Last updated: 7 Oct 26 13:40:28 (UTC)
Chrome CVE Report: 2026-10-07
Source: http://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html Report generated: 2026-10-07 Chrome version: 155.0.8059.39 Total CVEs: 247
Executive Summary
This release contains 247 CVEs across 4 severity levels with a total bounty pool of $33,000.
- Critical: 4
- High: 53
- Medium: 122
- Low: 68
- Bounty-bearing: 16
- External reporters: 40
Vulnerability Type Breakdown
| Type | Count | % of Total |
|---|---|---|
| Other | 190 | 76.9% |
| Use After Free | 34 | 13.8% |
| Race Condition | 12 | 4.9% |
| Type Confusion | 4 | 1.6% |
| Out of Bounds | 4 | 1.6% |
| Integer Overflow | 3 | 1.2% |
Component Area Distribution
| Component | Count | % of Total |
|---|---|---|
| XR | 51 | 20.6% |
| General UI | 14 | 5.7% |
| Media | 12 | 4.9% |
| Mobile UI | 11 | 4.5% |
| ANGLE (Graphics) | 9 | 3.6% |
| Permissions | 9 | 3.6% |
| Browser Core | 8 | 3.2% |
| Autofill | 8 | 3.2% |
| Fonts | 8 | 3.2% |
| Chromoting (Remote Desktop) | 8 | 3.2% |
| Forms | 7 | 2.8% |
| V8 (JavaScript) | 7 | 2.8% |
| Input Handling | 7 | 2.8% |
| WebAudio | 5 | 2.0% |
| DevTools | 5 | 2.0% |
| Password Manager | 5 | 2.0% |
| Extensions API | 5 | 2.0% |
| Other/Uncategorized | 5 | 2.0% |
| Omnibox | 4 | 1.6% |
| File System/Input | 4 | 1.6% |
| Web App Installs | 4 | 1.6% |
| Networking | 4 | 1.6% |
| GPU | 4 | 1.6% |
| Dawn (WebGPU) | 3 | 1.2% |
| 3 | 1.2% | |
| Other (27 more) | 98 | 39.7% |
Bounty Analysis
Total bounty pool: $33,000 Bounty-bearing CVEs: 16
| CVE ID | Severity | Description | Bounty |
|---|---|---|---|
| CVE-2026-102322 | High | Incorrect Authorization in SiteIsolation. | $5000 |
| CVE-2026-106265 | Medium | UI misrepresentation in File. | $3000 |
| CVE-2026-106238 | Medium | Race condition in Fonts. | $3000 |
| CVE-2026-106245 | High | Uninitialized resource in ANGLE. | $2000 |
| CVE-2026-106327 | High | Incorrect authorization in Core. | $2000 |
| CVE-2026-106366 | High | Incomplete cleanup in CustomTabs. | $2000 |
| CVE-2026-106258 | High | Uninitialized resource in ANGLE. | $2000 |
| CVE-2026-106376 | High | Uninitialized resource in ANGLE. | $2000 |
| CVE-2026-106308 | High | Incorrect reference resolution in Autofill. | $2000 |
| CVE-2026-106215 | High | Uninitialized resource in ANGLE. | $2000 |
| CVE-2026-106324 | Medium | Incorrect authorization in WebAppInstalls. | $2000 |
| CVE-2026-106340 | Low | Missing authorization in CredentialProvider. | $2000 |
| CVE-2026-106369 | High | Missing authorization in Translate. | $1000 |
| CVE-2026-106293 | High | Type confusion in ANGLE. | $1000 |
| CVE-2026-106420 | Medium | Incorrect calculation in API. | $1000 |
| CVE-2026-106276 | Low | UI misrepresentation in Payments. | $1000 |
External Researcher Credits
| Researcher | CVEs | |
|---|---|---|
| 0599jiangyc | CVE-2026-106281 | |
| Alessandro Rizzo (0xAlessandro) | CVE-2026-106248 | |
| Avadhut Mahamuni | CVE-2026-102322 | |
| Blockian Creator of Kritt and Open-Kritt | CVE-2026-106193 | |
| Emond Papegaaij | CVE-2026-106426 | |
| Findingz | CVE-2026-106234 | |
| Hafiizh | CVE-2026-106210, CVE-2026-106338 | |
| James Burton (Offensive Security @ Meta) | CVE-2026-106184 | |
| Jinpyo Lee | CVE-2026-106293 | |
| JonathanBouman | CVE-2026-106245, CVE-2026-106215 | |
| Khalil Zhani | CVE-2026-106276 | |
| Luan Herrera (@lbherrera_) | CVE-2026-106420 | |
| M. Fauzan Wijaya (Gh05t666nero) | CVE-2026-106369 | |
| Manojkumar Jaganathan ( https://www.linkedin.com/in/manojkumar-j-7ba35b202/ ) Aka TheWhiteEvil ( https://hackerone.com/the-white-evil ) with HackerBro Technologies | CVE-2026-106317 | |
| NH DEV | CVE-2026-106360 | |
| Naoya Miyaguchi | CVE-2026-106366 | |
| Narenda Singh (@_3P1C) | CVE-2026-106324 | |
| OGINOME Tomohito | CVE-2026-106327 | |
| OpenAI Codex Security (amyb) | CVE-2026-106257, CVE-2026-106240 | |
| Paulos Yibelo Mesfin | CVE-2026-106378 | |
| Project Fortify | CVE-2026-106394 | |
| Putra Mahardika | Instagram @mhrdkaa._ | CVE-2026-106309 |
| Quyen Son at VinFast (@zer0qs) | CVE-2026-106372, CVE-2026-106409 | |
| SecBuddyN, Tencent KeenLab (CodeBuddy Security) | CVE-2026-106374 | |
| Shaked Reiner (Palo Alto Networks) | CVE-2026-106419 | |
| TIENPA | CVE-2026-106298 | |
| Team Allied (Hyeongeun Ji, h4nk3r1n, h4vrut4, HunSec, nag0x) | CVE-2026-106235 | |
| Umar Farooq | CVE-2026-106265 | |
| Wooseok Sung | CVE-2026-106340 | |
| Xinyang Ge | CVE-2026-106197, CVE-2026-106393 | |
| Xinyang Ge (Anthropic), assisted by Claude | CVE-2026-106358, CVE-2026-106347, CVE-2026-106278, CVE-2026-106233, CVE-2026-106318, CVE-2026-106411, CVE-2026-106423, CVE-2026-106357, CVE-2026-106383, CVE-2026-106349, CVE-2026-106421, CVE-2026-106204 | |
