Описание
Security update for chromium
This update for chromium fixes the following issues:
Changes in chromium:
- Chromium 151.0.7922.71 (boo#1272936):
- CVE-2026-17650: Use after free in Compositing
- CVE-2026-17651: Insufficient validation of untrusted input in Dawn
- CVE-2026-17652: Use after free in Views
- CVE-2026-17653: Use after free in Skia
- CVE-2026-17654: Race in Updater
- CVE-2026-17655: Insufficient validation of untrusted input in ANGLE
- CVE-2026-17656: Use after free in Ozone
- CVE-2026-17657: Use after free in Navigation
- CVE-2026-17658: Use after free in V8
- CVE-2026-17659: Inappropriate implementation in SiteIsolation
- CVE-2026-17660: Insufficient validation of untrusted input in Network
- CVE-2026-17661: Use after free in Loader
- CVE-2026-17662: Insufficient policy enforcement in Prefetch
- CVE-2026-17663: Insufficient validation of untrusted input in GPU
- CVE-2026-17664: Insufficient validation of untrusted input in Loader
- CVE-2026-17665: Use after free in V8
- CVE-2026-17666: Cryptographic Flaw in Enterprise
- CVE-2026-17667: Uninitialized Use in ANGLE
- CVE-2026-17668: Uninitialized Use in ANGLE
- CVE-2026-17669: Inappropriate implementation in Chrome for iOS
- CVE-2026-17670: Use after free in Views
- CVE-2026-17671: Insufficient validation of untrusted input in ANGLE
- CVE-2026-17672: Insufficient validation of untrusted input in Chromecast
- CVE-2026-17673: Integer overflow in QUIC
- CVE-2026-17674: Inappropriate implementation in HTML
- CVE-2026-17675: Out of bounds write in ANGLE
- CVE-2026-17676: Inappropriate implementation in ANGLE
- CVE-2026-17677: Inappropriate implementation in ANGLE
- CVE-2026-17678: Out of bounds read in ANGLE
- CVE-2026-17679: Insufficient validation of untrusted input in Print Preview
- CVE-2026-17680: Heap buffer overflow in Color
- CVE-2026-17681: Insufficient validation of untrusted input in Web Authentication
- CVE-2026-17682: Integer overflow in ANGLE
- CVE-2026-17683: Inappropriate implementation in ANGLE
- CVE-2026-17684: Insufficient validation of untrusted input in Chrome for iOS
- CVE-2026-17685: Use after free in Autofill
- CVE-2026-17686: Insufficient validation of untrusted input in Passwords
- CVE-2026-17687: Type Confusion in ANGLE
- CVE-2026-17688: Use after free in Input
- CVE-2026-17689: Uninitialized Use in ANGLE
- CVE-2026-17690: Insufficient validation of untrusted input in PDF
- CVE-2026-17691: Out of bounds write in ANGLE
- CVE-2026-17692: Use after free in DataTransfer
- CVE-2026-17693: Inappropriate implementation in FileSystem
- CVE-2026-17694: Use after free in DOM
- CVE-2026-17695: Inappropriate implementation in ANGLE
- CVE-2026-17696: Side-channel information leakage in Media
- CVE-2026-17697: Type Confusion in ANGLE
- CVE-2026-17698: Insufficient validation of untrusted input in UI
- CVE-2026-17699: Use after free in Views
- CVE-2026-17700: Insufficient validation of untrusted input in Actor
- CVE-2026-17701: Out of bounds read in ANGLE
- CVE-2026-17702: Inappropriate implementation in Skia
- CVE-2026-17703: Policy bypass in Chrome for iOS
- CVE-2026-17704: Use after free in ANGLE
- CVE-2026-17705: Integer overflow in libxml
- CVE-2026-17706: Insufficient validation of untrusted input in Media
- CVE-2026-17707: Uninitialized Use in Media
- CVE-2026-17708: Use after free in Audio
- CVE-2026-17709: Race in Downloads
- CVE-2026-17710: Inappropriate implementation in MHTML
- CVE-2026-17711: Race in Downloads
- CVE-2026-17712: Race in Skia
- CVE-2026-17713: Insufficient validation of untrusted input in Accessibility
- CVE-2026-17714: Uninitialized Use in ANGLE
- CVE-2026-17715: Inappropriate implementation in Passwords
- CVE-2026-17716: Use after free in Updater
- CVE-2026-17717: Integer overflow in ANGLE
- CVE-2026-17718: Use after free in ANGLE
- CVE-2026-17719: Use after free in Input
- CVE-2026-17720: Insufficient policy enforcement in Passwords
- CVE-2026-17721: Out of bounds write in ANGLE
- CVE-2026-17722: Object lifecycle issue in WebView
- CVE-2026-17723: Use after free in Media
- CVE-2026-17724: Race in Chrome for iOS
- CVE-2026-17725: Type Confusion in V8
- CVE-2026-17726: Integer overflow in WebGL
- CVE-2026-17727: Out of bounds write in WebGL
- CVE-2026-17728: Inappropriate implementation in Extensions
- CVE-2026-17758: Heap buffer overflow in Dawn
- CVE-2026-17732: Inappropriate implementation in SVG
- CVE-2026-17729: Use after free in V8
- CVE-2026-17730: Side-channel information leakage in Autofill
- CVE-2026-17731: Inappropriate implementation in Autofill
- CVE-2026-17733: Inappropriate implementation in QUIC
- CVE-2026-17734: Inappropriate implementation in Autofill
- CVE-2026-17735: Insufficient validation of untrusted input in BFCache
- CVE-2026-17736: Insufficient validation of untrusted input in WebView
- CVE-2026-17737: Use after free in Bluetooth
- CVE-2026-17738: Insufficient validation of untrusted input in Payments
- CVE-2026-17739: Insufficient policy enforcement in Extensions
- CVE-2026-17740: Uninitialized Use in ANGLE
- CVE-2026-17741: Insufficient validation of untrusted input in WebView
- CVE-2026-17742: Insufficient policy enforcement in Payments
- CVE-2026-17743: Insufficient policy enforcement in ControlledFrame
- CVE-2026-17744: Inappropriate implementation in File Input
- CVE-2026-17745: Out of bounds read in Skia
- CVE-2026-17746: Use after free in GPU
- CVE-2026-17747: Insufficient validation of untrusted input in Payments
- CVE-2026-17748: Inappropriate implementation in Extensions
- CVE-2026-17749: Insufficient validation of untrusted input in Extensions
- CVE-2026-17750: Use after free in ANGLE
- CVE-2026-17751: Inappropriate implementation in AdFilter
- CVE-2026-17752: Use after free in Views
- CVE-2026-17753: Inappropriate implementation in Autofill
- CVE-2026-17754: Inappropriate implementation in Blink
- CVE-2026-17755: Incorrect security UI in Extensions
- CVE-2026-17756: Insufficient policy enforcement in Presentation
- CVE-2026-17757: Uninitialized Use in Skia
- CVE-2026-17759: Uninitialized Use in Codecs
- CVE-2026-17760: Side-channel information leakage in NoStatePrefetch
- CVE-2026-17761: Insufficient validation of untrusted input in Chrome for iOS
- CVE-2026-17762: Inappropriate implementation in Chrome for iOS
- CVE-2026-17763: Inappropriate implementation in GPU
- CVE-2026-17764: Inappropriate implementation in FedCM
- CVE-2026-17765: Inappropriate implementation in WebProtect
- CVE-2026-17766: Insufficient validation of untrusted input in Clipboard
- CVE-2026-17767: Insufficient validation of untrusted input in WebView
- CVE-2026-17768: Insufficient validation of untrusted input in WebSockets
- CVE-2026-17769: Insufficient validation of untrusted input in Cast
- CVE-2026-17770: Out of bounds read in Media
- CVE-2026-17771: Uninitialized Use in Skia
- CVE-2026-17772: Out of bounds read in WebGL
- CVE-2026-17773: Insufficient validation of untrusted input in Cast
- CVE-2026-17774: Insufficient validation of untrusted input in Variations
- CVE-2026-17775: Inappropriate implementation in PresentationAPI
- CVE-2026-17776: Policy bypass in Receiver
- CVE-2026-17777: Inappropriate implementation in Autofill
- CVE-2026-17778: Use after free in Extensions
- CVE-2026-17779: Inappropriate implementation in Site Isolation
- CVE-2026-17780: Inappropriate implementation in Isolated Web Apps
- CVE-2026-17781: Inappropriate implementation in Extensions
- CVE-2026-17782: Incorrect security UI in Chrome for iOS
- CVE-2026-17783: Inappropriate implementation in Loader
- CVE-2026-17784: Use after free in Audio
- CVE-2026-17785: Uninitialized Use in ANGLE
- CVE-2026-17786: Insufficient validation of untrusted input in DevTools
