Total
385 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-84137 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-09-03 | N/A | 4.3 MEDIUM |
| Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. | |||||
| CVE-2026-84356 | 1 Google | 1 Chrome | 2026-09-03 | N/A | 4.3 MEDIUM |
| UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-81267 | 1 Mozilla | 1 Firefox Mobile | 2026-09-03 | N/A | 5.4 MEDIUM |
| A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 155.0. | |||||
| CVE-2026-78974 | 1 Google | 1 Chrome | 2026-08-31 | N/A | 5.4 MEDIUM |
| UI misrepresentation in Linux Toolkit Theming in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-79108 | 1 Google | 1 Chrome | 2026-08-31 | N/A | 6.5 MEDIUM |
| UI misrepresentation in Web Authentication (Passkeys & Security Keys) in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-79011 | 1 Google | 1 Chrome | 2026-08-31 | N/A | 8.1 HIGH |
| UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-78912 | 1 Google | 1 Chrome | 2026-08-28 | N/A | 5.4 MEDIUM |
| UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-18487 | 2026-08-28 | N/A | 5.4 MEDIUM | ||
| A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a colon (for example, [https://trusted.com:80@attacker.com/](https://trusted.com:80@attacker.com/)), the address bar and security menus will display the safe website (trusted.com) but it will actually load the attacker website (attacker.com) on the screen. This allows attackers to create convincing phishing pages to trick users into trusting a malicious site. | |||||
| CVE-2026-79009 | 1 Google | 1 Chrome | 2026-08-28 | N/A | 4.3 MEDIUM |
| UI misrepresentation in UI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-79022 | 1 Google | 1 Chrome | 2026-08-28 | N/A | 4.3 MEDIUM |
| UI misrepresentation in Transactions Platform in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-79098 | 1 Google | 1 Chrome | 2026-08-28 | N/A | 4.3 MEDIUM |
| UI misrepresentation in PermissionElement in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-79173 | 1 Google | 1 Chrome | 2026-08-28 | N/A | 5.4 MEDIUM |
| UI misrepresentation in WebAppInstalls in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-79180 | 1 Google | 2 Android, Chrome | 2026-08-28 | N/A | 5.4 MEDIUM |
| UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-79204 | 2 Apple, Google | 2 Macos, Chrome | 2026-08-28 | N/A | 5.4 MEDIUM |
| UI misrepresentation in Input in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-79250 | 1 Google | 1 Chrome | 2026-08-28 | N/A | 5.4 MEDIUM |
| UI misrepresentation in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-79283 | 1 Google | 1 Chrome | 2026-08-28 | N/A | 5.4 MEDIUM |
| UI misrepresentation in Geometry in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-79233 | 1 Google | 2 Android, Chrome | 2026-08-27 | N/A | 4.3 MEDIUM |
| UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-79176 | 1 Google | 1 Chrome | 2026-08-27 | N/A | 6.5 MEDIUM |
| UI misrepresentation in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium) | |||||
| CVE-2026-79284 | 2 Apple, Google | 2 Macos, Chrome | 2026-08-27 | N/A | 4.3 MEDIUM |
| UI misrepresentation in Core in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-74975 | 1 Mozilla | 1 Firefox Mobile | 2026-08-25 | N/A | 5.4 MEDIUM |
| Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154. | |||||