| c6eed09fc8b174b0f3eebedcceb1e792 | CVE-2026-106238 | |
| caveeroo | CVE-2026-106398 | |
| flyyy | CVE-2026-106207 | |
| leolee | CVE-2026-106388 | |
| med.bassia | CVE-2026-106384 | |
| mute1008 | CVE-2026-106249 | |
| pakhunov.anton.n | CVE-2026-106198 | |
| weihengqiuu | CVE-2026-106258, CVE-2026-106376, CVE-2026-106190 | |
| xinyang | CVE-2026-106268, CVE-2026-106269 |
Critical & High Severity Analysis
57 CVEs at Critical or High severity.
By vulnerability type:
- Use After Free: 27
- Other: 22
- Race Condition: 4
- Type Confusion: 2
- Integer Overflow: 2
By component:
- XR: 14
- ANGLE (Graphics): 7
- Media: 5
- V8 (JavaScript): 3
- Autofill: 2
- Fonts: 2
- Omnibox: 2
- Parser: 2
- WebRTC: 2
- PDF: 2
Reporting Timeline
| Date | CVEs Reported |
|---|---|
| 2024-11-25 | 1 |
| 2025-05-14 | 1 |
| 2025-10-02 | 1 |
| 2025-10-09 | 1 |
| 2026-01-21 | 1 |
| 2026-03-13 | 1 |
| 2026-03-26 | 1 |
| 2026-03-28 | 2 |
| 2026-03-29 | 1 |
| 2026-03-30 | 2 |
| 2026-03-31 | 1 |
| 2026-04-01 | 3 |
| 2026-04-02 | 1 |
| 2026-04-04 | 2 |
| 2026-04-06 | 1 |
| 2026-04-08 | 1 |
| 2026-04-09 | 1 |
| 2026-04-10 | 1 |
| 2026-04-11 | 4 |
| 2026-04-12 | 5 |
| 2026-04-13 | 7 |
| 2026-04-14 | 4 |
| 2026-04-17 | 4 |
| 2026-04-19 | 3 |
| 2026-04-20 | 1 |
| 2026-04-22 | 1 |
| 2026-04-28 | 1 |
| 2026-04-29 | 1 |
| 2026-05-07 | 1 |
| 2026-05-10 | 3 |
| 2026-05-13 | 1 |
| 2026-05-14 | 1 |
| 2026-05-15 | 5 |
| 2026-05-16 | 5 |
| 2026-05-17 | 6 |
| 2026-05-18 | 2 |
| 2026-05-19 | 2 |
| 2026-05-21 | 1 |
| 2026-05-27 | 4 |
| 2026-05-28 | 6 |
| 2026-05-29 | 7 |
| 2026-05-30 | 4 |
| 2026-06-02 | 1 |
| 2026-06-03 | 2 |
| 2026-06-05 | 4 |
| 2026-06-06 | 2 |
| 2026-06-09 | 1 |
| 2026-06-10 | 2 |
| 2026-06-11 | 2 |
| 2026-06-13 | 2 |
| 2026-06-14 | 1 |
| 2026-06-16 | 3 |
| 2026-06-23 | 1 |
| 2026-07-01 | 1 |
| 2026-07-09 | 3 |
| 2026-07-10 | 2 |
| 2026-07-14 | 1 |
| 2026-07-15 | 1 |
| 2026-07-17 | 1 |
| 2026-07-19 | 2 |
| 2026-07-21 | 1 |
| 2026-07-22 | 1 |
| 2026-07-26 | 1 |
| 2026-07-28 | 5 |
| 2026-08-05 | 1 |
| 2026-08-14 | 1 |
| 2026-08-16 | 1 |
| 2026-08-17 | 1 |
| 2026-08-21 | 3 |
| 2026-08-23 | 1 |
| 2026-08-24 | 1 |
| 2026-08-25 | 2 |
| 2026-08-26 | 17 |
| 2026-08-27 | 17 |
| 2026-08-28 | 5 |
| 2026-08-29 | 2 |
| 2026-08-30 | 2 |
| 2026-08-31 | 1 |
| 2026-09-02 | 11 |
| 2026-09-03 | 1 |
| 2026-09-04 | 1 |
| 2026-09-05 | 2 |
| 2026-09-08 | 1 |
| 2026-09-09 | 1 |
| 2026-09-10 | 3 |
| 2026-09-11 | 2 |
| 2026-09-13 | 1 |
| 2026-09-15 | 4 |
| 2026-09-19 | 1 |
| 2026-09-20 | 1 |
| 2026-09-24 | 6 |
| 2026-09-25 | 2 |
| 2026-09-26 | 2 |
| 2026-09-27 | 1 |
| 2026-09-28 | 3 |
| 2026-09-29 | 3 |
| 2026-09-30 | 3 |
| 2026-10-01 | 1 |
Critical CVEs
| CVE ID | Description | Reporter | Reported | Bounty | Issue |
|---|---|---|---|---|---|
| CVE-2026-106382 | Use after free in Chromecast. | 2026-07-15 | — | 534994449 | |
| CVE-2026-106197 | Use after free in Browser. | Xinyang Ge | 2026-09-11 | — | 560238696 |
| CVE-2026-106358 | Use after free in Navigation. | Xinyang Ge (Anthropic), assisted by Claude | 2026-09-28 | — | 567160164 |
| CVE-2026-106347 | Use after free in Track. | Xinyang Ge (Anthropic), assisted by Claude | 2026-09-30 | — | 567936270 |
Full CVE Table
| CVE ID | Severity | Description | Reporter | Reported | Bounty | Issue | |
|---|---|---|---|---|---|---|---|
| CVE-2026-106197 | Critical | Use after free in Browser. | Xinyang Ge | 2026-09-11 | — | 560238696 | |
| CVE-2026-106347 | Critical | Use after free in Track. | Xinyang Ge (Anthropic), assisted by Claude | 2026-09-30 | — | 567936270 | |
| CVE-2026-106358 | Critical | Use after free in Navigation. | Xinyang Ge (Anthropic), assisted by Claude | 2026-09-28 | — | 567160164 | |
| CVE-2026-106382 | Critical | Use after free in Chromecast. | 2026-07-15 | — | 534994449 | ||
| CVE-2026-102322 | High | Incorrect Authorization in SiteIsolation. | Avadhut Mahamuni | 2026-06-23 | $5000 | 527023137 | |
| CVE-2026-106184 | High | Uninitialized resource in Media. | James Burton (Offensive Security @ Meta) | 2026-09-29 | — | 567379988 | |
| CVE-2026-106190 | High | Use after free in Media. | weihengqiuu | 2026-09-27 | — | 566824998 | |
