Leagues Cup kicks off tomorrow, August 4, on Apple TV


We are pleased to announce the fourth release candidate preview release of Jellyfin 12.0!
This is a preview release, intended for those interested in testing 12.0 before it's final public release. We welcome testers to help find as many bugs as we can before the final release.
As always, please ensure you stop your Jellyfin server and take a full backup before upgrading!
Starting with this release, we are dropping the preceding 10. from our versioning. Thus, 10.11.x -> [10.]12.x = 12.x. The reason is simple: at this point in the project, we don't envision a hard break in the API like we planned way back in the early days, and this version scheme was causing a lot of confusion amongst users about what a "major" release was. For more information, please see the RC1 release notes.
The main goal of this release has been performance. 10.11.0 dropped a major backend rewrite, and while it was broadly functional, it had a lot of rough edges. This release seeks to polish out most of those rough edges and bring better performance to all users.
There are many other small fixes, improvements, changes, and translations. See our draft release notes here or below for the full list of pull requests. You can also view the Server side changelog here.
Note: You must be on Jellyfin 10.10.7+ or 10.11.x (ideally, 10.11.11) before upgrading! If you are not, the upgrade will fail. Ensure you upgrade to one of these versions first!
Note: The initial load of Jellyfin 12.x will run a few migrations and will take several minutes. Please be patient and do not interrupt the process. You can leverage the (newly improved!) startup UI on your local network to see specific progress, or off-network to see general progress, by visiting the server URL in your web browser during startup.
Note: If you install the RC, you should disable all external plugins and reinstall using the unstable plugin repository, or plugins may fail to load and cause unintended side effects.
This preview release is distributed in all our traditional forms, though not automatically via our Apt repository or latest tag.
12.0-rc4 or preview tags.v12.0-rc3)Full Changelog: v12.0-rc3...v12.0-rc4
We are pleased to announce the fourth release candidate preview release of Jellyfin 12.0!
This is a preview release, intended for those interested in testing 12.0 before its final public release. We welcome testers to help find as many bugs as we can before the final release.
As always, please ensure you stop your Jellyfin server and take a full backup before upgrading!
Starting with this release, we are dropping the preceding 10. from our versioning. Thus, 10.11.x -> [10.]12.x = 12.x. The reason is simple: at this point in the project, we don't envision a hard break in the API like we planned way back in the early days, and this version scheme was causing a lot of confusion amongst users about what a "major" release was. For more information, please see the RC1 release notes.
The main goal of this release has been performance. 10.11.0 dropped a major backend rewrite, and while it was broadly functional, it had a lot of rough edges. This release seeks to polish out most of those rough edges and bring better performance to all users.
There are many other small fixes, improvements, changes, and translations. See our draft release notes here or below for the full list of pull requests. You can also view the Web side changelog here.
Note: You must be on Jellyfin 10.10.7+ or 10.11.x (ideally, 10.11.11) before upgrading! If you are not, the upgrade will fail. Ensure you upgrade to one of these versions first!
Note: The initial load of Jellyfin 12.x will run a few migrations and will take several minutes. Please be patient and do not interrupt the process. You can leverage the (newly improved!) startup UI on your local network to see specific progress, or off-network to see general progress, by visiting the server URL in your web browser during startup.
Note: If you install the RC, you should disable all external plugins and reinstall using the unstable plugin repository, or plugins may fail to load and cause unintended side effects.
This preview release is distributed in all our traditional forms, though not automatically via our Apt repository or latest tag.
12.0-rc4 or preview tags.v12.0-rc3)Full Changelog: v12.0-rc3...v12.0-rc4
Important
If you are using Part-DB it would be helpful if you fill out this short survey on your usage of Part-DB (Google Forms): https://forms.gle/Q15twx3YYq3qCNfe8
Full Changelog: v2.14.0...v2.14.1
If you are upgrading from v0.16.x, replace the binary (or run docker pull). If you are upgrading from v0.15.x and below, please read the upgrading documentation for more information on how to upgrade from previous versions.
orcpt during the DATA stage.accessKey can now be read from an environment variable or file.GET instead of creating a new task which times out on busy servers.LF line endings, producing a single 4247 octet line that strict SMTP relays reject with line too long.Identity-Alignment: none when a mechanism authenticated successfully but against an identity that is not aligned with the From domain.BDAT chunks sent without a valid MAIL FROM are answered with 552 5.3.4 Message too big for system instead of 503 5.5.1.maxMessageSize of 0 rejects every message with 552 5.3.4 Message too big for system instead of disabling the size limit.[::]), including all defaults, refuse IPv4 connections such as 127.0.0.1, since IPV6_V6ONLY is enabled by default on Windows.
We are excited to continue expanding the world of American Truck Simulator as we head further into the Northern Plains. Our map teams are currently working on bringing another unique state to life, filled with sweeping prairies, vibrant communities, and industries that keep America moving:
Welcome to the Peace Garden State! Bordering Canada to the north, North Dakota is a land of sweeping prairies, fertile farmland, winding rivers, and skies that seem to stretch forever. Whether you're rolling into the capital city of Bismarck, navigating the busy streets of Fargo, or passing through communities such as Pembina and the Devil's Lake region, every stop offers a different glimpse into the character of this northern state.
North Dakota's road network is just as memorable as its destinations. Alongside major highways, you'll travel scenic routes like ND-57 and cruise along parts of the famous Enchanted Highway, where towering metal sculptures line the roadside, creating one of the state's most unique driving experiences. Nature lovers will also enjoy the expansive National Grasslands, whose open prairies perfectly capture the beauty of the Northern Plains.