- CVE-2026-17787: Inappropriate implementation in DevTools
- CVE-2026-17788: Inappropriate implementation in Blink
- CVE-2026-17789: Insufficient validation of untrusted input in Chrome for iOS
- CVE-2026-17790: Uninitialized Use in ANGLE
- CVE-2026-17791: Insufficient validation of untrusted input in Payments
- CVE-2026-17792: Inappropriate implementation in Credential Management
- CVE-2026-17793: Inappropriate implementation in Messages
- CVE-2026-17794: Insufficient validation of untrusted input in Mobile
- CVE-2026-17795: Insufficient validation of untrusted input in GetUserMedia
- CVE-2026-17796: Side-channel information leakage in WebXR
- CVE-2026-17797: Inappropriate implementation in CSS
- CVE-2026-17798: Inappropriate implementation in Cast
- CVE-2026-17799: Insufficient validation of untrusted input in Safe Browsing
- CVE-2026-17800: Side-channel information leakage in MediaRecording
- CVE-2026-17801: Out of bounds memory access in ANGLE
- CVE-2026-17802: Side-channel information leakage in GPU
- CVE-2026-17803: Insufficient validation of untrusted input in Save to Drive
- CVE-2026-17804: Use after free in Media
- CVE-2026-17805: Insufficient policy enforcement in Glic
- CVE-2026-17806: Insufficient validation of untrusted input in Extensions
- CVE-2026-17807: Use after free in V8
- CVE-2026-17808: Uninitialized Use in WebGL
- CVE-2026-17809: Insufficient validation of untrusted input in Extensions
- CVE-2026-17810: Uninitialized Use in Dawn
- CVE-2026-17811: Use after free in ANGLE
- CVE-2026-17812: Inappropriate implementation in DigitalCredentials
- CVE-2026-17813: Insufficient policy enforcement in Chrome for iOS
- CVE-2026-17814: Insufficient validation of untrusted input in Chrome for iOS
- CVE-2026-17815: Insufficient policy enforcement in GuestView
- CVE-2026-17816: Inappropriate implementation in Speech
- CVE-2026-17817: Inappropriate implementation in ReportingAndNEL
- CVE-2026-17818: Inappropriate implementation in Network
- CVE-2026-17819: Inappropriate implementation in WebAppInstalls
- CVE-2026-17820: Insufficient policy enforcement in Autofill
- CVE-2026-17821: Insufficient policy enforcement in Extensions
- CVE-2026-17822: Inappropriate implementation in Chrome for iOS
- CVE-2026-17823: Insufficient policy enforcement in WebXR
- CVE-2026-17824: Insufficient policy enforcement in ServiceWorker
- CVE-2026-17825: Insufficient policy enforcement in Passwords
- CVE-2026-17826: Inappropriate implementation in Chrome for iOS
- CVE-2026-17827: Inappropriate implementation in CSS
- CVE-2026-17828: Inappropriate implementation in Chrome for iOS
- CVE-2026-17829: Insufficient policy enforcement in Passwords
- CVE-2026-17830: Inappropriate implementation in Chrome for iOS
- CVE-2026-17831: Insufficient validation of untrusted input in Passwords
- CVE-2026-17832: Use after free in ANGLE
- CVE-2026-17833: Inappropriate implementation in Passwords
- CVE-2026-17834: Inappropriate implementation in Passwords
- CVE-2026-17835: Inappropriate implementation in Chrome for iOS
- CVE-2026-17836: Use after free in V8
- CVE-2026-17837: Insufficient validation of untrusted input in DevTools
- CVE-2026-17838: Incorrect security UI in Chrome for iOS
- CVE-2026-17839: Inappropriate implementation in Chrome for iOS
- CVE-2026-17840: Incorrect security UI in Passwords
- CVE-2026-17841: Race in Chrome for iOS
- CVE-2026-17842: Inappropriate implementation in Chrome for iOS
- CVE-2026-17843: Inappropriate implementation in CSS
- CVE-2026-17844: Insufficient validation of untrusted input in Cast
- CVE-2026-17845: Inappropriate implementation in CSS
- CVE-2026-17846: Inappropriate implementation in Media
- CVE-2026-17847: Insufficient validation of untrusted input in ANGLE
- CVE-2026-17848: Insufficient validation of untrusted input in Codecs
- CVE-2026-17849: Inappropriate implementation in Chrome for iOS
- CVE-2026-17850: Inappropriate implementation in Permissions
- CVE-2026-17851: Side-channel information leakage in Autofill
- CVE-2026-17852: Inappropriate implementation in Media Router
- CVE-2026-17853: Inappropriate implementation in DevTools
- CVE-2026-17854: Insufficient policy enforcement in WebMCP
- CVE-2026-17855: Race in DevTools
- CVE-2026-17856: Inappropriate implementation in Network
- CVE-2026-17857: Inappropriate implementation in Network
- CVE-2026-17858: Uninitialized Use in WebNN
- CVE-2026-17859: Side-channel information leakage in Favicons
- CVE-2026-17860: Insufficient validation of untrusted input in Mobile
- CVE-2026-17861: Insufficient validation of untrusted input in Updater
- CVE-2026-17862: Use after free in Tracing
- CVE-2026-17863: Inappropriate implementation in Browser
- CVE-2026-17864: Inappropriate implementation in Updater
- CVE-2026-17865: Inappropriate implementation in Crypto
- CVE-2026-17866: Type Confusion in Tab
- CVE-2026-17867: Insufficient validation of untrusted input in Dawn
- CVE-2026-17868: Insufficient policy enforcement in USB
- CVE-2026-17869: Out of bounds read in WebXR
- CVE-2026-17870: Insufficient validation of untrusted input in Cast
- CVE-2026-17871: Inappropriate implementation in Passwords
- CVE-2026-17872: Cryptographic Flaw in WebAppInstalls
- CVE-2026-17873: Insufficient policy enforcement in Chrome for iOS
- CVE-2026-17874: Inappropriate implementation in Chrome for iOS
- CVE-2026-17875: Use after free in PDFium
- CVE-2026-17876: Inappropriate implementation in Payments
- CVE-2026-17877: Inappropriate implementation in Chromoting
- CVE-2026-17878: Inappropriate implementation in CSS
- CVE-2026-17879: Inappropriate implementation in Autofill
- CVE-2026-17880: Inappropriate implementation in Autofill
- CVE-2026-17881: Use after free in WebXR
- CVE-2026-17882: Policy bypass in Extensions
- CVE-2026-17883: Inappropriate implementation in Headless
- CVE-2026-17884: Object lifecycle issue in WebRTC
- CVE-2026-17885: Inappropriate implementation in Paint
- CVE-2026-17886: Use after free in Enterprise
- CVE-2026-17887: Use after free in TabStrip
- CVE-2026-17888: Insufficient validation of untrusted input in WebUI
- CVE-2026-17889: Uninitialized Use in WebXR
- CVE-2026-17890: Insufficient validation of untrusted input in DevTools
- CVE-2026-17891: Use after free in ANGLE
- CVE-2026-17892: Inappropriate implementation in WebXR
- CVE-2026-17893: Insufficient validation of untrusted input in Updater
- CVE-2026-17894: Use after free in Views
- CVE-2026-17895: Inappropriate implementation in DataTransfer
- CVE-2026-17896: Use after free in DevTools
- CVE-2026-17897: Inappropriate implementation in ORB
- CVE-2026-17898: Use after free in DevTools
- CVE-2026-17899: Insufficient policy enforcement in DevTools
- CVE-2026-17900: Inappropriate implementation in Enterprise
- CVE-2026-17901: Inappropriate implementation in Sharing
- CVE-2026-17902: Inappropriate implementation in Editing
- CVE-2026-17903: Insufficient policy enforcement in Chromecast
- CVE-2026-17904: Insufficient policy enforcement in NFC
- CVE-2026-17905: Inappropriate implementation in SurfaceCapture
- CVE-2026-17906: Insufficient validation of untrusted input in Bluetooth
- CVE-2026-17907: Side-channel information leakage in Network
- CVE-2026-17908: Insufficient validation of untrusted input in Printing
- CVE-2026-17909: Insufficient validation of untrusted input in Isolated Web Apps
- CVE-2026-17910: Insufficient policy enforcement in NFC
- CVE-2026-17911: Insufficient policy enforcement in SVG
- CVE-2026-17912: Inappropriate implementation in Chrome for iOS
- CVE-2026-17913: Inappropriate implementation in Chrome for iOS
- CVE-2026-17914: Side-channel information leakage in Skia
- CVE-2026-17915: Inappropriate implementation in WebView