| CVE-2026-106193 | High | Use after free in Parser. | Blockian Creator of Kritt and Open-Kritt | 2026-09-05 | — | 557729858 | |
| CVE-2026-106200 | High | Use after free in Track. | 2026-10-01 | — | 568422505 | ||
| CVE-2026-106202 | High | Uninitialized resource in ANGLE. | 2026-08-26 | — | 553117809 | ||
| CVE-2026-106203 | High | Incomplete cleanup in Autofill. | Anonymous | 2026-08-27 | — | 553394296 | |
| CVE-2026-106204 | High | Use after free in PDF. | Xinyang Ge (Anthropic), assisted by Claude | 2026-09-30 | — | 567910530 | |
| CVE-2026-106211 | High | Use after free in TabStrip. | 2026-09-15 | — | 562002095 | ||
| CVE-2026-106214 | High | Information leak in Proxy. | 2026-07-10 | — | 533493992 | ||
| CVE-2026-106215 | High | Uninitialized resource in ANGLE. | JonathanBouman | 2026-09-13 | $2000 | 561066220 | |
| CVE-2026-106227 | High | Use after free in Core. | 2026-09-15 | — | 561891645 | ||
| CVE-2026-106231 | High | Uninitialized resource in Dawn. | 2026-08-26 | — | 553115993 | ||
| CVE-2026-106233 | High | Use after free in Metrics. | Xinyang Ge (Anthropic), assisted by Claude | 2026-09-24 | — | 565797213 | |
| CVE-2026-106235 | High | Use after free in WebAudio. | Team Allied (Hyeongeun Ji, h4nk3r1n, h4vrut4, HunSec, nag0x) | 2026-09-24 | — | 565612897 | |
| CVE-2026-106239 | High | Integer overflow in WebGL. | 2026-08-14 | — | 546630009 | ||
| CVE-2026-106240 | High | Type confusion in V8. | OpenAI Codex Security (amyb) | 2026-09-28 | — | 567177599 | |
| CVE-2026-106243 | High | Incomplete cleanup in Proxy Auth. | 2026-07-10 | — | 533426590 | ||
| CVE-2026-106245 | High | Uninitialized resource in ANGLE. | JonathanBouman | 2026-08-21 | $2000 | 550302121 | |
| CVE-2026-106248 | High | Use after free in Bindings. | Alessandro Rizzo (0xAlessandro) | 2026-09-19 | — | 563673584 | |
| CVE-2026-106255 | High | Race condition in V8. | 2026-09-10 | — | 559780376 | ||
| CVE-2026-106257 | High | Use after free in HTML. | OpenAI Codex Security (amyb) | 2026-09-24 | — | 565674529 | |
| CVE-2026-106258 | High | Uninitialized resource in ANGLE. | weihengqiuu | 2026-08-28 | $2000 | 553857574 | |
| CVE-2026-106268 | High | Use after free in WebRTC. | xinyang | 2026-09-24 | — | 565742177 | |
| CVE-2026-106273 | High | Uninitialized resource in Video. | 2026-08-26 | — | 553118338 | ||
| CVE-2026-106278 | High | Use after free in Select. | Xinyang Ge (Anthropic), assisted by Claude | 2026-09-24 | — | 565774991 | |
| CVE-2026-106281 | High | Use after free in Tint. | 0599jiangyc | 2026-08-31 | — | 554992296 | |
| CVE-2026-106293 | High | Type confusion in ANGLE. | Jinpyo Lee | 2026-08-16 | $1000 | 547343108 | |
| CVE-2026-106298 | High | Use after free in Chrome Tabs. | TIENPA | 2026-09-02 | — | 555932520 | |
| CVE-2026-106308 | High | Incorrect reference resolution in Autofill. | Anonymous | 2026-09-11 | $2000 | 560055258 | |
| CVE-2026-106318 | High | Use after free in Media. | Xinyang Ge (Anthropic), assisted by Claude | 2026-09-25 | — | 566111249 | |
| CVE-2026-106323 | High | Missing authorization in Chrome for iOS. | 2026-08-26 | — | 553114676 | ||
| CVE-2026-106327 | High | Incorrect authorization in Core. | OGINOME Tomohito | 2026-08-23 | $2000 | 551529559 | |
| CVE-2026-106329 | High | Incorrect authorization in FileSystem. | 2026-09-15 | — | 562043997 | ||
| CVE-2026-106332 | High | Integer overflow in Compositing. | 2026-08-27 | — | 553454734 | ||
| CVE-2026-106346 | High | Improper state validation in DevTools. | 2026-09-26 | — | 566404364 | ||
| CVE-2026-106349 | High | Use after free in V8. | Xinyang Ge (Anthropic), assisted by Claude | 2026-09-29 | — | 567538973 | |
| CVE-2026-106357 | High | Use after free in WebRTC. | Xinyang Ge (Anthropic), assisted by Claude | 2026-09-28 | — | 567160162 | |
| CVE-2026-106364 | High | Incorrect authorization in Omnibox. | 2026-07-28 | — | 540018068 | ||
| CVE-2026-106366 | High | Incomplete cleanup in CustomTabs. | Naoya Miyaguchi | 2026-08-24 | $2000 | 552115620 | |
| CVE-2026-106369 | High | Missing authorization in Translate. | M. Fauzan Wijaya (Gh05t666nero) | 2026-07-26 | $1000 | 539043243 | |
