Blogger

Blogger

Top 100 site
Bounty RecognitionPartial Safe Harbor

Known Exploited Vulnerabilities 74CVEs

  • CVE-2026-87491Chromium V8Sep 9, 20261.0% EPSS

    Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

  • CVE-2026-85046Chromium V8Sep 4, 20261.5% EPSS

    Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

  • CVE-2026-11645Chromium V8Jun 9, 20262.2% EPSS

    Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

  • CVE-2026-5281DawnApr 1, 20264.9% EPSS

    Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based products including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

  • CVE-2026-3910Chromium V8Mar 13, 20262.0% EPSS

    Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

  • CVE-2026-3909SkiaMar 13, 20261.6% EPSS

    Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products.

  • CVE-2026-2441ChromiumFeb 17, 202622.4% EPSS

    Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

  • CVE-2025-14174ChromiumDec 12, 202522.3% EPSS

    Google Chromium contains an out of bounds memory access vulnerability in ANGLE that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

  • CVE-2025-13223Chromium V8Nov 19, 20255.0% EPSS

    Google Chromium V8 contains a type confusion vulnerability that allows for heap corruption.

  • CVE-2025-10585Chromium V8Sep 23, 20255.4% EPSS

    Google Chromium contains a type confusion vulnerability in the V8 JavaScript and WebAssembly engine.

and 64 more - view full CISA catalog →

security.txt

Contact
https://g.co/vulnz, mailto:[email protected]
Encryption
https://services.google.com/corporate/publickey.txt
Policy
https://g.co/vrp
Hiring
https://g.co/SecurityPrivacyEngJobs
Acknowledgments
https://bughunters.google.com/
Expires
Apr 1, 2030
View raw security.txt →