- CVE-2026-17916: Insufficient policy enforcement in Settings
- CVE-2026-17917: Policy bypass in Chrome for iOS
- CVE-2026-17918: Use after free in Sync
- CVE-2026-17919: Insufficient policy enforcement in Enterprise
- CVE-2026-17920: Use after free in V8
- CVE-2026-17921: Insufficient validation of untrusted input in Navigation
- CVE-2026-17922: Inappropriate implementation in Enterprise
- CVE-2026-17923: Policy bypass in Enterprise
- CVE-2026-17924: Use after free in DNS
- CVE-2026-17925: Inappropriate implementation in Cast
- CVE-2026-17926: Insufficient validation of untrusted input in DevTools
- CVE-2026-17927: Insufficient policy enforcement in DevTools
- CVE-2026-17928: Inappropriate implementation in DataTransfer
- CVE-2026-17929: Insufficient validation of untrusted input in DevTools
- CVE-2026-17930: Insufficient validation of untrusted input in Extensions
- CVE-2026-17931: Inappropriate implementation in DevTools
- CVE-2026-17932: Use after free in DataTransfer
- CVE-2026-17933: Inappropriate implementation in DOMStorage
- CVE-2026-17934: Insufficient validation of untrusted input in DevTools
- CVE-2026-17935: Heap buffer overflow in Codecs
- CVE-2026-17936: Inappropriate implementation in DevTools
- CVE-2026-17937: Inappropriate implementation in DevTools
- CVE-2026-17938: Inappropriate implementation in FullScreen
- CVE-2026-17939: Inappropriate implementation in Passwords
- CVE-2026-17940: Insufficient validation of untrusted input in Picture-in-Picture
- CVE-2026-17941: Inappropriate implementation in Chrome for iOS
- CVE-2026-17942: Side-channel information leakage in SVG
- CVE-2026-17943: Inappropriate implementation in Parser
- CVE-2026-17944: Inappropriate implementation in Chrome for iOS
- CVE-2026-17945: Inappropriate implementation in Navigation
- CVE-2026-17946: Uninitialized Use in Dawn
- CVE-2026-17947: Use after free in WebSockets
- CVE-2026-17948: Type Confusion in V8
- CVE-2026-17949: Uninitialized Use in GPU
- CVE-2026-17950: Policy bypass in Safebrowsing
- CVE-2026-17951: Heap buffer overflow in WebRTC
- CVE-2026-17952: Inappropriate implementation in V8
- CVE-2026-17953: Insufficient policy enforcement in WebView
- CVE-2026-17954: Policy bypass in MHTML
- CVE-2026-17955: Insufficient validation of untrusted input in Payments
- CVE-2026-17956: Inappropriate implementation in Scheduling
- CVE-2026-17957: Inappropriate implementation in CORS
- CVE-2026-17958: Inappropriate implementation in Views
- CVE-2026-17959: Inappropriate implementation in Network
- CVE-2026-17960: Inappropriate implementation in Chrome for iOS
- CVE-2026-17961: Inappropriate implementation in Session
- CVE-2026-17962: Inappropriate implementation in Blink
- CVE-2026-17963: Inappropriate implementation in SVG
- CVE-2026-17964: Incorrect security UI in UI
- CVE-2026-17965: Incorrect security UI in Chrome for iOS
- CVE-2026-17966: Inappropriate implementation in Views
- CVE-2026-17967: Use after free in Chrome for iOS
- CVE-2026-17968: Uninitialized Use in WebXR
- CVE-2026-17969: Inappropriate implementation in Passwords
- CVE-2026-17970: Insufficient validation of untrusted input in Passwords
- CVE-2026-17971: Inappropriate implementation in Frame
- CVE-2026-17972: Inappropriate implementation in Chrome for iOS
- CVE-2026-17973: Inappropriate implementation in Views
- CVE-2026-17974: Insufficient policy enforcement in DevTools
- CVE-2026-17975: Inappropriate implementation in IME
- CVE-2026-17976: Policy bypass in Extensions
- CVE-2026-17977: Policy bypass in CSS
- CVE-2026-17978: Side-channel information leakage in WebCodecs
- CVE-2026-17979: Race in V8
- CVE-2026-17980: Inappropriate implementation in UI
- CVE-2026-17981: Inappropriate implementation in Blink
- CVE-2026-17982: Insufficient validation of untrusted input in Cast
- CVE-2026-17983: Incorrect security UI in Global Media Controls
- CVE-2026-17984: Inappropriate implementation in Browser
- CVE-2026-17985: Insufficient policy enforcement in Speech
- CVE-2026-17986: Insufficient policy enforcement in Bluetooth
- CVE-2026-17987: Insufficient validation of untrusted input in Notifications
- CVE-2026-17988: Insufficient validation of untrusted input in Navigation
- CVE-2026-17989: Type Confusion in V8
- CVE-2026-17990: Insufficient validation of untrusted input in WebAuthn
- CVE-2026-17991: Insufficient validation of untrusted input in AI
- CVE-2026-17992: Uninitialized Use in Skia
- CVE-2026-17993: Race in Updater
- CVE-2026-17994: Inappropriate implementation in Media
- CVE-2026-17995: Out of bounds read in Dawn
- CVE-2026-17996: Inappropriate implementation in Browser
- CVE-2026-17997: Inappropriate implementation in Passwords
- CVE-2026-17998: Incorrect security UI in Extensions
- CVE-2026-17999: Incorrect security UI in PictureInPicture
- CVE-2026-18000: Insufficient policy enforcement in USB
- CVE-2026-18001: Inappropriate implementation in WebGL
- CVE-2026-18002: Insufficient validation of untrusted input in Google Lens
- CVE-2026-18003: Inappropriate implementation in Chrome for iOS
- CVE-2026-18004: Insufficient policy enforcement in Speech
- CVE-2026-18005: Inappropriate implementation in WebXR
- CVE-2026-18006: Inappropriate implementation in Google Lens
- CVE-2026-18007: Inappropriate implementation in Input
- CVE-2026-18008: Inappropriate implementation in Settings
- CVE-2026-18009: Insufficient validation of untrusted input in Passwords
- CVE-2026-18010: Inappropriate implementation in Passwords
- CVE-2026-18011: Inappropriate implementation in Chrome for iOS
- CVE-2026-18012: Use after free in PDFium
- CVE-2026-18013: Inappropriate implementation in Chrome for iOS
- CVE-2026-18014: Insufficient validation of untrusted input in DevTools
- CVE-2026-18015: Inappropriate implementation in Tint
- CVE-2026-18016: Insufficient policy enforcement in Chrome for iOS
- CVE-2026-18017: Use after free in Dawn
- CVE-2026-18018: Inappropriate implementation in Updater
- CVE-2026-18019: Side-channel information leakage in Media
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1272936
- SUSE CVE CVE-2026-17650 page
- SUSE CVE CVE-2026-17651 page
- SUSE CVE CVE-2026-17652 page
- SUSE CVE CVE-2026-17653 page
- SUSE CVE CVE-2026-17654 page
- SUSE CVE CVE-2026-17655 page
- SUSE CVE CVE-2026-17656 page
- SUSE CVE CVE-2026-17657 page
- SUSE CVE CVE-2026-17658 page
- SUSE CVE CVE-2026-17659 page
- SUSE CVE CVE-2026-17660 page
- SUSE CVE CVE-2026-17661 page
- SUSE CVE CVE-2026-17662 page
- SUSE CVE CVE-2026-17663 page
- SUSE CVE CVE-2026-17664 page
- SUSE CVE CVE-2026-17665 page
- SUSE CVE CVE-2026-17666 page
- SUSE CVE CVE-2026-17667 page
Описание
Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-17650
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-17651
- SUSE Bug 1272936
Описание
Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-17652
- SUSE Bug 1272936
Описание
Use after free in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-17653
- SUSE Bug 1272936
Описание
Race in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-17654
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-17655
- SUSE Bug 1272936
Описание
Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-17656
- SUSE Bug 1272936
Описание
Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17657
- SUSE Bug 1272936
Описание
Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17658
- SUSE Bug 1272936
Описание
Inappropriate implementation in SiteIsolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17659
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17660
- SUSE Bug 1272936
Описание
Use after free in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17661