Of course, no trucking adventure would be complete without plenty of cargo to haul. Agriculture remains the backbone of North Dakota, with vast fields producing crops that supply industries across the country. You'll also service facilities such as the sugar processing plant in Wahpeton and support the state's booming oil industry, ensuring there's always another job waiting just down the road.
As you explore, don't forget to keep an eye out for some of North Dakota's most distinctive landmarks. You may spot the state's highest TV tower rising above the prairie or encounter Wahpper, the World's Largest Catfish in Wahpeton. From famous landmarks to quiet country roads, North Dakota is full of memorable moments waiting to be discovered.
We can't wait to share more locations and information about North Dakota in later blogs! If you're excited to explore the Peace Garden State, be sure to add the North Dakota DLC to your Steam wishlist!
Remember to follow us on X/Twitter, Facebook, Instagram, TikTok, Bluesky, and YouTube for all the latest news about this upcoming American Truck Simulator map expansion, or sign up for our newsletter so you never miss an update. Until next time, we wish you happy travels!
Release created in https://github.com/OpenRCT2/OpenRCT2/actions/runs/30744228503
SHA256 checksums:
e86b79590e197a4f4a4a5767b86378fa9337889f3320f1f442c4674ad4711c88 ./OpenRCT2-v0.5.4-windows-portable-win32.zip
54fadd030336ea03f2de391822faef396325ceefb76d976b97a30f6064dfd977 ./OpenRCT2-v0.5.4-sha256sums.txt
aec44e248dc88e50ed6c9897226053631f5b94bf99f45ccb85bae56d52e01688 ./OpenRCT2-v0.5.4-linux-x86_64.AppImage
19798ebac741069ef91a8e48dc7bbe56e6edbfa1daa4e99ef4045330b0973d61 ./OpenRCT2-v0.5.4-windows-portable-x64.zip
f1985ec320fb511056f9549e844ab0072a92cb224536ddc2ca8c5f246a7c2498 ./OpenRCT2-v0.5.4-windows-installer-win32.exe
01f27dfa7d4cb534c9710c2fb993df7f202493d1dd178622459e3882623a4e1e ./OpenRCT2-v0.5.4-windows-symbols-arm64.zip
45ae7057fbd3701c1392430f0cdb619e5ccf153b9c4799bba6a38f0dff8167b2 ./OpenRCT2-v0.5.4-Linux-trixie-x86_64.tar.gz
cb8591e2e252444c2fef60b0a9553d3c5cda0d38d51142fdeb7f3e5dc52393ac ./OpenRCT2-v0.5.4-windows-symbols-win32.zip
9b50ea372a41e1335600e8f4e8b81a6b035d461a59df20d32f3ac989172612f5 ./OpenRCT2-v0.5.4-Linux-bookworm-x86_64.tar.gz
67eb59e88df0ae3a6cc869100a9f3a8aa132df12dc3cf64a0f1999a68f0b0037 ./OpenRCT2-v0.5.4-Linux-resolute-x86_64.tar.gz
d063d00ba809cbae3f3ba9725b6259b4702d84735358d9a599af891bde5726eb ./OpenRCT2-v0.5.4-android.apk
9c32dde9a23aa07e5249e20a02dd87efdd0e7806f390b70d5d992df1e52d069e ./OpenRCT2-v0.5.4-Linux-noble-x86_64.tar.gz
7a518d35a76d39c783bb20de4f6fbdb01bd989fe08b3bda616cbfc477a8366b1 ./OpenRCT2-v0.5.4-windows-symbols-x64.zip
c9381c0cf753a1f60a5012a280aad28403a6e8cc5536bfd200b30a03d6512cac ./OpenRCT2-v0.5.4-windows-portable-arm64.zip
ac6cd0bf3df54db546a6b5aa54f1038c538d05ddb82cfb55b70acd571dbc14d1 ./OpenRCT2-v0.5.4-windows-installer-arm64.exe
32e635854e028b365a28ebef879fa8fa2bdf2e5bf238f094f89da813b6b02620 ./OpenRCT2-v0.5.4-windows-installer-x64.exe
f52fec44e34d3d0094b94f1ff1d5d90f220f9a8ce32c99b2723fb513d2fe1e14 ./OpenRCT2-v0.5.4-macos-universal.zip
Ready to hit the open road behind the wheel of a true American legend? Today, we're excited to share a new gameplay preview from our upcoming Road Trip module for American Truck Simulator, featuring the iconic 1967 Ford Mustang Fastback, which is a part of the Ford Car Pack DLC.
Something big just happened. As the Open Home Foundation’s Android developer for Home Assistant, I was invited by the European Commission to consult on Android interoperability. On July 16, 2026, the Commission adopted a decision requiring Alphabet to open up eleven Android features — including always-on wake word detection, ambient sensor access, and screen automation — to all assistants, on equal terms.

Today, we're taking a closer look at Sioux Falls, the largest city in South Dakota and one of the highlights of our upcoming South Dakota DLC for American Truck Simulator. Whether you're delivering cargo or simply enjoying the drive, this city offers plenty of memorable sights and destinations to explore. Let's take a closer look!
The Open Home Foundation fights for privacy, choice, and sustainability. These principles are at the heart of everything we do, including how we handle website analytics. Our position is clear: we reject tools that track individuals across the web to monetize their data. Instead, we want aggregated, anonymized analytics that show how our websites are performing overall — without identifying who our visitors are, or compromising their privacy.