| CVE-2026-106376 | High | Uninitialized resource in ANGLE. | weihengqiuu | 2026-08-28 | $2000 | 553881031 | |
| CVE-2026-106377 | High | Race condition in Fonts. | 2026-06-05 | — | 520179149 | ||
| CVE-2026-106379 | High | Uninitialized resource in Skia. | 2026-09-15 | — | 561987051 | ||
| CVE-2026-106383 | High | Use after free in Media. | Xinyang Ge (Anthropic), assisted by Claude | 2026-09-29 | — | 567447106 | |
| CVE-2026-106393 | High | Use after free in Storage. | Xinyang Ge | 2026-09-10 | — | 559793873 | |
| CVE-2026-106396 | High | Improper input validation in Omnibox. | 2026-08-25 | — | 552423127 | ||
| CVE-2026-106411 | High | Use after free in Parser. | Xinyang Ge (Anthropic), assisted by Claude | 2026-09-25 | — | 566136674 | |
| CVE-2026-106412 | High | Race condition in Core. | 2026-06-06 | — | 520755056 | ||
| CVE-2026-106419 | High | Use after free in ANGLE. | Shaked Reiner (Palo Alto Networks) | 2026-08-21 | — | 550379413 | |
| CVE-2026-106421 | High | Use after free in PDF. | Xinyang Ge (Anthropic), assisted by Claude | 2026-09-30 | — | 567873463 | |
| CVE-2026-106423 | High | Use after free in Media. | Xinyang Ge (Anthropic), assisted by Claude | 2026-09-26 | — | 566347711 | |
| CVE-2026-106426 | High | Race condition in Fonts. | Emond Papegaaij | 2026-08-17 | — | 547065823 | |
| CVE-2026-106180 | Medium | Observable discrepancy in Animation. | 2026-05-28 | — | 517429254 | ||
| CVE-2026-106181 | Medium | Incorrect reference resolution in DevTools. | 2026-03-29 | — | 497350668 | ||
| CVE-2026-106182 | Medium | UI misrepresentation in Paint. | 2026-05-17 | — | 514078734 | ||
| CVE-2026-106183 | Medium | Missing authorization in Chromoting. | 2026-08-26 | — | 553154579 | ||
| CVE-2026-106185 | Medium | Improper input validation in Viz. | 2026-04-14 | — | 502462485 | ||
| CVE-2026-106188 | Medium | Confused deputy in SignIn. | 2026-05-21 | — | 515477538 | ||
| CVE-2026-106189 | Medium | Code injection in ReaderMode. | 2026-04-13 | — | 502034469 | ||
| CVE-2026-106194 | Medium | Missing authorization in WebAppInstalls. | 2026-04-01 | — | 498739277 | ||
| CVE-2026-106196 | Medium | Missing authorization in Navigation. | 2026-04-19 | — | 504215649 | ||
| CVE-2026-106198 | Medium | Missing authorization in FileSystem. | pakhunov.anton.n | 2026-05-07 | — | 510773353 | |
| CVE-2026-106201 | Medium | Race condition in V8. | 2026-05-28 | — | 517546096 | ||
| CVE-2026-106205 | Medium | Missing authorization in Passwords. | 2026-06-03 | — | 519499907 | ||
| CVE-2026-106206 | Medium | Improper input validation in Mobile. | 2026-05-28 | — | 517374100 | ||
| CVE-2026-106207 | Medium | Race condition in V8. | flyyy | 2026-08-30 | — | 554619028 | |
| CVE-2026-106208 | Medium | Missing authorization in API. | 2026-03-28 | — | 497062057 | ||
| CVE-2026-106209 | Medium | UI misrepresentation in Mobile. | 2026-05-29 | — | 518039724 | ||
| CVE-2026-106210 | Medium | Observable discrepancy in Scroll. | Hafiizh | 2026-09-03 | — | 556304559 | |
| CVE-2026-106212 | Medium | Incorrect authorization in Autofill. | 2026-07-28 | — | 540072162 | ||
| CVE-2026-106213 | Medium | Race condition in WebAudio. | 2026-06-05 | — | 520153320 | ||
| CVE-2026-106216 | Medium | Cross-site request forgery in ReadingList. | 2026-05-30 | — | 518076654 | ||
| CVE-2026-106217 | Medium | Missing authorization in Google Lens. | 2026-04-12 | — | 501770489 | ||
| CVE-2026-106222 | Medium | Incorrect authorization in Sync. | 2026-03-26 | — | 496623893 | ||
| CVE-2026-106223 | Medium | Uninitialized resource in GPU. | 2026-04-11 | — | 501633302 | ||
| CVE-2026-106224 | Medium | Missing authorization in Google Lens. | 2026-04-13 | — | 502278429 | ||
| CVE-2026-106225 | Medium | Missing authorization in Autofill. | 2026-04-12 | — | 501805355 | ||
| CVE-2026-106226 | Medium | Improper input validation in Compositing. | 2026-06-06 | — | 520573237 | ||
| CVE-2026-106228 | Medium | Confused deputy in Google Lens. | 2026-05-29 | — | 517689673 | ||
| CVE-2026-106229 | Medium | UI misrepresentation in FileSystem. | 2026-06-09 | — | 521949525 | ||