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in Prefetch in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17662
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17663
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17664
- SUSE Bug 1272936
Описание
Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17665
- SUSE Bug 1272936
Описание
Cryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network position to bypass discretionary access control via malicious network traffic. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17666
- SUSE Bug 1272936
Описание
Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17667
- SUSE Bug 1272936
Описание
Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17668
- SUSE Bug 1272936
Описание
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17669
- SUSE Bug 1272936
Описание
Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17670
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17671
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17672
- SUSE Bug 1272936
Описание
Integer overflow in QUIC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17673
- SUSE Bug 1272936
Описание
Inappropriate implementation in HTML in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17674
- SUSE Bug 1272936
Описание
Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17675
- SUSE Bug 1272936
Описание
Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17676
- SUSE Bug 1272936
Описание
Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17677
- SUSE Bug 1272936
Описание
Out of bounds read in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17678
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Print Preview in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17679
- SUSE Bug 1272936
Описание
Heap buffer overflow in Color in Google Chrome on ChromeOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17680
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Web Authentication in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17681
- SUSE Bug 1272936
Описание
Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17682
- SUSE Bug 1272936
Описание
Inappropriate implementation in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17683
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17684
- SUSE Bug 1272936
Описание
Use after free in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17685
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17686
- SUSE Bug 1272936
Описание
Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17687
- SUSE Bug 1272936
Описание
Use after free in Input in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17688
- SUSE Bug 1272936
Описание
Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17689
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in PDF in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17690
- SUSE Bug 1272936
Описание
Out of bounds write in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17691
- SUSE Bug 1272936
Описание
Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17692
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in FileSystem in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17693
- SUSE Bug 1272936
Описание
Use after free in DOM in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17694
- SUSE Bug 1272936
Описание
Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17695
- SUSE Bug 1272936
Описание
Side-channel information leakage in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17696
- SUSE Bug 1272936
Описание
Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17697
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in UI in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17698
- SUSE Bug 1272936
Описание
Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17699
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Actor in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17700
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17701
- SUSE Bug 1272936
Описание
Inappropriate implementation in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17702
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17703
- SUSE Bug 1272936
Описание
Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17704
- SUSE Bug 1272936
Описание
Integer overflow in libxml in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17705
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17706
- SUSE Bug 1272936
Описание
Uninitialized Use in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17707
- SUSE Bug 1272936
Описание
Use after free in Audio in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17708
- SUSE Bug 1272936
Описание
Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17709
- SUSE Bug 1272936
Описание
Inappropriate implementation in MHTML in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17710
- SUSE Bug 1272936
Описание
Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17711
- SUSE Bug 1272936
Описание
Race in Skia in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17712
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Accessibility in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17713
- SUSE Bug 1272936
Описание
Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17714
- SUSE Bug 1272936
Описание
Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17715
- SUSE Bug 1272936
Описание
Use after free in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via malicious network traffic. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17716
- SUSE Bug 1272936
Описание
Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17717
- SUSE Bug 1272936
Описание
Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17718
- SUSE Bug 1272936
Описание
Use after free in Input in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17719
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17720
- SUSE Bug 1272936
Описание
Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17721
- SUSE Bug 1272936
Описание
Object lifecycle issue in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17722
- SUSE Bug 1272936
Описание
Use after free in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17723
- SUSE Bug 1272936
Описание
Race in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17724
- SUSE Bug 1272936
Описание
Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17725
- SUSE Bug 1272936
Описание
Integer overflow in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17726
- SUSE Bug 1272936
Описание
Out of bounds write in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-17727
- SUSE Bug 1272936
Описание
Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17728
- SUSE Bug 1272936
Описание
Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17729
- SUSE Bug 1272936
Описание
Side-channel information leakage in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17730
- SUSE Bug 1272936
Описание
Inappropriate implementation in Autofill in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17731
- SUSE Bug 1272936
Описание
Inappropriate implementation in SVG in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17732
- SUSE Bug 1272936
Описание
Inappropriate implementation in QUIC in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17733
- SUSE Bug 1272936
Описание
Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17734
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in BFCache in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17735
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17736
- SUSE Bug 1272936
Описание
Use after free in Bluetooth in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17737
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17738