Windows Installer
Windows No Installer (zip)
macOS - Universal
Linux - deb, AppImage or rpm
Windows intel x32 releases are marked -ia32-
ChangeLog:
The Stable channel has been updated to 151.0.7922.71/.72 for Windows and Mac and 151.0.7922.71 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log
Security Fixes and Rewards
Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.
This update includes 370 security fixes. Please see the Chrome Security Page for more information.
[N/A][514442821] Critical CVE-2026-17650: Use after free in Compositing. Reported by Google on 2026-05-18
[N/A][517307966] Critical CVE-2026-17651: Insufficient validation of untrusted input in Dawn. Reported by Google on 2026-05-28
[N/A][519262990] Critical CVE-2026-17652: Use after free in Views. Reported by Google on 2026-06-02
[N/A][520514458] Critical CVE-2026-17653: Use after free in Skia. Reported by Google on 2026-06-05
[N/A][522314940] Critical CVE-2026-17654: Race in Updater. Reported by Google on 2026-06-10
[N/A][522556145] Critical CVE-2026-17655: Insufficient validation of untrusted input in ANGLE. Reported by Google on 2026-06-11
[N/A][523725277] Critical CVE-2026-17656: Use after free in Ozone. Reported by Google on 2026-06-14
[$36000][502293787] High CVE-2026-17657: Use after free in Navigation. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-04-14
[$1000][523030583] High CVE-2026-17658: Use after free in V8. Reported by Duc Nguyen of Calif.io in collaboration with OpenAI Codex Security on 2026-06-12
[N/A][495463654] High CVE-2026-17659: Inappropriate implementation in SiteIsolation. Reported by Google on 2026-03-23
[N/A][497428001] High CVE-2026-17660: Insufficient validation of untrusted input in Network. Reported by Google on 2026-03-29
[N/A][497451790] High CVE-2026-17661: Use after free in Loader. Reported by Google on 2026-03-29
[N/A][497491557] High CVE-2026-17662: Insufficient policy enforcement in Prefetch. Reported by Google on 2026-03-29
[N/A][500225310] High CVE-2026-17663: Insufficient validation of untrusted input in GPU. Reported by Google on 2026-04-07
[N/A][500554346] High CVE-2026-17664: Insufficient validation of untrusted input in Loader. Reported by Google on 2026-04-08
[N/A][511277457] High CVE-2026-17665: Use after free in V8. Reported by Google on 2026-05-08
[N/A][511761758] High CVE-2026-17666: Cryptographic Flaw in Enterprise. Reported by Google on 2026-05-10
[N/A][513043537] High CVE-2026-17667: Uninitialized Use in ANGLE. Reported by Google on 2026-05-14
[N/A][513134019] High CVE-2026-17668: Uninitialized Use in ANGLE. Reported by Google on 2026-05-14
[N/A][513142464] High CVE-2026-17669: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-14
[N/A][513228974] High CVE-2026-17670: Use after free in Views. Reported by Google on 2026-05-14
[N/A][513257423] High CVE-2026-17671: Insufficient validation of untrusted input in ANGLE. Reported by Google on 2026-05-14
[N/A][513375270] High CVE-2026-17672: Insufficient validation of untrusted input in Chromecast. Reported by Google on 2026-05-15
[N/A][513735177] High CVE-2026-17673: Integer overflow in QUIC. Reported by Google on 2026-05-16
[N/A][513791232] High CVE-2026-17674: Inappropriate implementation in HTML. Reported by Google on 2026-05-16
[N/A][513920258] High CVE-2026-17675: Out of bounds write in ANGLE. Reported by Google on 2026-05-17
[N/A][513920298] High CVE-2026-17676: Inappropriate implementation in ANGLE. Reported by Google on 2026-05-17
[N/A][513921488] High CVE-2026-17677: Inappropriate implementation in ANGLE. Reported by Google on 2026-05-17
[N/A][515452019] High CVE-2026-17678: Out of bounds read in ANGLE. Reported by Google on 2026-05-21
[N/A][516430649] High CVE-2026-17679: Insufficient validation of untrusted input in Print Preview. Reported by Google on 2026-05-25
[N/A][516486611] High CVE-2026-17680: Heap buffer overflow in Color. Reported by Google on 2026-05-25
[N/A][516813184] High CVE-2026-17681: Insufficient validation of untrusted input in Web Authentication. Reported by Google on 2026-05-26
[N/A][516837126] High CVE-2026-17682: Integer overflow in ANGLE. Reported by Google on 2026-05-26
[N/A][516887576] High CVE-2026-17683: Inappropriate implementation in ANGLE. Reported by Google on 2026-05-26
[N/A][516894682] High CVE-2026-17684: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google on 2026-05-26
[N/A][516910278] High CVE-2026-17685: Use after free in Autofill. Reported by Google on 2026-05-27
[N/A][516917065] High CVE-2026-17686: Insufficient validation of untrusted input in Passwords. Reported by Google on 2026-05-27
[N/A][516985726] High CVE-2026-17687: Type Confusion in ANGLE. Reported by Google on 2026-05-27
[N/A][517016413] High CVE-2026-17688: Use after free in Input. Reported by Google on 2026-05-27
[N/A][517045160] High CVE-2026-17689: Uninitialized Use in ANGLE. Reported by Google on 2026-05-27
[N/A][517129282] High CVE-2026-17690: Insufficient validation of untrusted input in PDF. Reported by Google on 2026-05-27
