Security Risk Category

Browser Security Risks — Page 6

Published vulnerability pages connected to Browser. Each page keeps one canonical URL and focused remediation guidance.

215 published Browser risks

Browser risks

Showing 181–215 of 215 published risks.

highEPSS 0.002

Google Chrome IndexedDB Use-After-Free Code Execution Vulnerability

Use after free in IndexedDB in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-15107browserremote-code-executionmemory-corruption

Updated Jul 10, 2026

mediumEPSS 0.001

Google Chrome Extensions API Integer Overflow Out-of-Bounds Read Vulnerability

Integer overflow in Extensions API in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted Chrome Extension. (Chromium security severity: High)

CVE-2026-15108browserapi-securityinput-validationinformation-disclosure

Updated Jul 10, 2026

mediumEPSS 0.002

Google Chrome ANGLE Uninitialized Memory Disclosure Vulnerability

Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15109browserinformation-disclosurememory-corruption

Updated Jul 10, 2026

highEPSS 0.001

Google Chrome Extensions Use-After-Free Heap Corruption Vulnerability

Use after free in Extensions in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)

CVE-2026-15110browsermemory-corruption

Updated Jul 10, 2026

highEPSS 0.002

Google Chrome Views Use-After-Free Heap Corruption Vulnerability

Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15111browsermemory-corruption

Updated Jul 10, 2026

highEPSS 0.002

Google Chrome Ozone Use-After-Free Heap Corruption Vulnerability

Use after free in Ozone in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-15112browsermemory-corruption

Updated Jul 10, 2026

criticalEPSS 0.002

Google Chrome Android Autofill Use-After-Free Sandbox Escape Vulnerability

Use after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15113browsermemory-corruption

Updated Jul 10, 2026

highEPSS 0.001

Google Chrome Codecs Out-of-Bounds Video Heap Corruption Vulnerability

Out of bounds read and write in Codecs in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: High)

CVE-2026-15114browserinformation-disclosurememory-corruption

Updated Jul 10, 2026

lowEPSS 0.001

Google Chrome Android WebAppInstalls Same-Origin Policy Bypass Vulnerability

Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.115 allowed a local attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15115browserweb-applicationinput-validation

Updated Jul 10, 2026

highEPSS 0.002

Google Chrome Actor Use-After-Free Code Execution Vulnerability

Use after free in Actor in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15116browserremote-code-executionmemory-corruption

Updated Jul 10, 2026

highEPSS 0.002

Google Chrome Payments Use-After-Free Heap Corruption Vulnerability

Use after free in Payments in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15117browsermemory-corruption

Updated Jul 10, 2026

highEPSS 0.002

Google Chrome Input Use-After-Free Code Execution Vulnerability

Use after free in Input in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15118browserremote-code-executionmemory-corruption

Updated Jul 10, 2026

highEPSS 0.002

Google Chrome GetUserMedia Race Condition Sandbox Escape Vulnerability

Race in GetUserMedia in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15119browserrace-condition

Updated Jul 10, 2026

highEPSS 0.002

Google Chrome Windows Core Use-After-Free Sandbox Escape Vulnerability

Use after free in Core in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15120browserwindowsmemory-corruption

Updated Jul 10, 2026

highEPSS 0.002

Google Chrome WebRTC Use-After-Free Code Execution Vulnerability

Use after free in WebRTC in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15121browserremote-code-executionmemory-corruption

Updated Jul 10, 2026

highEPSS 0.002

Google Chrome Windows Codecs Sandbox Escape Vulnerability

Insufficient validation of untrusted input in Codecs in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15122browserwindowsinput-validation

Updated Jul 10, 2026

highEPSS 0.002

Google Chrome DOM Heap Corruption Vulnerability

Inappropriate implementation in DOM in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15123browsermemory-corruption

Updated Jul 10, 2026

mediumEPSS 0.002

Google Chrome Passwords Same-Origin Policy Bypass Vulnerability

Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15124browserinput-validation

Updated Jul 10, 2026

highEPSS 0.002

Google Chrome Forms Inappropriate Implementation Code Execution Vulnerability

Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15125browserremote-code-executionauthorization-bypass

Updated Jul 10, 2026

highEPSS 0.002

Google Chrome Forms Use-After-Free Code Execution Vulnerability

Use after free in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15126browserremote-code-executionmemory-corruption