| CVE-2026-106230 | Medium | Incorrect reference resolution in Offline. | 2026-06-05 | — | 520507737 | ||
| CVE-2026-106232 | Medium | UI misrepresentation in Browser. | 2026-06-10 | — | 522299740 | ||
| CVE-2026-106238 | Medium | Race condition in Fonts. | c6eed09fc8b174b0f3eebedcceb1e792 | 2026-03-13 | $3000 | 492374387 | |
| CVE-2026-106241 | Medium | Incorrect authorization in Search. | 2026-04-11 | — | 501729675 | ||
| CVE-2026-106242 | Medium | Information leak in Omnibox. | 2026-04-11 | — | 501647772 | ||
| CVE-2026-106244 | Medium | Incorrect authorization in Permissions. | 2026-04-14 | — | 502475175 | ||
| CVE-2026-106246 | Medium | Incorrect authorization in Browser. | 2026-05-17 | — | 514070956 | ||
| CVE-2026-106253 | Medium | Incorrect authorization in Extensions. | 2026-05-16 | — | 513741326 | ||
| CVE-2026-106254 | Medium | Information leak in Mobile. | Anonymous | 2026-09-04 | — | 557036053 | |
| CVE-2026-106261 | Medium | Uninitialized resource in Video. | 2026-04-20 | — | 504638005 | ||
| CVE-2026-106262 | Medium | Incomplete cleanup in GetUserMedia. | 2026-07-09 | — | 533066295 | ||
| CVE-2026-106263 | Medium | Improper input validation in SignIn. | 2026-08-26 | — | 553149001 | ||
| CVE-2026-106265 | Medium | UI misrepresentation in File. | Umar Farooq | 2024-11-25 | $3000 | 380789337 | |
| CVE-2026-106266 | Medium | Confused deputy in Contextual Tasks. | 2026-04-12 | — | 501914204 | ||
| CVE-2026-106267 | Medium | Missing authorization in Network. | 2026-04-01 | — | 498737756 | ||
| CVE-2026-106271 | Medium | Missing authorization in Workers. | 2026-08-26 | — | 553118313 | ||
| CVE-2026-106274 | Medium | Incorrect reference resolution in Browser. | 2026-03-30 | — | 497842821 | ||
| CVE-2026-106277 | Medium | Information leak in Animation. | 2026-05-29 | — | 517708426 | ||
| CVE-2026-106279 | Medium | Incorrect reference resolution in Passwords. | 2026-05-16 | — | 513757840 | ||
| CVE-2026-106280 | Medium | Incorrect authorization in PermissionElement. | 2026-05-28 | — | 517366426 | ||
| CVE-2026-106282 | Medium | UI misrepresentation in WebOTP. | 2026-05-18 | — | 514204338 | ||
| CVE-2026-106283 | Medium | Use after free in Streaming. | 2026-04-04 | — | 499468981 | ||
| CVE-2026-106284 | Medium | Out of bounds read in Printing. | 2026-05-29 | — | 517804731 | ||
| CVE-2026-106286 | Medium | Confused deputy in Omnibox. | 2026-03-28 | — | 497148613 | ||
| CVE-2026-106289 | Medium | Missing authorization in FedCM. | 2026-05-29 | — | 517700327 | ||
| CVE-2026-106290 | Medium | Uninitialized resource in GPU. | 2026-04-28 | — | 507351786 | ||
| CVE-2026-106291 | Medium | Use after free in GarbageCollection. | 2026-04-04 | — | 499571442 | ||
| CVE-2026-106292 | Medium | Buffer overflow in Fonts. | 2026-06-16 | — | 524587778 | ||
| CVE-2026-106295 | Medium | Incorrect authorization in Unbounded Element. | 2026-08-26 | — | 553138969 | ||
| CVE-2026-106300 | Medium | Race condition in CacheStorage. | 2026-04-06 | — | 500106110 | ||
| CVE-2026-106301 | Medium | Confused deputy in Contextual Tasks. | 2026-06-14 | — | 523750306 | ||
| CVE-2026-106302 | Medium | UI misrepresentation in PermissionElement. | 2026-05-17 | — | 514071472 | ||
| CVE-2026-106303 | Medium | Observable discrepancy in Autofill AI. | 2026-05-28 | — | 517475258 | ||
| CVE-2026-106304 | Medium | Out of bounds read in ANGLE. | 2026-08-26 | — | 553124799 | ||
| CVE-2026-106307 | Medium | Incorrect authorization in Network. | 2026-07-22 | — | 537832408 | ||
| CVE-2026-106311 | Medium | Clickjacking in PermissionElement. | 2026-05-17 | — | 514061289 | ||
| CVE-2026-106313 | Medium | Incorrect authorization in Browser. | 2026-04-02 | — | 498770931 | ||
| CVE-2026-106314 | Medium | Incorrect authorization in Bluetooth. | 2026-04-10 | — | 501533684 | ||
| CVE-2026-106315 | Medium | Use after free in Modularization. | 2026-03-30 | — | 497652727 | ||
| CVE-2026-106321 | Medium | Information leak in Editing. | 2026-09-02 | — | 556235808 | ||
| CVE-2026-106322 | Medium | Open redirect in AppManifest. | 2026-05-27 | — | 517213220 | ||
| CVE-2026-106324 | Medium | Incorrect authorization in WebAppInstalls. | Narenda Singh (@_3P1C) | 2026-04-09 | $2000 | 501171258 | |
