If you find new issues, please let us know one of the following ways
File a bug
Visit our ChromeOS communities
General: Chromebook Help Community
Beta Specific: ChromeOS Beta Help Community
Report an issue or send feedback on Chrome
Interested in switching channels? Find out how.
Alon Bajayo,
Google ChromeOS
ChromeOS Vulnerability Rewards Program Reported Bug Fixes:
N/A
Other 3rd Party Security Fixes Included:
High Fixes mali_kbase: use-after-free write in delete_hoarded_chunks allows GPU-process to kernel memory corruption
High Fixes Potential StartArcVm unvalidated wayland_server field leads to crosvm sandbox weakening
Android Security fixes can be found here
Chrome Browser Security Fixes:
[$TBD] [562242429] High CVE-2026-95351 Use after free in Views Reported by [Xinyang Ge ] on 2026-09-15
[$TBD] [562151598] Critical CVE-2026-95310 Use after free in AdFilter Reported by [Xinyang Ge ] on 2026-09-15
[$TBD] [560439699] Critical CVE-2026-95356 Use after free in WindowDialog Reported by [Xinyang Ge ] on 2026-09-12
[$TBD] [560536735] High CVE-2026-95306 Type confusion in V8 on 2026-09-12
[$TBD] [560536731] High CVE-2026-95304 Out of bounds write in V8 on 2026-09-12
[$TBD] [560406548] High CVE-2026-95280 Race condition in V8 on 2026-09-11
[$1000.0] [559815527] High CVE-2026-95343 Use after free in WebAudio Reported by [HoneyBee] on 2026-09-10
[$TBD] [559682346] Medium CVE-2026-95333 Use after free in Metrics on 2026-09-10
[$TBD] [558764482] High CVE-2026-95365 Type confusion in IndexedDB Reported by [~~Anaconda~~ HoneyBee] on 2026-09-08
[$500.0] [557523002] High CVE-2026-95286 Type confusion in Bindings on 2026-09-05
[$TBD] [556576976] High CVE-2026-95318 Buffer overflow in Video on 2026-09-03
[$1000.0] [556535630] High CVE-2026-95338 Use after free in PDFium on 2026-09-03
[$TBD] [555299641] High CVE-2026-95335 Use after free in HID Reported by [WinD39 - Huynh Dinh Vu] on 2026-08-31
[$TBD] [554558320] High CVE-2026-95348 Use after free in Bluetooth on 2026-08-29
[$TBD] [553921181] Low CVE-2026-95305 UI misrepresentation in Chromoting on 2026-08-28
[$TBD] [553271219] Low CVE-2026-95364 Improper input validation in Passwords on 2026-08-26
[$TBD] [553268567] Low CVE-2026-95340 Incorrect authorization in PictureInPicture on 2026-08-26
[$TBD] [553136141] High CVE-2026-95277 Use after free in Views on 2026-08-26
[$TBD] [553130481] High CVE-2026-95373 Use after free in DevTools on 2026-08-26
[$TBD] [553129513] High CVE-2026-95282 Use after free in Platform on 2026-08-26
[$TBD] [553123003] Medium CVE-2026-95311 Free of non-heap memory in Fonts on 2026-08-26
[$TBD] [553116160] High CVE-2026-95274 Improper output encoding in DevTools on 2026-08-26
[$TBD] [552665794] Critical CVE-2026-95313 Use after free in Fullscreen Reported by [WinD39 - Huynh Dinh Vu] on 2026-08-26
[$TBD] [552023752] Low CVE-2026-95316 Unchecked return value in Performance on 2026-08-24
[$TBD] [550953039] High CVE-2026-95293 Uninitialized resource in GPU on 2026-08-22
[$TBD] [549911100] Medium CVE-2026-95289 Incorrect authorization in Scroll on 2026-08-21
[$TBD] [548611433] Medium CVE-2026-95344 Race condition in DevTools on 2026-08-18
[$2500.0] [548585299] Critical CVE-2026-95339 Use after free in ServiceWorker on 2026-08-18
[$TBD] [547832510] Medium CVE-2026-95312 Information leak in Passwords Reported by [[goes here]] on 2026-08-17