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts or HTML (UXSS) via a crafted Chrome Extension. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17739
- SUSE Bug 1272936
Описание
Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17740
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17741
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17742
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in ControlledFrame in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17743
- SUSE Bug 1272936
Описание
Inappropriate implementation in File Input in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17744
- SUSE Bug 1272936
Описание
Out of bounds read in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17745
- SUSE Bug 1272936
Описание
Use after free in GPU in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17746
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Payments in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17747
- SUSE Bug 1272936
Описание
Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17748
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17749
- SUSE Bug 1272936
Описание
Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17750
- SUSE Bug 1272936
Описание
Inappropriate implementation in AdFilter in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17751
- SUSE Bug 1272936
Описание
Use after free in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17752
- SUSE Bug 1272936
Описание
Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17753
- SUSE Bug 1272936
Описание
Inappropriate implementation in Blink in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17754
- SUSE Bug 1272936
Описание
Incorrect security UI in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17755
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in Presentation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17756
- SUSE Bug 1272936
Описание
Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17757
- SUSE Bug 1272936
Описание
Heap buffer overflow in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17758
- SUSE Bug 1272936
Описание
Uninitialized Use in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17759
- SUSE Bug 1272936
Описание
Side-channel information leakage in NoStatePrefetch in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17760
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via malicious network traffic. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17761
- SUSE Bug 1272936
Описание
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17762
- SUSE Bug 1272936
Описание
Inappropriate implementation in GPU in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17763
- SUSE Bug 1272936
Описание
Inappropriate implementation in FedCM in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17764
- SUSE Bug 1272936
Описание
Inappropriate implementation in WebProtect in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17765
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Clipboard in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17766
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17767
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17768
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17769
- SUSE Bug 1272936
Описание
Out of bounds read in Media in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17770
- SUSE Bug 1272936
Описание
Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17771
- SUSE Bug 1272936
Описание
Out of bounds read in WebGL in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17772
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17773
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Variations in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network position to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17774
- SUSE Bug 1272936
Описание
Inappropriate implementation in PresentationAPI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17775
- SUSE Bug 1272936
Описание
Policy bypass in Receiver in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17776
- SUSE Bug 1272936
Описание
Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17777
- SUSE Bug 1272936
Описание
Use after free in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17778
- SUSE Bug 1272936
Описание
Inappropriate implementation in Site Isolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17779
- SUSE Bug 1272936
Описание
Inappropriate implementation in Isolated Web Apps in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17780
- SUSE Bug 1272936
Описание
Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17781
- SUSE Bug 1272936
Описание
Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17782
- SUSE Bug 1272936
Описание
Inappropriate implementation in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17783
- SUSE Bug 1272936
Описание
Use after free in Audio in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17784
- SUSE Bug 1272936
Описание
Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17785
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17786
- SUSE Bug 1272936
Описание
Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17787
- SUSE Bug 1272936
Описание
Inappropriate implementation in Blink in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17788
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via malicious network traffic. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17789
- SUSE Bug 1272936
Описание
Uninitialized Use in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17790
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17791
- SUSE Bug 1272936
Описание
Inappropriate implementation in Credential Management in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17792
- SUSE Bug 1272936
Описание
Inappropriate implementation in Messages in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17793
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17794
- SUSE Bug 1272936
Описание
Inappropriate implementation in GetUserMedia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17795
- SUSE Bug 1272936
Описание
Side-channel information leakage in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17796
- SUSE Bug 1272936
Описание
Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17797
- SUSE Bug 1272936
Описание
Inappropriate implementation in Cast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17798
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass discretionary access control via a malicious file. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17799
- SUSE Bug 1272936
Описание
Inappropriate implementation in MediaRecording in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17800
- SUSE Bug 1272936
Описание
Out of bounds read and write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17801
- SUSE Bug 1272936
Описание
Side-channel information leakage in GPU in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17802
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Save to Drive in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17803
- SUSE Bug 1272936
Описание
Use after free in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17804
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in Glic in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17805
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17806
- SUSE Bug 1272936
Описание
Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17807
- SUSE Bug 1272936
Описание
Uninitialized Use in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17808
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17809
- SUSE Bug 1272936
Описание
Uninitialized Use in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17810
