Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.3 MS:CVE-2026-11254

Chromium: CVE-2026-11254 Inappropriate implementation in Permissions_MS:CVE-2026-11254

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
MEDIUM 6.5 MS:CVE-2026-10985

Chromium: CVE-2026-10985 Out of bounds read in Skia_MS:CVE-2026-10985

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
MEDIUM 6.5 MS:CVE-2026-11039

Chromium: CVE-2026-11039 Uninitialized Use in Skia_MS:CVE-2026-11039

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
MEDIUM 5.7 MS:CVE-2026-11199

Chromium: CVE-2026-11199 Insufficient validation of untrusted input in WebRTC_MS:CVE-2026-11199

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
MEDIUM 6.1 CVE-2026-11150

CVE-2026-11150_CVE-2026-11150

Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) vi...

Google Chrome 149.0.7827.53 CVE
MEDIUM 6.5 CVE-2026-11148

CVE-2026-11148_CVE-2026-11148

Inappropriate implementation in Payments in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to leak cross-origin data via ...

Google Chrome 149.0.7827.53 CVE
MEDIUM 6.5 CVE-2026-11145

CVE-2026-11145_CVE-2026-11145

Race in Geolocation in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page....

Google Chrome 149.0.7827.53 CVE
MEDIUM 6.5 CVE-2026-11143

CVE-2026-11143_CVE-2026-11143

Out of bounds read in Extensions in Google Chrome on Linux prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious e...

Google Chrome 149.0.7827.53 CVE
MEDIUM 6.5 CVE-2026-11142

CVE-2026-11142_CVE-2026-11142

Insufficient policy enforcement in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a craft...

Google Chrome 149.0.7827.53 CVE
MEDIUM 6.5 CVE-2026-11141

CVE-2026-11141_CVE-2026-11141

Uninitialized Use in Audio in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain pot...

Google Chrome 149.0.7827.53 CVE