[N/A][517321292] High CVE-2026-17691: Out of bounds write in ANGLE. Reported by Google on 2026-05-28
[N/A][517350808] High CVE-2026-17692: Use after free in DataTransfer. Reported by Google on 2026-05-28
[N/A][517448723] High CVE-2026-17693: Inappropriate implementation in FileSystem. Reported by Google on 2026-05-28
[N/A][517511796] High CVE-2026-17694: Use after free in DOM. Reported by Google on 2026-05-28
[N/A][517543052] High CVE-2026-17695: Inappropriate implementation in ANGLE. Reported by Google on 2026-05-28
[N/A][517550034] High CVE-2026-17696: Side-channel information leakage in Media. Reported by Google on 2026-05-28
[N/A][517575864] High CVE-2026-17697: Type Confusion in ANGLE. Reported by Google on 2026-05-28
[N/A][517670731] High CVE-2026-17698: Insufficient validation of untrusted input in UI. Reported by Google on 2026-05-29
[N/A][517785292] High CVE-2026-17699: Use after free in Views. Reported by Google on 2026-05-29
[N/A][517789833] High CVE-2026-17700: Insufficient validation of untrusted input in Actor. Reported by Google on 2026-05-29
[N/A][517972648] High CVE-2026-17701: Out of bounds read in ANGLE. Reported by Google on 2026-05-29
[N/A][517973093] High CVE-2026-17702: Inappropriate implementation in Skia. Reported by Google on 2026-05-29
[N/A][518051499] High CVE-2026-17703: Policy bypass in Chrome for iOS. Reported by Google on 2026-05-30
[N/A][519259107] High CVE-2026-17704: Use after free in ANGLE. Reported by Google on 2026-06-02
[TBD][519665978] High CVE-2026-17705: Integer overflow in libxml. Reported by ebassi of Igalia on 2026-06-04
[N/A][519693032] High CVE-2026-17706: Insufficient validation of untrusted input in Media. Reported by Google on 2026-06-03
[N/A][519701233] High CVE-2026-17707: Uninitialized Use in Media. Reported by Google on 2026-06-03
[N/A][519738647] High CVE-2026-17708: Use after free in Audio. Reported by Google on 2026-06-04
[N/A][519981494] High CVE-2026-17709: Race in Downloads. Reported by Google on 2026-06-04
[N/A][519991712] High CVE-2026-17710: Inappropriate implementation in MHTML. Reported by Google on 2026-06-04
[N/A][519996040] High CVE-2026-17711: Race in Downloads. Reported by Google on 2026-06-04
[N/A][520535595] High CVE-2026-17712: Race in Skia. Reported by Google on 2026-06-05
[N/A][520572766] High CVE-2026-17713: Insufficient validation of untrusted input in Accessibility. Reported by Google on 2026-06-06
[N/A][521293438] High CVE-2026-17714: Uninitialized Use in ANGLE. Reported by Google on 2026-06-08
[N/A][521491778] High CVE-2026-17715: Inappropriate implementation in Passwords. Reported by Google on 2026-06-08
[N/A][521866061] High CVE-2026-17716: Use after free in Updater. Reported by Google on 2026-06-09
[N/A][522063116] High CVE-2026-17717: Integer overflow in ANGLE. Reported by Google on 2026-06-10
[N/A][522079372] High CVE-2026-17718: Use after free in ANGLE. Reported by Google on 2026-06-10
[N/A][522304853] High CVE-2026-17719: Use after free in Input. Reported by Google on 2026-06-10
[N/A][522545249] High CVE-2026-17720: Insufficient policy enforcement in Passwords. Reported by Google on 2026-06-11
[N/A][523495723] High CVE-2026-17721: Out of bounds write in ANGLE. Reported by Google on 2026-06-13
[N/A][523592755] High CVE-2026-17722: Object lifecycle issue in WebView. Reported by Google on 2026-06-13
[N/A][523718303] High CVE-2026-17723: Use after free in Media. Reported by Google on 2026-06-14
[N/A][523720739] High CVE-2026-17724: Race in Chrome for iOS. Reported by Google on 2026-06-14
[TBD][528501127] High CVE-2026-17725: Type Confusion in V8. Reported by nh.dev2022 on 2026-06-27
[N/A][529867799] High CVE-2026-17726: Integer overflow in WebGL. Reported by Google on 2026-06-30
[N/A][529932631] High CVE-2026-17727: Out of bounds write in WebGL. Reported by Google on 2026-07-01
[$10000][461167648] Medium CVE-2026-17728: Inappropriate implementation in Extensions. Reported by Suhas S P on 2025-11-16
[$5000][503801946] Medium CVE-2026-17758: Heap buffer overflow in Dawn. Reported by Hyeonjun Ahn (@_deayzl) on 2026-04-18
[$2000][476646486] Medium CVE-2026-17732: Inappropriate implementation in SVG. Reported by Lyra Rebane (rebane2001) on 2026-01-17
[$500][520656237] Medium CVE-2026-17729: Use after free in V8. Reported by wang1r && lhfff on 2026-06-07
[N/A][40057032] Medium CVE-2026-17730: Side-channel information leakage in Autofill. Reported by Google on 2021-08-26
[TBD][463551850] Medium CVE-2026-17731: Inappropriate implementation in Autofill. Reported by Manojkumar Jaganathan Aka TheWhiteEvil with HackerBro Technologies on 2025-11-25
[N/A][495793059] Medium CVE-2026-17733: Inappropriate implementation in QUIC. Reported by Google on 2026-03-24
[N/A][496304083] Medium CVE-2026-17734: Inappropriate implementation in Autofill. Reported by Google on 2026-03-25
[N/A][496569497] Medium CVE-2026-17735: Insufficient validation of untrusted input in BFCache. Reported by Google on 2026-03-26
[N/A][496715442] Medium CVE-2026-17736: Insufficient validation of untrusted input in WebView. Reported by Google on 2026-03-27
