CVE tracker
385 subscribers
5.43K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-84333 - Google Chrome Dawn Use-After-Free Vulnerability

CVE ID :CVE-2026-84333
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84351 - Google Chrome GPU Buffer Overflow

CVE ID :CVE-2026-84351
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84325 - Google Chrome DataTransfer Improper Input Validation

CVE ID :CVE-2026-84325
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84328 - Google Chrome FileSystem Authorization Bypass

CVE ID :CVE-2026-84328
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84347 - Google Chrome WebRTC Use-After-Free Vulnerability

CVE ID :CVE-2026-84347
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84323 - Google Chrome FileSystem Missing Authorization Vulnerability

CVE ID :CVE-2026-84323
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84355 - Google Chrome Navigation Incorrect Authorization

CVE ID :CVE-2026-84355
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84358 - Google Chrome Downloads Improper Privilege Management Address Bar Spoofing

CVE ID :CVE-2026-84358
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Improper privilege management in Downloads in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84332 - Google Chrome SiteSettings Authorization Bypass

CVE ID :CVE-2026-84332
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Incorrect authorization in SiteSettings in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84330 - Google Chrome Address Bar Spoofing via Fullscreen UI Misrepresentation

CVE ID :CVE-2026-84330
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :UI misrepresentation in FullScreen in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84334 - Google Chrome Chromoting Local Privilege Escalation

CVE ID :CVE-2026-84334
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84348 - Google Chrome MediaCapture Information Disclosure

CVE ID :CVE-2026-84348
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Information leak in MediaCapture in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84335 - Google Chrome TabStrip Improper Authorization

CVE ID :CVE-2026-84335
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84327 - Google Chrome Autofill Improper Authorization

CVE ID :CVE-2026-84327
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84329 - Google Chrome CredentialProvider Confused Deputy Vulnerability

CVE ID :CVE-2026-84329
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Confused deputy in CredentialProvider in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84356 - Google Chrome FullScreen UI Spoofing Vulnerability

CVE ID :CVE-2026-84356
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84350 - Google Chrome TabStrip Use-After-Free Vulnerability

CVE ID :CVE-2026-84350
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Low)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84331 - Google Chrome Actor Web Origin Policy Bypass

CVE ID :CVE-2026-84331
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84425 - zhayujie CowAgent Browser Tool browser_tool.py BrowserTool denial of service

CVE ID :CVE-2026-84425
Published : Sept. 2, 2026, 1:17 a.m. | 2 hours, 52 minutes ago
Description :A vulnerability was found in zhayujie CowAgent up to 2.1.3. This impacts the function BrowserTool of the file agent/tools/browser/browser_tool.py of the component Browser Tool. Performing a manipulation results in denial of service. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84427 - zhayujie CowAgent Bash Tool bash.py denial of service

CVE ID :CVE-2026-84427
Published : Sept. 2, 2026, 1:17 a.m. | 2 hours, 52 minutes ago
Description :A vulnerability was determined in zhayujie CowAgent up to 2.1.7. Affected is an unknown function of the file agent/tools/bash/bash.py of the component Bash Tool. Executing a manipulation can lead to denial of service. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84430 - gouguoa edit_personal Endpoint Index.php update dynamically-determined object attributes

CVE ID :CVE-2026-84430
Published : Sept. 2, 2026, 1:17 a.m. | 2 hours, 52 minutes ago
Description :A security vulnerability has been detected in gouguoa up to 5.10.0/6.0.1. This vulnerability affects the function update of the file app/home/controller/Index.php of the component edit_personal Endpoint. Such manipulation of the argument position_id leads to dynamically-determined object attributes. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 6.0.3 is able to resolve this issue. Upgrading the affected component is advised.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...