| CVE-2026-106326 | Medium | Confused deputy in UI. | 2026-05-10 | — | 511745101 | ||
| CVE-2026-106328 | Medium | Incorrect authorization in PDF. | 2026-05-30 | — | 518091868 | ||
| CVE-2026-106330 | Medium | Information leak in Paint. | 2026-08-26 | — | 553135213 | ||
| CVE-2026-106333 | Medium | Incorrect authorization in Input. | 2026-05-28 | — | 517649552 | ||
| CVE-2026-106335 | Medium | Use after free in Media. | 2026-04-13 | — | 502105238 | ||
| CVE-2026-106336 | Medium | Observable discrepancy in Paint. | 2026-06-11 | — | 522722456 | ||
| CVE-2026-106337 | Medium | UI misrepresentation in UI. | 2026-08-26 | — | 553145497 | ||
| CVE-2026-106341 | Medium | Type confusion in V8. | 2026-09-08 | — | 558539954 | ||
| CVE-2026-106342 | Medium | Information leak in Autofill. | 2026-05-13 | — | 512998592 | ||
| CVE-2026-106348 | Medium | Information leak in Animation. | 2026-07-21 | — | 537107728 | ||
| CVE-2026-106351 | Medium | Observable discrepancy in Safebrowsing. | 2026-08-27 | — | 553164077 | ||
| CVE-2026-106352 | Medium | Incorrect authorization in WebProtect. | 2026-08-26 | — | 553139506 | ||
| CVE-2026-106354 | Medium | Improper resource exposure in Extensions. | 2026-05-10 | — | 511796554 | ||
| CVE-2026-106356 | Medium | Clickjacking in EVP. | 2026-05-27 | — | 517090646 | ||
| CVE-2026-106360 | Medium | Information leak in Payments. | NH DEV | 2026-07-17 | — | 535639435 | |
| CVE-2026-106361 | Medium | Incorrect provision of specified functionality in Mobile. | 2026-05-16 | — | 513781133 | ||
| CVE-2026-106363 | Medium | Missing authorization in FullScreen. | 2026-04-12 | — | 501896592 | ||
| CVE-2026-106365 | Medium | Missing authorization in Animation. | 2026-03-31 | — | 498075038 | ||
| CVE-2026-106367 | Medium | Missing authorization in Mobile. | 2026-06-05 | — | 520533412 | ||
| CVE-2026-106370 | Medium | Uninitialized resource in GPU. | 2026-05-27 | — | 517033396 | ||
| CVE-2026-106372 | Medium | Incorrect authorization in UI. | Quyen Son at VinFast (@zer0qs) | 2026-09-05 | — | 557288890 | |
| CVE-2026-106373 | Medium | Use after free in Fonts. | 2026-06-13 | — | 523699645 | ||
| CVE-2026-106375 | Medium | Incomplete cleanup in Dawn. | 2026-07-19 | — | 536507840 | ||
| CVE-2026-106378 | Medium | Privilege elevation in Sandbox. | Paulos Yibelo Mesfin | 2026-04-29 | — | 507596239 | |
| CVE-2026-106381 | Medium | Incorrect authorization in Passwords. | 2026-04-11 | — | 501763586 | ||
| CVE-2026-106384 | Medium | Missing authorization in SiteIsolation. | med.bassia | 2026-08-29 | — | 554348119 | |
| CVE-2026-106386 | Medium | Uninitialized resource in WebAudio. | 2026-08-26 | — | 553156221 | ||
| CVE-2026-106387 | Medium | Missing authorization in Mobile. | 2026-05-30 | — | 518096516 | ||
| CVE-2026-106388 | Medium | Missing authorization in DataTransfer. | leolee | 2026-08-21 | — | 550512266 | |
| CVE-2026-106389 | Medium | Incorrect authorization in USB. | 2026-04-17 | — | 503625361 | ||
| CVE-2026-106391 | Medium | Incorrect authorization in WebShare. | 2026-06-10 | — | 522325665 | ||
| CVE-2026-106392 | Medium | Information leak in WebAudio. | 2026-05-18 | — | 514426571 | ||
| CVE-2026-106395 | Medium | Uninitialized resource in Dawn. | 2026-08-26 | — | 553121488 | ||
| CVE-2026-106397 | Medium | Incorrect authorization in Mobile. | 2026-04-17 | — | 503725788 | ||
| CVE-2026-106398 | Medium | Incorrect authorization in Media. | caveeroo | 2026-08-05 | — | 543082212 | |
| CVE-2026-106400 | Medium | Clickjacking in Messages. | 2026-05-30 | — | 518108937 | ||
| CVE-2026-106401 | Medium | Out of bounds write in Media. | 2026-08-26 | — | 553129739 | ||
| CVE-2026-106402 | Medium | Incorrect authorization in Extensions. | 2026-05-17 | — | 514041626 | ||
| CVE-2026-106403 | Medium | Incorrect authorization in Accessibility. | 2026-06-13 | — | 523601696 | ||
| CVE-2026-106404 | Medium | Incorrect authorization in FontAccess. | 2026-08-26 | — | 553150261 | ||
| CVE-2026-106405 | Medium | Race condition in CustomTabs. | 2026-05-27 | — | 517150523 | ||
| CVE-2026-106406 | Medium | Missing authorization in Mobile. | 2026-04-22 | — | 505186109 | ||