[N/A][498000415] Medium CVE-2026-17737: Use after free in Bluetooth. Reported by Google on 2026-03-31
[N/A][498079379] Medium CVE-2026-17738: Insufficient validation of untrusted input in Payments. Reported by Google on 2026-03-31
[N/A][498353463] Medium CVE-2026-17739: Insufficient policy enforcement in Extensions. Reported by Google on 2026-03-31
[N/A][498827800] Medium CVE-2026-17740: Uninitialized Use in ANGLE. Reported by Google on 2026-04-02
[N/A][498877660] Medium CVE-2026-17741: Insufficient validation of untrusted input in WebView. Reported by Google on 2026-04-02
[N/A][499003233] Medium CVE-2026-17742: Insufficient policy enforcement in Payments. Reported by Google on 2026-04-02
[N/A][499204022] Medium CVE-2026-17743: Insufficient policy enforcement in ControlledFrame. Reported by Google on 2026-04-03
[N/A][500137309] Medium CVE-2026-17744: Inappropriate implementation in File Input. Reported by Google on 2026-04-07
[N/A][500172224] Medium CVE-2026-17745: Out of bounds read in Skia. Reported by Google on 2026-04-07
[N/A][500390256] Medium CVE-2026-17746: Use after free in GPU. Reported by Google on 2026-04-07
[N/A][500472958] Medium CVE-2026-17747: Insufficient validation of untrusted input in Payments. Reported by Google on 2026-04-07
[N/A][500494349] Medium CVE-2026-17748: Inappropriate implementation in Extensions. Reported by Google on 2026-04-08
[N/A][500526602] Medium CVE-2026-17749: Insufficient validation of untrusted input in Extensions. Reported by Google on 2026-04-08
[N/A][500560234] Medium CVE-2026-17750: Use after free in ANGLE. Reported by Google on 2026-04-08
[N/A][501591293] Medium CVE-2026-17751: Inappropriate implementation in AdFilter. Reported by Google on 2026-04-11
[N/A][501619207] Medium CVE-2026-17752: Use after free in Views. Reported by Google on 2026-04-11
[N/A][501628355] Medium CVE-2026-17753: Inappropriate implementation in Autofill. Reported by Google on 2026-04-11
[N/A][501675996] Medium CVE-2026-17754: Inappropriate implementation in Blink. Reported by Google on 2026-04-11
[N/A][501854535] Medium CVE-2026-17755: Incorrect security UI in Extensions. Reported by Google on 2026-04-12
[N/A][501980797] Medium CVE-2026-17756: Insufficient policy enforcement in Presentation. Reported by Google on 2026-04-13
[N/A][502351526] Medium CVE-2026-17757: Uninitialized Use in Skia. Reported by Google on 2026-04-14
[N/A][504650654] Medium CVE-2026-17759: Uninitialized Use in Codecs. Reported by Google on 2026-04-20
[N/A][506473189] Medium CVE-2026-17760: Side-channel information leakage in NoStatePrefetch. Reported by Google on 2026-04-25
[N/A][508249524] Medium CVE-2026-17761: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google on 2026-04-30
[N/A][508251844] Medium CVE-2026-17762: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-04-30
[N/A][511738693] Medium CVE-2026-17763: Inappropriate implementation in GPU. Reported by Google on 2026-05-10
[N/A][511754400] Medium CVE-2026-17764: Inappropriate implementation in FedCM. Reported by Google on 2026-05-10
[N/A][511765328] Medium CVE-2026-17765: Inappropriate implementation in WebProtect. Reported by Google on 2026-05-10
[N/A][511799537] Medium CVE-2026-17766: Insufficient validation of untrusted input in Clipboard. Reported by Google on 2026-05-10
[N/A][511822402] Medium CVE-2026-17767: Insufficient validation of untrusted input in WebView. Reported by Google on 2026-05-10
[N/A][512999037] Medium CVE-2026-17768: Insufficient validation of untrusted input in WebSockets. Reported by Google on 2026-05-13
[N/A][513022076] Medium CVE-2026-17769: Insufficient validation of untrusted input in Cast. Reported by Google on 2026-05-14
[N/A][513103345] Medium CVE-2026-17770: Out of bounds read in Media. Reported by Google on 2026-05-14
[N/A][513160525] Medium CVE-2026-17771: Uninitialized Use in Skia. Reported by Google on 2026-05-14
[N/A][513197846] Medium CVE-2026-17772: Out of bounds read in WebGL. Reported by Google on 2026-05-14
[N/A][513232523] Medium CVE-2026-17773: Insufficient validation of untrusted input in Cast. Reported by Google on 2026-05-14
[N/A][513323066] Medium CVE-2026-17774: Insufficient validation of untrusted input in Variations. Reported by Google on 2026-05-14
[N/A][513363822] Medium CVE-2026-17775: Inappropriate implementation in PresentationAPI. Reported by Google on 2026-05-15
[N/A][513404032] Medium CVE-2026-17776: Policy bypass in Receiver. Reported by Google on 2026-05-15
[N/A][513462236] Medium CVE-2026-17777: Inappropriate implementation in Autofill. Reported by Google on 2026-05-15
[N/A][513467993] Medium CVE-2026-17778: Use after free in Extensions. Reported by Google on 2026-05-15
[N/A][513478933] Medium CVE-2026-17779: Inappropriate implementation in Site Isolation. Reported by Google on 2026-05-15
[N/A][513485951] Medium CVE-2026-17780: Inappropriate implementation in Isolated Web Apps. Reported by Google on 2026-05-15
[N/A][513502990] Medium CVE-2026-17781: Inappropriate implementation in Extensions. Reported by Google on 2026-05-15