[$TBD] [547027738] Low CVE-2026-95342 Missing authorization in V8 Reported by [Hongwei Li, Zhun Wang, Ziyue Pan, Junmin Zhu, Saastha Vasan, and Wenbo Guo] on 2026-08-16
[$TBD] [545449081] Medium CVE-2026-95300 Missing authorization in DevTools on 2026-08-12
[$TBD] [543464436] Medium CVE-2026-95374 Incorrect authorization in Network Reported by [NH DEV] on 2026-08-06
[$TBD] [542926849] Medium CVE-2026-95275 Incorrect reference resolution in MediaStream on 2026-08-05
[$5000.0] [540265100] High CVE-2026-95301 Missing authorization in Extensions on 2026-07-29
[$TBD] [537857253] High CVE-2026-95324 Uninitialized resource in GPU on 2026-07-22
[$TBD] [536648933] Medium CVE-2026-95325 Use after free in ANGLE on 2026-07-19
[$TBD] [536161355] Medium CVE-2026-95290 Missing authorization in NFC on 2026-07-17
[$TBD] [534997484] High CVE-2026-95372 Use after free in Chromecast on 2026-07-14
[$TBD] [534579660] Low CVE-2026-95380 Type confusion in V8 on 2026-07-13
[$TBD] [533095855] Low CVE-2026-95361 Confused deputy in DevTools on 2026-07-09
[$TBD] [533041383] Low CVE-2026-95326 Incomplete cleanup in Bluetooth on 2026-07-09
[$TBD] [532962621] Medium CVE-2026-95336 Information leak in Transactions Platform on 2026-07-09
[$TBD] [524582798] Medium CVE-2026-95354 Use after free in Verifier on 2026-06-16
[$TBD] [523719002] Medium CVE-2026-95341 Improper input validation in Desktop on 2026-06-13
[$TBD] [522413520] Low CVE-2026-95368 Incorrect authorization in DevTools on 2026-06-10
[$TBD] [522344883] Medium CVE-2026-95363 UI misrepresentation in FileSystem on 2026-06-10
[$TBD] [522061704] Medium CVE-2026-95353 Use after free in Bindings on 2026-06-09
[$TBD] [520516206] High CVE-2026-95298 Use after free in Browser on 2026-06-05
[$TBD] [517802696] Medium CVE-2026-95314 Incorrect authorization in HID on 2026-05-29
[$TBD] [517730821] Medium CVE-2026-95276 Improper input validation in Themes on 2026-05-28
[$TBD] [517661385] High CVE-2026-95315 Use after free in Aura on 2026-05-28
[$TBD] [517584808] Medium CVE-2026-95360 Race condition in Editing on 2026-05-28
[$TBD] [517442714] Medium CVE-2026-95303 Incomplete cleanup in SmartCard on 2026-05-28
[$TBD] [517417437] Medium CVE-2026-95370 Inappropriate implementation in NFC on 2026-05-28
[$TBD] [517163294] Medium CVE-2026-95330 Improper state validation in Downloads on 2026-05-27
[$TBD] [516404074] Medium CVE-2026-95345 Use after free in Actor on 2026-05-25
[$TBD] [514524620] Low CVE-2026-95367 Information leak in DataTransfer on 2026-05-18
[$TBD] [514487499] Medium CVE-2026-95317 Incorrect authorization in MediaCapture on 2026-05-18
[$TBD] [514072284] Medium CVE-2026-95320 Missing authorization in Navigation on 2026-05-17
[$TBD] [514059630] Medium CVE-2026-95346 UI misrepresentation in Chromoting on 2026-05-17
[$TBD] [513992281] Medium CVE-2026-95294 UI misrepresentation in Browser on 2026-05-17
[$TBD] [513791872] Low CVE-2026-95352 Incorrect authorization in DevTools on 2026-05-16
[$TBD] [513781838] Low CVE-2026-95292 Incorrect authorization in Safebrowsing on 2026-05-16
[$TBD] [513714849] Low CVE-2026-95308 Integer overflow in Metrics on 2026-05-15
[$TBD] [513403696] Low CVE-2026-95334 Incorrect reference resolution in WebProtect on 2026-05-14
[$TBD] [513134076] Medium CVE-2026-95376 Externally controlled reference in DevTools on 2026-05-14
[$TBD] [513049042] Medium CVE-2026-95369 Inappropriate implementation in XML on 2026-05-13
