Total
8659 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-64216 | 1 Linux | 1 Linux Kernel | 2026-08-27 | N/A | 9.8 CRITICAL |
| In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages() netfs_unlock_abandoned_read_pages(rreq) accesses the index of the folios it is wanting to unlock and compares that to rreq->no_unlock_folio so that it doesn't unlock a folio being read for netfs_perform_write() or netfs_write_begin(). However, given that netfs_unlock_abandoned_read_pages() is called _after_ NETFS_RREQ_IN_PROGRESS is cleared, the one folio that it's not allowed to dereference is the one specified by ->no_unlock_folio as ownership immediately reverts to the caller. Fix this by storing the folio pointer instead and using that rather than the index. Also fix netfs_unlock_read_folio() where the same applies. | |||||
| CVE-2026-79187 | 1 Google | 1 Chrome | 2026-08-27 | N/A | 8.8 HIGH |
| Use after free in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-79150 | 2 Apple, Google | 2 Macos, Chrome | 2026-08-27 | N/A | 9.6 CRITICAL |
| Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | |||||
| CVE-2026-79149 | 1 Google | 1 Chrome | 2026-08-27 | N/A | 9.6 CRITICAL |
| Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-79140 | 2 Apple, Google | 2 Macos, Chrome | 2026-08-27 | N/A | 9.6 CRITICAL |
| Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-79128 | 2 Apple, Google | 2 Macos, Chrome | 2026-08-27 | N/A | 9.6 CRITICAL |
| Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-79129 | 1 Google | 2 Android, Chrome | 2026-08-27 | N/A | 9.6 CRITICAL |
| Use after free in Sessions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Medium) | |||||
| CVE-2026-79247 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-08-27 | N/A | 8.3 HIGH |
| Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High) | |||||
| CVE-2026-79219 | 1 Google | 1 Chrome | 2026-08-27 | N/A | 8.8 HIGH |
| Use after free in Bluetooth in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: High) | |||||
| CVE-2026-79197 | 1 Google | 1 Chrome | 2026-08-27 | N/A | 8.8 HIGH |
| Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-79195 | 1 Google | 1 Chrome | 2026-08-27 | N/A | 8.8 HIGH |
| Use after free in Script in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-79119 | 1 Google | 1 Chrome | 2026-08-27 | N/A | 8.8 HIGH |
| Use after free in PDF in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: Low) | |||||
| CVE-2026-79097 | 1 Google | 1 Chrome | 2026-08-27 | N/A | 8.8 HIGH |
| Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-79091 | 2 Apple, Google | 2 Macos, Chrome | 2026-08-27 | N/A | 9.6 CRITICAL |
| Use after free in Bluetooth in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-79078 | 1 Google | 1 Chrome | 2026-08-27 | N/A | 9.6 CRITICAL |
| Use after free in FedCM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-79064 | 2 Apple, Google | 2 Macos, Chrome | 2026-08-27 | N/A | 9.6 CRITICAL |
| Use after free in Network in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium) | |||||
| CVE-2026-79056 | 1 Google | 1 Chrome | 2026-08-27 | N/A | 9.6 CRITICAL |
| Use after free in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-79054 | 1 Google | 1 Chrome | 2026-08-27 | N/A | 8.3 HIGH |
| Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | |||||
| CVE-2026-79052 | 1 Google | 1 Chrome | 2026-08-27 | N/A | 9.6 CRITICAL |
| Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | |||||
| CVE-2026-79047 | 1 Google | 1 Chrome | 2026-08-27 | N/A | 9.6 CRITICAL |
| Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
