google

41 records · 1 with a public proof-of-concept

Disclosed vulnerabilities where the NVD names google as an affected vendor, highest CVSS first.

  1. CRITICAL 9.6CVE-2026-91738

    Improper input validation in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    chrome

    AI risk analysis on Exploit-DB.ai →

  2. CRITICAL 9.6CVE-2026-91729

    Use after free in DigitalCredentials in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    chrome

    AI risk analysis on Exploit-DB.ai →

  3. CRITICAL 9.6CVE-2026-91728

    Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

    chrome

    AI risk analysis on Exploit-DB.ai →

  4. CRITICAL 9.6CVE-2026-91718

    Use after free in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    chrome

    AI risk analysis on Exploit-DB.ai →

  5. CRITICAL 9.6CVE-2026-91716

    Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    chrome

    AI risk analysis on Exploit-DB.ai →

  6. CRITICAL 9.6CVE-2026-91710

    Use after free in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    chrome

    AI risk analysis on Exploit-DB.ai →

  7. HIGH 8.8CVE-2026-91745

    Use after free in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

    chrome

    AI risk analysis on Exploit-DB.ai →

  8. HIGH 8.8CVE-2026-91741

    Type confusion in CacheStorage in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

    chrome

    AI risk analysis on Exploit-DB.ai →

  9. HIGH 8.8CVE-2026-91737

    Use after free in PDF in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

    chrome

    AI risk analysis on Exploit-DB.ai →

  10. HIGH 8.8CVE-2026-91736

    Use after free in DOM in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

    chrome

    AI risk analysis on Exploit-DB.ai →

  11. HIGH 8.8CVE-2026-91731

    Type confusion in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

    chrome

    AI risk analysis on Exploit-DB.ai →

  12. HIGH 8.8CVE-2026-91722

    Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    chrome

    AI risk analysis on Exploit-DB.ai →

  13. HIGH 8.8CVE-2026-91721

    Use after free in Internals in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

    chrome

    AI risk analysis on Exploit-DB.ai →

  14. HIGH 8.8CVE-2026-91715

    Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

    chrome

    AI risk analysis on Exploit-DB.ai →

  15. HIGH 8.8CVE-2026-91711

    Out of bounds write in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

    chrome

    AI risk analysis on Exploit-DB.ai →

  16. HIGH 8.8CVE-2026-91709

    Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

    chrome

    AI risk analysis on Exploit-DB.ai →

  17. HIGH 8.3CVE-2026-91748

    Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via UI Interaction. (Ch

    chrome · macos

    AI risk analysis on Exploit-DB.ai →

  18. HIGH 8.3CVE-2026-91743

    Race condition in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    chrome

    AI risk analysis on Exploit-DB.ai →

  19. HIGH 8.3CVE-2026-91735

    Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    chrome

    AI risk analysis on Exploit-DB.ai →

  20. HIGH 8.3CVE-2026-91733

    Improper state validation in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    chrome

    AI risk analysis on Exploit-DB.ai →

  21. HIGH 8.3CVE-2026-91724

    Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    chrome

    AI risk analysis on Exploit-DB.ai →

  22. HIGH 8.3CVE-2026-91712

    Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Hi

    chrome · macos

    AI risk analysis on Exploit-DB.ai →

  23. HIGH 8.1CVE-2026-91732public PoC

    Missing authorization in AppManifest in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: M

    chrome

    AI risk analysis on Exploit-DB.ai →

  24. HIGH 8.1CVE-2026-91727

    Incorrect reference resolution in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a local attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Hig

    chrome · macos

    AI risk analysis on Exploit-DB.ai →

  25. HIGH 8.1CVE-2026-91719

    Code injection in XML in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

    chrome

    AI risk analysis on Exploit-DB.ai →

  26. HIGH 7.4CVE-2026-91734

    Incorrect authorization in Core in Google Chrome on on Windows prior to 153.0.8010.47 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)

    chrome · windows

    AI risk analysis on Exploit-DB.ai →

  27. MEDIUM 5.3CVE-2026-91744

    Race condition in PlatformIntegration in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium secur

    chrome · macos

    AI risk analysis on Exploit-DB.ai →

  28. MEDIUM 5.3CVE-2026-91725

    Observable discrepancy in CSS in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)

    chrome

    AI risk analysis on Exploit-DB.ai →

  29. MEDIUM 5.3CVE-2026-91714

    Observable discrepancy in Fonts in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)

    chrome

    AI risk analysis on Exploit-DB.ai →

  30. MEDIUM 5.1CVE-2026-91717

    Missing authorization in Android in Google Chrome on on Android prior to 153.0.8010.47 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: High)

    chrome · android

    AI risk analysis on Exploit-DB.ai →

  31. MEDIUM 4.8CVE-2026-91742

    Confused deputy in PriceTracking in Google Chrome on on iOS prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to bypass system access restrictions into a privileged page via crafted network traffic. (Chromium security severity: Med

    chrome · iphone os

    AI risk analysis on Exploit-DB.ai →

  32. MEDIUM 4.7CVE-2026-91726

    Out of bounds read in WebGL in Google Chrome on on Android prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

    chrome · android

    AI risk analysis on Exploit-DB.ai →

  33. MEDIUM 4.7CVE-2026-91720

    Uninitialized resource in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    chrome

    AI risk analysis on Exploit-DB.ai →

  34. MEDIUM 4.3CVE-2026-91746

    Integer overflow in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

    chrome

    AI risk analysis on Exploit-DB.ai →

  35. MEDIUM 4.3CVE-2026-91740

    Uninitialized resource in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

    chrome

    AI risk analysis on Exploit-DB.ai →

  36. MEDIUM 4.2CVE-2026-91739

    Missing authorization in Transactions Platform in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

    chrome

    AI risk analysis on Exploit-DB.ai →

  37. MEDIUM 4.2CVE-2026-91713

    Missing authorization in Browser in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

    chrome

    AI risk analysis on Exploit-DB.ai →

  38. LOW 3.1CVE-2026-91747

    Use after free in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

    chrome

    AI risk analysis on Exploit-DB.ai →

  39. LOW 3.1CVE-2026-91730

    Incomplete cleanup in GetUserMedia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Med

    chrome

    AI risk analysis on Exploit-DB.ai →

  40. LOW 3.1CVE-2026-91723

    Race condition in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

    chrome

    AI risk analysis on Exploit-DB.ai →

  41. LOW 3.1CVE-2026-91708

    Race condition in Network in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

    chrome

    AI risk analysis on Exploit-DB.ai →