[$TBD] [511791538] Medium CVE-2026-95362 Cross-site request forgery in DevTools on 2026-05-10
[$TBD] [502179319] Medium CVE-2026-95375 Incorrect authorization in BrowserTag on 2026-04-13
[$TBD] [502077689] Low CVE-2026-95327 Information leak in Networking on 2026-04-13
[$TBD] [501648493] Medium CVE-2026-95297 Missing authorization in Contextual Tasks on 2026-04-11
[$TBD] [497603247] Medium CVE-2026-95381 Improper input validation in Printing on 2026-03-29
[$TBD] [497344014] Low CVE-2026-95278 Missing authorization in WakeLock on 2026-03-28
[$TBD] [497212105] Medium CVE-2026-95382 Improper input validation in Auth on 2026-03-28
[$TBD] [497204165] Medium CVE-2026-95366 Use of released resource in Core on 2026-03-28
[$TBD] [495529018] Medium CVE-2026-95287 Missing authorization in Navigation on 2026-03-23
[$500.0] [423956129] Low CVE-2026-95307 UI misrepresentation in ExtensionsMenu on 2025-06-10
[$TBD] [565328105] High CVE-2026-102321 Type confusion in V8 on 2026-09-23
[$TBD] [563716534] High CVE-2026-102302 Buffer overflow in V8 on 2026-09-19
[$5000.0] [563297615] High CVE-2026-102329 Cross-site scripting in WebUI on 2026-09-18
[$TBD] [562279351] High CVE-2026-102318 Out of bounds read in WebGL on 2026-09-15
[$1500.0] [562174487] High CVE-2026-102324 Use after free in PictureInPicture on 2026-09-15
[$TBD] [562042411] High CVE-2026-102319 Uninitialized resource in GPU on 2026-09-15
[$TBD] [562004351] High CVE-2026-102301 Out of bounds write in GPU on 2026-09-15
[$TBD] [561997480] High CVE-2026-102308 Use after free in Views on 2026-09-15
[$TBD] [561994362] High CVE-2026-102325 Uninitialized resource in Skia on 2026-09-15
[$TBD] [560536732] High CVE-2026-102328 Type confusion in V8 on 2026-09-12
[$TBD] [560251736] High CVE-2026-102304 Use after free in Passwords Reported by [Xinyang Ge ] on 2026-09-11
[$TBD] [560238698] High CVE-2026-102316 Use after free in Views Reported by [Xinyang Ge ] on 2026-09-11
[$TBD] [560233248] High CVE-2026-102326 Type confusion in V8 on 2026-09-11
[$2000.0] [560062638] High CVE-2026-102300 Uninitialized resource in WebGPU on 2026-09-11
[$TBD] [559266114] High CVE-2026-102323 Type confusion in V8 on 2026-09-09
[$TBD] [556926296] High CVE-2026-102306 Use after free in Bluetooth on 2026-09-03
[$500.0] [556908674] High CVE-2026-102299 Type confusion in V8 on 2026-09-03
[$TBD] [554038924] Medium CVE-2026-102320 Missing authorization in CORS on 2026-08-28
[$TBD] [514059780] Low CVE-2026-102314 UI misrepresentation in TabStrip on 2026-05-17
[$TBD] [498793976] Low CVE-2026-102330 Incorrect authorization in SiteIsolation on 2026-04-01
[$1000.0] [477726837] Low CVE-2026-102310 Missing authorization in Payments on 2026-01-21
[$TBD] [567088927] High CVE-2026-103631 Buffer overflow in WebRTC on 2026-09-28
[$TBD] [565742180] High CVE-2026-103623 Use after free in MediaStream on 2026-09-24
[$TBD] [565742179] High CVE-2026-103622 Use after free in SVG on 2026-09-24
[$TBD] [559893859] High CVE-2026-103625 Type confusion in V8 on 2026-09-10
[$TBD] [557323166] High CVE-2026-103630 Use after free in FedCM on 2026-09-04
[$TBD] [556268833] High CVE-2026-103621 Integer overflow in Compositing on 2026-09-02
[$TBD] [553147154] Medium CVE-2026-103627 Information leak in SVG on 2026-08-26
[$TBD] [549995090] Critical CVE-2026-103628 Out of bounds write in WebGL on 2026-08-20