- SUSE Bug 1272936
Описание
Use after free in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17811
- SUSE Bug 1272936
Описание
Inappropriate implementation in DigitalCredentials in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17812
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17813
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17814
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in GuestView in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17815
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in Speech in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17816
- SUSE Bug 1272936
Описание
Inappropriate implementation in ReportingAndNEL in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17817
- SUSE Bug 1272936
Описание
Inappropriate implementation in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17818
- SUSE Bug 1272936
Описание
Inappropriate implementation in WebAppInstalls in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17819
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17820
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17821
- SUSE Bug 1272936
Описание
Race in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17822
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17823
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17824
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in Passwords in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17825
- SUSE Bug 1272936
Описание
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17826
- SUSE Bug 1272936
Описание
Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17827
- SUSE Bug 1272936
Описание
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17828
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17829
- SUSE Bug 1272936
Описание
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17830
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17831
- SUSE Bug 1272936
Описание
Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17832
- SUSE Bug 1272936
Описание
Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17833
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17834
- SUSE Bug 1272936
Описание
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17835
- SUSE Bug 1272936
Описание
Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17836
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17837
- SUSE Bug 1272936
Описание
Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17838
- SUSE Bug 1272936
Описание
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17839
- SUSE Bug 1272936
Описание
Incorrect security UI in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17840
- SUSE Bug 1272936
Описание
Race in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17841
- SUSE Bug 1272936
Описание
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17842
- SUSE Bug 1272936
Описание
Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17843
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed an attacker on the local network segment to leak cross-origin data via malicious network traffic. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17844
- SUSE Bug 1272936
Описание
Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17845
- SUSE Bug 1272936
Описание
Inappropriate implementation in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17846
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17847
- SUSE Bug 1272936
Описание
Integer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17848
- SUSE Bug 1272936
Описание
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via malicious network traffic. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17849
- SUSE Bug 1272936
Описание
Inappropriate implementation in Permissions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17850
- SUSE Bug 1272936
Описание
Side-channel information leakage in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17851
- SUSE Bug 1272936
Описание
Inappropriate implementation in Media Router in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17852
- SUSE Bug 1272936
Описание
Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to inject scripts or HTML into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17853
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in WebMCP in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17854
- SUSE Bug 1272936
Описание
Race in DevTools in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17855
- SUSE Bug 1272936
Описание
Inappropriate implementation in Network in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17856
- SUSE Bug 1272936
Описание
Inappropriate implementation in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17857
- SUSE Bug 1272936
Описание
Uninitialized Use in WebNN in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17858
- SUSE Bug 1272936
Описание
Inappropriate implementation in Favicons in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17859
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to spoof the contents of the Omnibox (URL bar) via a malicious file. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17860
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Updater in Google Chrome prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17861
- SUSE Bug 1272936
Описание
Use after free in Tracing in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17862
- SUSE Bug 1272936
Описание
Inappropriate implementation in Browser in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17863
- SUSE Bug 1272936
Описание
Inappropriate implementation in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17864
- SUSE Bug 1272936
Описание
Inappropriate implementation in Crypto in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17865
- SUSE Bug 1272936
Описание
Type Confusion in Tab in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17866
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17867
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in USB in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17868
- SUSE Bug 1272936
Описание
Out of bounds read in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17869
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed an attacker on the local network segment to leak cross-origin data via malicious network traffic. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17870
- SUSE Bug 1272936
Описание
Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17871
- SUSE Bug 1272936
Описание
Cryptographic Flaw in WebAppInstalls in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17872
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17873
- SUSE Bug 1272936
Описание
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17874
- SUSE Bug 1272936
Описание
Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17875
- SUSE Bug 1272936
Описание
Inappropriate implementation in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17876
- SUSE Bug 1272936
Описание
Inappropriate implementation in Chromoting in Google Chrome on Linux prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via malicious network traffic. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17877
- SUSE Bug 1272936
Описание
Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17878
- SUSE Bug 1272936
Описание
Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17879
- SUSE Bug 1272936
Описание
Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17880
- SUSE Bug 1272936
Описание
Integer overflow in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17881
- SUSE Bug 1272936
Описание
Policy bypass in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to bypass site isolation via a crafted Chrome Extension. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17882