| CVE-2026-106407 | Medium | Incorrect authorization in GetUserMedia. | 2026-04-14 | — | 502648640 | ||
| CVE-2026-106408 | Medium | Protection mechanism failure in Mobile. | 2026-04-19 | — | 504227656 | ||
| CVE-2026-106409 | Medium | Incorrect reference resolution in WebAppInstalls. | Quyen Son at VinFast (@zer0qs) | 2026-09-09 | — | 559097675 | |
| CVE-2026-106410 | Medium | Missing authorization in Permissions. | 2026-05-29 | — | 517801814 | ||
| CVE-2026-106414 | Medium | Improper input validation in Mobile. | 2026-04-19 | — | 504223609 | ||
| CVE-2026-106415 | Medium | Information leak in Enterprise. | 2026-04-13 | — | 502179715 | ||
| CVE-2026-106416 | Medium | Code injection in Extensions. | 2026-05-17 | — | 514072462 | ||
| CVE-2026-106420 | Medium | Incorrect calculation in API. | Luan Herrera (@lbherrera_) | 2026-01-21 | $1000 | 477327257 | |
| CVE-2026-106424 | Medium | Information leak in Audio. | 2026-05-15 | — | 513365978 | ||
| CVE-2026-106425 | Medium | Missing authorization in BrowserTag. | 2026-04-12 | — | 501790682 | ||
| CVE-2026-106179 | Low | UI misrepresentation in WebAppInstalls. | 2026-08-27 | — | 553250818 | ||
| CVE-2026-106186 | Low | Uncontrolled search path element in CredentialProvider. | 2026-06-11 | — | 522557469 | ||
| CVE-2026-106187 | Low | Missing authorization in Permissions. | 2026-05-10 | — | 511776800 | ||
| CVE-2026-106191 | Low | Missing authorization in Actor. | 2026-04-13 | — | 502282293 | ||
| CVE-2026-106192 | Low | Information leak in Mobile. | 2026-06-16 | — | 524681280 | ||
| CVE-2026-106195 | Low | Incorrect authorization in Chromoting. | 2026-08-28 | — | 553930843 | ||
| CVE-2026-106199 | Low | Incorrect authorization in Actor. | 2026-05-29 | — | 517703787 | ||
| CVE-2026-106220 | Low | Information leak in Passwords. | 2026-07-14 | — | 534843648 | ||
| CVE-2026-106221 | Low | Confused deputy in WebAPKs. | 2026-07-28 | — | 540049672 | ||
| CVE-2026-106234 | Low | Use after free in Network. | Findingz | 2026-09-20 | — | 564085088 | |
| CVE-2026-106236 | Low | UI misrepresentation in Chromoting. | 2026-09-02 | — | 556233068 | ||
| CVE-2026-106237 | Low | Information leak in Permissions. | 2026-08-27 | — | 553255283 | ||
| CVE-2026-106247 | Low | Buffer overflow in ANGLE. | 2026-06-16 | — | 524435922 | ||
| CVE-2026-106249 | Low | Incorrect authorization in Autofill. | mute1008 | 2026-08-25 | — | 552440317 | |
| CVE-2026-106250 | Low | Missing authorization in Actor. | 2026-04-14 | — | 502497790 | ||
| CVE-2026-106251 | Low | UI misrepresentation in Chromoting. | 2026-09-02 | — | 556237314 | ||
| CVE-2026-106252 | Low | Incorrect comparison in Fonts. | 2026-05-15 | — | 513446410 | ||
| CVE-2026-106256 | Low | Information leak in Passwords. | 2026-08-27 | — | 553335319 | ||
| CVE-2026-106259 | Low | Incorrect authorization in PermissionElement. | 2026-07-28 | — | 540076586 | ||
| CVE-2026-106260 | Low | Incorrect authorization in DevTools. | 2026-05-16 | — | 513821237 | ||
| CVE-2026-106264 | Low | Missing authorization in Web Authentication (Passkeys & Security Keys). | 2026-07-09 | — | 533084756 | ||
| CVE-2026-106269 | Low | Use after free in CSS. | xinyang | 2026-09-24 | — | 565742178 | |
| CVE-2026-106270 | Low | Incorrect authorization in WebAppInstalls. | 2026-08-27 | — | 553269860 | ||
| CVE-2026-106272 | Low | UI misrepresentation in Chromoting. | 2026-09-02 | — | 556259957 | ||
| CVE-2026-106275 | Low | Uninitialized resource in GPU. | 2026-05-19 | — | 514460295 | ||
| CVE-2026-106276 | Low | UI misrepresentation in Payments. | Khalil Zhani | 2025-05-14 | $1000 | 417555081 | |
| CVE-2026-106285 | Low | UI misrepresentation in WebAppInstalls. | 2026-07-09 | — | 533119681 | ||
| CVE-2026-106287 | Low | Information loss in CORS. | 2026-05-15 | — | 513518289 | ||
| CVE-2026-106288 | Low | Missing authorization in Browser. | 2026-08-27 | — | 553274076 | ||
| CVE-2026-106294 | Low | Incomplete cleanup in Chromoting. | 2026-09-02 | — | 556215048 | ||
| CVE-2026-106296 | Low | Improper privilege management in UI. | 2026-07-28 | — | 540078886 | ||