[N/A][513507830] Medium CVE-2026-17782: Incorrect security UI in Chrome for iOS. Reported by Google on 2026-05-15
[N/A][513532735] Medium CVE-2026-17783: Inappropriate implementation in Loader. Reported by Google on 2026-05-15
[N/A][513694032] Medium CVE-2026-17784: Use after free in Audio. Reported by Google on 2026-05-16
[N/A][513769898] Medium CVE-2026-17785: Uninitialized Use in ANGLE. Reported by Google on 2026-05-16
[N/A][513770449] Medium CVE-2026-17786: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-05-16
[N/A][513783632] Medium CVE-2026-17787: Inappropriate implementation in DevTools. Reported by Google on 2026-05-16
[N/A][513824957] Medium CVE-2026-17788: Inappropriate implementation in Blink. Reported by Google on 2026-05-16
[N/A][513855922] Medium CVE-2026-17789: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google on 2026-05-16
[N/A][513919931] Medium CVE-2026-17790: Uninitialized Use in ANGLE. Reported by Google on 2026-05-17
[N/A][514006959] Medium CVE-2026-17791: Insufficient validation of untrusted input in Payments. Reported by Google on 2026-05-17
[N/A][514019823] Medium CVE-2026-17792: Inappropriate implementation in Credential Management. Reported by Google on 2026-05-17
[N/A][514063859] Medium CVE-2026-17793: Inappropriate implementation in Messages. Reported by Google on 2026-05-17
[N/A][514067070] Medium CVE-2026-17794: Insufficient validation of untrusted input in Mobile. Reported by Google on 2026-05-17
[TBD][514242889] Medium CVE-2026-17795: Insufficient validation of untrusted input in GetUserMedia. Reported by Mihnea Nicolau on 2026-05-18
[N/A][514427844] Medium CVE-2026-17796: Side-channel information leakage in WebXR. Reported by Google on 2026-05-18
[N/A][514441966] Medium CVE-2026-17797: Inappropriate implementation in CSS. Reported by Google on 2026-05-18
[N/A][514460133] Medium CVE-2026-17798: Inappropriate implementation in Cast. Reported by Google on 2026-05-19
[N/A][514461031] Medium CVE-2026-17799: Insufficient validation of untrusted input in Safe Browsing. Reported by Google on 2026-05-19
[N/A][514480948] Medium CVE-2026-17800: Side-channel information leakage in MediaRecording. Reported by Google on 2026-05-19
[N/A][514482938] Medium CVE-2026-17801: Out of bounds memory access in ANGLE. Reported by Google on 2026-05-19
[N/A][514512198] Medium CVE-2026-17802: Side-channel information leakage in GPU. Reported by Google on 2026-05-19
[N/A][515438919] Medium CVE-2026-17803: Insufficient validation of untrusted input in Save to Drive. Reported by Google on 2026-05-21
[N/A][515448947] Medium CVE-2026-17804: Use after free in Media. Reported by Google on 2026-05-21
[N/A][516420806] Medium CVE-2026-17805: Insufficient policy enforcement in Glic. Reported by Google on 2026-05-25
[N/A][516433058] Medium CVE-2026-17806: Insufficient validation of untrusted input in Extensions. Reported by Google on 2026-05-25
[N/A][516763884] Medium CVE-2026-17807: Use after free in V8. Reported by Google on 2026-05-26
[N/A][516778390] Medium CVE-2026-17808: Uninitialized Use in WebGL. Reported by Google on 2026-05-26
[N/A][516813317] Medium CVE-2026-17809: Insufficient validation of untrusted input in Extensions. Reported by Google on 2026-05-26
[N/A][516882109] Medium CVE-2026-17810: Uninitialized Use in Dawn. Reported by Google on 2026-05-26
[N/A][516954622] Medium CVE-2026-17811: Use after free in ANGLE. Reported by Google on 2026-05-27
[N/A][517101596] Medium CVE-2026-17812: Inappropriate implementation in DigitalCredentials. Reported by Google on 2026-05-27
[N/A][517184957] Medium CVE-2026-17813: Insufficient policy enforcement in Chrome for iOS. Reported by Google on 2026-05-27
[N/A][517312048] Medium CVE-2026-17814: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google on 2026-05-28
[N/A][517427352] Medium CVE-2026-17815: Insufficient policy enforcement in GuestView. Reported by Google on 2026-05-28
[N/A][517429672] Medium CVE-2026-17816: Inappropriate implementation in Speech. Reported by Google on 2026-05-28
[N/A][517461759] Medium CVE-2026-17817: Inappropriate implementation in ReportingAndNEL. Reported by Google on 2026-05-28
[N/A][517466133] Medium CVE-2026-17818: Inappropriate implementation in Network. Reported by Google on 2026-05-28
[N/A][517487028] Medium CVE-2026-17819: Inappropriate implementation in WebAppInstalls. Reported by Google on 2026-05-28
[N/A][517493101] Medium CVE-2026-17820: Insufficient policy enforcement in Autofill. Reported by Google on 2026-05-28
[N/A][517597914] Medium CVE-2026-17821: Insufficient policy enforcement in Extensions. Reported by Google on 2026-05-28
[N/A][517621178] Medium CVE-2026-17822: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-28
[N/A][517628043] Medium CVE-2026-17823: Insufficient policy enforcement in WebXR. Reported by Google on 2026-05-28
[N/A][517655543] Medium CVE-2026-17824: Insufficient policy enforcement in ServiceWorker. Reported by Google on 2026-05-28