- SUSE Bug 1272936
Описание
Inappropriate implementation in Headless in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17883
- SUSE Bug 1272936
Описание
Object lifecycle issue in WebRTC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17884
- SUSE Bug 1272936
Описание
Inappropriate implementation in Paint in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17885
- SUSE Bug 1272936
Описание
Use after free in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17886
- SUSE Bug 1272936
Описание
Use after free in TabStrip in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17887
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in WebUI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17888
- SUSE Bug 1272936
Описание
Uninitialized Use in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17889
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17890
- SUSE Bug 1272936
Описание
Use after free in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17891
- SUSE Bug 1272936
Описание
Inappropriate implementation in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17892
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17893
- SUSE Bug 1272936
Описание
Use after free in Views in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17894
- SUSE Bug 1272936
Описание
Inappropriate implementation in DataTransfer in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17895
- SUSE Bug 1272936
Описание
Use after free in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17896
- SUSE Bug 1272936
Описание
Inappropriate implementation in ORB in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-17897
- SUSE Bug 1272936
Описание
Use after free in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17898
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17899
- SUSE Bug 1272936
Описание
Inappropriate implementation in Enterprise in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a malicious file. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17900
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Sharing in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via malicious network traffic. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17901
- SUSE Bug 1272936
Описание
Inappropriate implementation in Editing in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17902
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in Chromecast in Google Chrome prior to 151.0.7922.72 allowed an attacker on the local network segment to inject scripts or HTML into a privileged page via malicious network traffic. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17903
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in NFC in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17904
- SUSE Bug 1272936
Описание
Inappropriate implementation in SurfaceCapture in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17905
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Bluetooth in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17906
- SUSE Bug 1272936
Описание
Side-channel information leakage in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17907
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17908
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Isolated Web Apps in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via malicious network traffic. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17909
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in NFC in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17910
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in SVG in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17911
- SUSE Bug 1272936
Описание
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17912
- SUSE Bug 1272936
Описание
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17913
- SUSE Bug 1272936
Описание
Side-channel information leakage in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17914
- SUSE Bug 1272936
Описание
Inappropriate implementation in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17915
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in Settings in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17916
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17917
- SUSE Bug 1272936
Описание
Use after free in Sync in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17918
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in Enterprise in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via physical access to the device. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17919
- SUSE Bug 1272936
Описание
Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17920
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17921
- SUSE Bug 1272936
Описание
Inappropriate implementation in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17922
- SUSE Bug 1272936
Описание
Policy bypass in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted domain name. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17923
- SUSE Bug 1272936
Описание
Use after free in DNS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17924
- SUSE Bug 1272936
Описание
Inappropriate implementation in Cast in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17925
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17926
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17927
- SUSE Bug 1272936
Описание
Inappropriate implementation in DataTransfer in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17928
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17929
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17930
- SUSE Bug 1272936
Описание
Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17931
- SUSE Bug 1272936
Описание
Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17932
- SUSE Bug 1272936
Описание
Inappropriate implementation in DOMStorage in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17933
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17934
- SUSE Bug 1272936
Описание
Heap buffer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17935
- SUSE Bug 1272936
Описание
Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17936
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17937
- SUSE Bug 1272936
Описание
Inappropriate implementation in FullScreen in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17938
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17939
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Picture-in-Picture in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17940
- SUSE Bug 1272936
Описание
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17941
- SUSE Bug 1272936
Описание
Side-channel information leakage in SVG in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17942
- SUSE Bug 1272936
Описание
Inappropriate implementation in Parser in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17943
- SUSE Bug 1272936
Описание
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17944
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17945
- SUSE Bug 1272936
Описание
Uninitialized Use in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17946
- SUSE Bug 1272936
Описание
Use after free in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17947
- SUSE Bug 1272936
Описание
Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17948
- SUSE Bug 1272936
Описание
Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17949
- SUSE Bug 1272936
Описание
Inappropriate implementation in Safebrowsing in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code via a malicious file. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17950