| CVE-2026-106297 | Low | Incorrect authorization in Scheduling. | 2026-05-16 | — | 513735469 | ||
| CVE-2026-106299 | Low | Improper input validation in WebAudio. | 2026-06-02 | — | 519211890 | ||
| CVE-2026-106305 | Low | UI misrepresentation in Mobile. | 2026-08-27 | — | 553276352 | ||
| CVE-2026-106306 | Low | Incorrect authorization in DevTools. | 2026-05-15 | — | 513383360 | ||
| CVE-2026-106309 | Low | Incorrect authorization in Selection. | Putra Mahardika | Instagram @mhrdkaa._ | 2026-04-17 | — | 503708636 |
| CVE-2026-106310 | Low | Use of released resource in FontAccess. | 2026-09-02 | — | 556250086 | ||
| CVE-2026-106312 | Low | Missing authorization in SignIn. | 2026-04-13 | — | 502111211 | ||
| CVE-2026-106316 | Low | UI misrepresentation in Chromoting. | 2026-08-29 | — | 554556423 | ||
| CVE-2026-106317 | Low | UI misrepresentation in FullScreen. | Manojkumar Jaganathan ( https://www.linkedin.com/in/manojkumar-j-7ba35b202/ ) Aka TheWhiteEvil ( https://hackerone.com/the-white-evil ) with HackerBro Technologies | 2025-10-09 | — | 450323465 | |
| CVE-2026-106320 | Low | Use of released resource in UI. | 2026-08-28 | — | 553929758 | ||
| CVE-2026-106325 | Low | Incorrect reference resolution in Core. | 2026-09-02 | — | 556211265 | ||
| CVE-2026-106331 | Low | Improper input validation in Extensions. | 2026-08-27 | — | 553256068 | ||
| CVE-2026-106334 | Low | Information leak in Payments. | 2026-09-02 | — | 556229780 | ||
| CVE-2026-106338 | Low | UI misrepresentation in PictureInPicture. | Hafiizh | 2025-10-02 | — | 448789663 | |
| CVE-2026-106339 | Low | Use of released resource in Core. | 2026-08-28 | — | 553913506 | ||
| CVE-2026-106340 | Low | Missing authorization in CredentialProvider. | Wooseok Sung | 2026-04-17 | $2000 | 503794852 | |
| CVE-2026-106343 | Low | Improper state validation in Autofill AI. | 2026-08-27 | — | 553317583 | ||
| CVE-2026-106344 | Low | Missing authorization in Permissions. | 2026-04-01 | — | 498375898 | ||
| CVE-2026-106345 | Low | Use of released resource in Session. | 2026-09-02 | — | 556258544 | ||
| CVE-2026-106350 | Low | Incorrect authorization in Browser. | 2026-08-27 | — | 553270559 | ||
| CVE-2026-106353 | Low | Improper input validation in Mobile. | 2026-04-13 | — | 502078791 | ||
| CVE-2026-106355 | Low | Missing authorization in Media. | 2026-09-10 | — | 559777100 | ||
| CVE-2026-106359 | Low | Confused deputy in DeviceBoundSessionCredentials. | 2026-04-08 | — | 500532594 | ||
| CVE-2026-106362 | Low | Missing authorization in DevTools. | 2026-05-19 | — | 514456975 | ||
| CVE-2026-106368 | Low | UI misrepresentation in UI. | 2026-08-27 | — | 553252261 | ||
| CVE-2026-106371 | Low | Incorrect authorization in Transactions Platform. | 2026-08-27 | — | 553326010 | ||
| CVE-2026-106374 | Low | Type confusion in V8. | SecBuddyN, Tencent KeenLab (CodeBuddy Security) | 2026-08-26 | — | 552832446 | |
| CVE-2026-106380 | Low | UI misrepresentation in UI. | 2026-08-27 | — | 553168380 | ||
| CVE-2026-106385 | Low | Race condition in Chromoting. | 2026-08-30 | — | 554874487 | ||
| CVE-2026-106390 | Low | Incorrect provision of specified functionality in SanitizerAPI. | 2026-09-02 | — | 556213916 | ||
| CVE-2026-106394 | Low | Incomplete cleanup in Glic. | Project Fortify | 2026-05-14 | — | 513122002 | |
| CVE-2026-106399 | Low | Out of bounds read in Skia. | 2026-07-01 | — | 530237174 | ||
| CVE-2026-106413 | Low | Race condition in Browser. | 2026-08-27 | — | 553336689 | ||
| CVE-2026-106417 | Low | Integer overflow in Media. | 2026-07-19 | — | 536471438 | ||
| CVE-2026-106418 | Low | Missing authorization in Network. | 2026-08-27 | — | 553283471 | ||
| CVE-2026-106422 | Low | Incorrect authorization in API. | 2026-06-03 | — | 519458746 | ||
| CVE-2026-106427 | Low | Confused deputy in Mobile. | 2026-05-15 | — | 513423334 |
Methodology Notes
- Structured CVE data extracted via
unjam --cve. - Vulnerability types and component areas classified from CVE description text.
- Bounty amounts from the
bountyfield in unjam output. - External researchers identified from the
reporterfield (non-Google, non-anonymous).