Updated Jul 10, 2026

mediumEPSS 0.002

Google Chrome WebGL Universal Cross-Site Scripting Vulnerability

Inappropriate implementation in WebGL in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15127browserxss

Updated Jul 10, 2026

mediumEPSS 0.002

Google Chrome Forms Universal Cross-Site Scripting Vulnerability

Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15128browserxss

Updated Jul 10, 2026

highEPSS 0.002

Google Chrome Views Use-After-Free Heap Corruption Vulnerability

Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-15129browsermemory-corruption

Updated Jul 10, 2026

mediumEPSS 0.002

Google Chrome Navigation Policy Enforcement Site Isolation Bypass Vulnerability

Insufficient policy enforcement in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15130browser

Updated Jul 10, 2026

mediumEPSS 0.002

Google Chrome Navigation Site Isolation Bypass Vulnerability

Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-15131browserinput-validation

Updated Jul 10, 2026

highEPSS 0.002

Google Chrome V8 Uninitialized Use Code Execution Vulnerability

Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15132browserremote-code-executionmemory-corruption

Updated Jul 10, 2026

highEPSS 0.002

Google Chrome InterestGroups Use-After-Free Code Execution Vulnerability

Use after free in InterestGroups in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15133browserremote-code-executionmemory-corruption

Updated Jul 10, 2026

highEPSS 0.001

Cline Hub Dashboard WebSocket Origin Validation Vulnerability

Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. Prior to 3.0.30, the Cline Hub dashboard server launched by the cline dashboard command accepts WebSocket connections on the /browser endpoint without validating the Origin header, and when ROOM_SECRET is unset for local 127.0.0.1 binds, isAuthorizedBrowserRequest() allows attacker-controlled websites to send desktopCommand frames that read workspace state, mutate MCP and provider settings, and trigger command execution when a provider or model is configured. This issue is fixed in version 3.0.30.

CVE-2026-59723browserapi-securityremote-code-execution

Updated Jul 10, 2026

mediumEPSS 0.002

Download Manager WordPress Plugin Stored Cross-Site Scripting Vulnerability

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes in all versions up to, and including, 3.3.61 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Because wp_kses_post filters post content on save for users without unfiltered_html, only kses-allowed tag and attribute payloads that survive save-time filtering will reach the unescaped sink; however, the sink itself remains unsafe and such payloads can still execute in the browser when a user renders the shortcode.

CVE-2026-14343wordpressbrowserxss

Updated Jul 10, 2026

mediumEPSS 0.001

Nozomi Guardian and CMC Diagram and Graph Stored HTML Injection Vulnerability

A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation function being insufficiently restrictive. An authenticated user with administrative privileges can inject malicious HTML tags into N2OS configuration data through multiple input vectors. When a victim views the affected data in the Diagram tab and Graph view, the injected HTML renders in their browser, enabling phishing and possibly open redirect attacks. Full XSS exploitation and direct information disclosure are prevented by the existing input validation and Content Security Policy configuration.

CVE-2026-31981browserindustrial-controlinput-validationxss

Updated Jul 10, 2026

high

Divi Torque Lite REST API CSRF Plugin Installation Vulnerability

The Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.3. This is due to the use of '__return_true' as the permission_callback for the /install_plugin and /activate_plugin REST API endpoints, which bypasses WordPress's built-in REST API nonce verification. Although the endpoint callbacks contain internal current_user_can() checks, the absence of nonce verification means that a forged cross-site request from a logged-in administrator's browser will pass the capability check via the admin's session cookies. This makes it possible for unauthenticated attackers to install arbitrary plugins from WordPress.

CVE-2026-4275wordpressbrowserapi-securitysupply-chain

Updated Jul 10, 2026

criticalCISA KEVEPSS 0.017

Google Chromium V8 Out-of-Bounds Read and Write Vulnerability

Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2026-11645browsermicrosoftremote-code-executioninformation-disclosure

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.919

Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CVE-2010-0249browsermicrosoftremote-code-executionmemory-corruption

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.822

Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CVE-2010-0806browsermicrosoftremote-code-executionmemory-corruption

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.056

Microsoft Exchange Server Cross-Site Scripting Vulnerability

Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.

CVE-2026-42897npmbrowsermicrosoftxss

Updated Jul 9, 2026