- SUSE Bug 1272936
Описание
Heap buffer overflow in WebRTC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17951
- SUSE Bug 1272936
Описание
Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17952
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17953
- SUSE Bug 1272936
Описание
Policy bypass in MHTML in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted MHTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17954
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17955
- SUSE Bug 1272936
Описание
Inappropriate implementation in Scheduling in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17956
- SUSE Bug 1272936
Описание
Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17957
- SUSE Bug 1272936
Описание
Inappropriate implementation in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17958
- SUSE Bug 1272936
Описание
Inappropriate implementation in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17959
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass no-referrer policy via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17960
- SUSE Bug 1272936
Описание
Inappropriate implementation in Session in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17961
- SUSE Bug 1272936
Описание
Inappropriate implementation in Blink in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17962
- SUSE Bug 1272936
Описание
Inappropriate implementation in SVG in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17963
- SUSE Bug 1272936
Описание
Incorrect security UI in UI in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17964
- SUSE Bug 1272936
Описание
Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17965
- SUSE Bug 1272936
Описание
Inappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17966
- SUSE Bug 1272936
Описание
Use after free in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17967
- SUSE Bug 1272936
Описание
Uninitialized Use in WebXR in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17968
- SUSE Bug 1272936
Описание
Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17969
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network position to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17970
- SUSE Bug 1272936
Описание
Inappropriate implementation in Frame in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17971
- SUSE Bug 1272936
Описание
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17972
- SUSE Bug 1272936
Описание
Inappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17973
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in DevTools in Google Chrome prior to 151.0.7922.72 allowed a local attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17974
- SUSE Bug 1272936
Описание
Inappropriate implementation in IME in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17975
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted domain name. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17976
- SUSE Bug 1272936
Описание
Policy bypass in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17977
- SUSE Bug 1272936
Описание
Side-channel information leakage in WebCodecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17978
- SUSE Bug 1272936
Описание
Race in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17979
- SUSE Bug 1272936
Описание
Inappropriate implementation in UI in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17980
- SUSE Bug 1272936
Описание
Inappropriate implementation in Blink in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17981
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17982
- SUSE Bug 1272936
Описание
Inappropriate implementation in Global Media Controls in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17983
- SUSE Bug 1272936
Описание
Inappropriate implementation in Browser in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17984
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in Speech in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17985
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in Bluetooth in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17986
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Notifications in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17987
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17988
- SUSE Bug 1272936
Описание
Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17989
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in WebAuthn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17990
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in AI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17991
- SUSE Bug 1272936
Описание
Uninitialized Use in Skia in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17992
- SUSE Bug 1272936
Описание
Race in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17993
- SUSE Bug 1272936
Описание
Inappropriate implementation in Media in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17994
- SUSE Bug 1272936
Описание
Out of bounds read in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17995
- SUSE Bug 1272936
Описание
Inappropriate implementation in Browser in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17996
- SUSE Bug 1272936
Описание
Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17997
- SUSE Bug 1272936
Описание
Incorrect security UI in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17998
- SUSE Bug 1272936
Описание
Race in PictureInPicture in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-17999
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in USB in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-18000
- SUSE Bug 1272936
Описание
Inappropriate implementation in WebGL in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-18001
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-18002
- SUSE Bug 1272936
Описание
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-18003
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in Speech in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-18004
- SUSE Bug 1272936
Описание
Inappropriate implementation in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-18005
- SUSE Bug 1272936
Описание
Inappropriate implementation in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-18006
- SUSE Bug 1272936
Описание
Inappropriate implementation in Input in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-18007
- SUSE Bug 1272936
Описание
Inappropriate implementation in Settings in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-18008
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-18009
- SUSE Bug 1272936
Описание
Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-18010
- SUSE Bug 1272936
Описание
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive information from process memory via physical access to the device. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-18011
- SUSE Bug 1272936
Описание
Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-18012
- SUSE Bug 1272936
Описание
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-18013
- SUSE Bug 1272936
Описание
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-18014
- SUSE Bug 1272936
Описание
Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-18015
- SUSE Bug 1272936
Описание
Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-18016
- SUSE Bug 1272936
Описание
Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-18017
- SUSE Bug 1272936
Описание
Inappropriate implementation in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-18018
- SUSE Bug 1272936
Описание
Side-channel information leakage in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-18019
- SUSE Bug 1272936