[N/A][517675979] Medium CVE-2026-17825: Insufficient policy enforcement in Passwords. Reported by Google on 2026-05-29
[N/A][517690521] Medium CVE-2026-17826: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-29
[N/A][517693726] Medium CVE-2026-17827: Inappropriate implementation in CSS. Reported by Google on 2026-05-29
[N/A][517702279] Medium CVE-2026-17828: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-29
[N/A][517705103] Medium CVE-2026-17829: Insufficient policy enforcement in Passwords. Reported by Google on 2026-05-29
[N/A][517710397] Medium CVE-2026-17830: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-29
[N/A][517714728] Medium CVE-2026-17831: Insufficient validation of untrusted input in Passwords. Reported by Google on 2026-05-29
[N/A][517723319] Medium CVE-2026-17832: Use after free in ANGLE. Reported by Google on 2026-05-29
[N/A][517779123] Medium CVE-2026-17833: Inappropriate implementation in Passwords. Reported by Google on 2026-05-29
[N/A][517793801] Medium CVE-2026-17834: Inappropriate implementation in Passwords. Reported by Google on 2026-05-29
[N/A][517801739] Medium CVE-2026-17835: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-29
[TBD][517972812] Medium CVE-2026-17836: Use after free in V8. Reported by yupyon.itome on 2026-05-30
[N/A][517978932] Medium CVE-2026-17837: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-05-29
[N/A][518075952] Medium CVE-2026-17838: Incorrect security UI in Chrome for iOS. Reported by Google on 2026-05-30
[N/A][518080978] Medium CVE-2026-17839: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-30
[N/A][518082162] Medium CVE-2026-17840: Incorrect security UI in Passwords. Reported by Google on 2026-05-30
[N/A][518088219] Medium CVE-2026-17841: Race in Chrome for iOS. Reported by Google on 2026-05-30
[N/A][518089997] Medium CVE-2026-17842: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-30
[N/A][518103887] Medium CVE-2026-17843: Inappropriate implementation in CSS. Reported by Google on 2026-05-30
[N/A][518111542] Medium CVE-2026-17844: Insufficient validation of untrusted input in Cast. Reported by Google on 2026-05-30
[N/A][518112775] Medium CVE-2026-17845: Inappropriate implementation in CSS. Reported by Google on 2026-05-30
[N/A][518121320] Medium CVE-2026-17846: Inappropriate implementation in Media. Reported by Google on 2026-05-30
[N/A][518243653] Medium CVE-2026-17847: Insufficient validation of untrusted input in ANGLE. Reported by Google on 2026-05-30
[TBD][518284253] Medium CVE-2026-17848: Insufficient validation of untrusted input in Codecs. Reported by Ameen Basha M K on 2026-05-31
[N/A][518812672] Medium CVE-2026-17849: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-06-01
[TBD][519078527] Medium CVE-2026-17850: Inappropriate implementation in Permissions. Reported by Tech Division (@taiphung) - Mobifone Digital Payment on 2026-06-02
[N/A][519243927] Medium CVE-2026-17851: Side-channel information leakage in Autofill. Reported by Google on 2026-06-02
[N/A][519348818] Medium CVE-2026-17852: Inappropriate implementation in Media Router. Reported by Google on 2026-06-03
[TBD][519472272] Medium CVE-2026-17853: Inappropriate implementation in DevTools. Reported by Orange Tsai (@orange_8361) of DEVCORE Research Team on 2026-06-03
[N/A][519500882] Medium CVE-2026-17854: Insufficient policy enforcement in WebMCP. Reported by Google on 2026-06-03
[N/A][519982572] Medium CVE-2026-17855: Race in DevTools. Reported by Google on 2026-06-04
[N/A][519991751] Medium CVE-2026-17856: Inappropriate implementation in Network. Reported by Google on 2026-06-04
[N/A][520186620] Medium CVE-2026-17857: Inappropriate implementation in Network. Reported by Google on 2026-06-05
[N/A][520191468] Medium CVE-2026-17858: Uninitialized Use in WebNN. Reported by Google on 2026-06-05
[N/A][520196753] Medium CVE-2026-17859: Side-channel information leakage in Favicons. Reported by Google on 2026-06-05
[N/A][520407381] Medium CVE-2026-17860: Insufficient validation of untrusted input in Mobile. Reported by Google on 2026-06-05
[N/A][520417861] Medium CVE-2026-17861: Insufficient validation of untrusted input in Updater. Reported by Google on 2026-06-05
[N/A][520426287] Medium CVE-2026-17862: Use after free in Tracing. Reported by Google on 2026-06-05
[N/A][520468718] Medium CVE-2026-17863: Inappropriate implementation in Browser. Reported by Google on 2026-06-05
[N/A][520494861] Medium CVE-2026-17864: Inappropriate implementation in Updater. Reported by Google on 2026-06-05
[N/A][520516655] Medium CVE-2026-17865: Inappropriate implementation in Crypto. Reported by Google on 2026-06-05
[N/A][520525732] Medium CVE-2026-17866: Type Confusion in Tab. Reported by Google on 2026-06-05
[N/A][520527496] Medium CVE-2026-17867: Insufficient validation of untrusted input in Dawn. Reported by Google on 2026-06-05
[TBD][520743499] Medium CVE-2026-17868: Insufficient policy enforcement in USB. Reported by Ariel Simon on 2026-06-06
[N/A][521759269] Medium CVE-2026-17869: Out of bounds read in WebXR. Reported by Google on 2026-06-09
