplied love query parameter of the api/v2/ilove.svg and api/v3/ilove.svg endpoints verbatim into the generated SVG document (into a text element) without HTML or XML escaping, and serves the response with Content-Type image/svg+xml. An attacker can craft a URL such as /api/v2/ilove.svg?love=<script>...</script>; when a victim navigates to it the injected script executes in the victim browser in the origin of the Netdata instance (reflected cross-site scripting). These endpoints are registered with HTTP_ACL_NOCHECK and anonymous access and, because bearer-token protection is disabled by default, are reachable without authentication on a default Netdata agent. The issue was resolved by removing the ilove endpoint.

CVE-2025-71385browserapi-securityweb-applicationxss

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-45488 edge chromium vulnerability

User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-45488browsermicrosoft

Updated Jul 14, 2026

mediumEPSS 0.005

CVE-2026-45489 edge chromium vulnerability

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVE-2026-45489browsermicrosoftauthentication-bypass

Updated Jul 14, 2026

mediumEPSS 0.001

CVE-2026-55945 edge chromium vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.

CVE-2026-55945browsermicrosoftrace-condition

Updated Jul 14, 2026

highEPSS 0.006

CVE-2026-56645 edge chromium vulnerability

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-56645browsermicrosoftmemory-corruption

Updated Jul 14, 2026

mediumEPSS 0.007

CVE-2026-56646 edge chromium vulnerability

Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-56646browsermicrosoftinformation-disclosure

Updated Jul 14, 2026

highEPSS 0.006

CVE-2026-57974 edge chromium vulnerability

Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-57974browsermicrosoftinput-validation

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-57975 edge chromium vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-57975browsermicrosoftmemory-corruption

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-57977 edge chromium vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-57977browsermicrosoftxss

Updated Jul 14, 2026

highEPSS 0.006

CVE-2026-57981 edge chromium vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-57981browsermicrosoftmemory-corruption

Updated Jul 14, 2026

highEPSS 0.005

CVE-2026-57983 edge chromium vulnerability

Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-57983browsermicrosoftauthorization-bypass

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-57984 edge chromium vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-57984browsermicrosoftmemory-corruption

Updated Jul 14, 2026

highEPSS 0.005

CVE-2026-57985 edge chromium vulnerability

Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-57985browsermicrosoftinput-validation

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-57986 edge chromium vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-57986browsermicrosoftmemory-corruption

Updated Jul 14, 2026

mediumEPSS 0.006

CVE-2026-57987 edge chromium vulnerability

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-57987browsermicrosoftssrf

Updated Jul 14, 2026