[N/A][521784856] Medium CVE-2026-17870: Insufficient validation of untrusted input in Cast. Reported by Google on 2026-06-09
[N/A][521938924] Medium CVE-2026-17871: Inappropriate implementation in Passwords. Reported by Google on 2026-06-09
[N/A][521963740] Medium CVE-2026-17872: Cryptographic Flaw in WebAppInstalls. Reported by Google on 2026-06-09
[N/A][522074033] Medium CVE-2026-17873: Insufficient policy enforcement in Chrome for iOS. Reported by Google on 2026-06-10
[N/A][522074154] Medium CVE-2026-17874: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-06-10
[N/A][522299155] Medium CVE-2026-17875: Use after free in PDFium. Reported by Google on 2026-06-10
[N/A][522425471] Medium CVE-2026-17876: Inappropriate implementation in Payments. Reported by Google on 2026-06-10
[N/A][522426086] Medium CVE-2026-17877: Inappropriate implementation in Chromoting. Reported by Google on 2026-06-10
[N/A][522781838] Medium CVE-2026-17878: Inappropriate implementation in CSS. Reported by Google on 2026-06-11
[N/A][522878450] Medium CVE-2026-17879: Inappropriate implementation in Autofill. Reported by Google on 2026-06-11
[N/A][523229759] Medium CVE-2026-17880: Inappropriate implementation in Autofill. Reported by Google on 2026-06-12
[N/A][523477987] Medium CVE-2026-17881: Use after free in WebXR. Reported by Google on 2026-06-13
[N/A][523637452] Medium CVE-2026-17882: Policy bypass in Extensions. Reported by Google on 2026-06-13
[N/A][523639090] Medium CVE-2026-17883: Inappropriate implementation in Headless. Reported by Google on 2026-06-13
[N/A][523692228] Medium CVE-2026-17884: Object lifecycle issue in WebRTC. Reported by Google on 2026-06-13
[N/A][523698038] Medium CVE-2026-17885: Inappropriate implementation in Paint. Reported by Google on 2026-06-13
[N/A][523715964] Medium CVE-2026-17886: Use after free in Enterprise. Reported by Google on 2026-06-14
[N/A][523717010] Medium CVE-2026-17887: Use after free in TabStrip. Reported by Google on 2026-06-14
[N/A][523720529] Medium CVE-2026-17888: Insufficient validation of untrusted input in WebUI. Reported by Google on 2026-06-14
[N/A][523735357] Medium CVE-2026-17889: Uninitialized Use in WebXR. Reported by Google on 2026-06-14
[N/A][524029061] Medium CVE-2026-17890: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-06-15
[N/A][524639223] Medium CVE-2026-17891: Use after free in ANGLE. Reported by Google on 2026-06-16
[N/A][524822998] Medium CVE-2026-17892: Inappropriate implementation in WebXR. Reported by Google on 2026-06-17
[N/A][524824730] Medium CVE-2026-17893: Insufficient validation of untrusted input in Updater. Reported by Google on 2026-06-17
[N/A][524825209] Medium CVE-2026-17894: Use after free in Views. Reported by Google on 2026-06-17
[TBD][524931675] Medium CVE-2026-17895: Inappropriate implementation in DataTransfer. Reported by hongan@calif.io on 2026-06-17
[N/A][525331547] Medium CVE-2026-17896: Use after free in DevTools. Reported by Google on 2026-06-18
[TBD][527665262] Medium CVE-2026-17897: Inappropriate implementation in ORB. Reported by Sharkkcode on 2026-06-25
[$3000][506193577] Low CVE-2026-17898: Use after free in DevTools. Reported by Syn4pse on 2026-04-24
[$1000][375959766] Low CVE-2026-17899: Insufficient policy enforcement in DevTools. Reported by asnine on 2024-10-28
[N/A][496195854] Low CVE-2026-17900: Inappropriate implementation in Enterprise. Reported by Google on 2026-03-25
[N/A][496271098] Low CVE-2026-17901: Inappropriate implementation in Sharing. Reported by Google on 2026-03-25
[N/A][497251066] Low CVE-2026-17902: Inappropriate implementation in Editing. Reported by Google on 2026-03-28
[N/A][497277880] Low CVE-2026-17903: Insufficient policy enforcement in Chromecast. Reported by Google on 2026-03-28
[N/A][497337759] Low CVE-2026-17904: Insufficient policy enforcement in NFC. Reported by Google on 2026-03-29
[N/A][497366217] Low CVE-2026-17905: Inappropriate implementation in SurfaceCapture. Reported by Google on 2026-03-29
[N/A][497654761] Low CVE-2026-17906: Insufficient validation of untrusted input in Bluetooth. Reported by Google on 2026-03-30
[N/A][497837927] Low CVE-2026-17907: Side-channel information leakage in Network. Reported by Google on 2026-03-30
[N/A][499062890] Low CVE-2026-17908: Insufficient validation of untrusted input in Printing. Reported by Google on 2026-04-02
[N/A][501693236] Low CVE-2026-17909: Insufficient validation of untrusted input in Isolated Web Apps. Reported by Google on 2026-04-11
[N/A][501749600] Low CVE-2026-17910: Insufficient policy enforcement in NFC. Reported by Google on 2026-04-11
[N/A][502505715] Low CVE-2026-17911: Insufficient policy enforcement in SVG. Reported by Google on 2026-04-14
[N/A][504202939] Low CVE-2026-17912: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-04-19
[N/A][504209246] Low CVE-2026-17913: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-04-19
[N/A][506377118] Low CVE-2026-17914: Side-channel information leakage in Skia. Reported by Google on 2026-04-25
[N/A][506390325] Low CVE-2026-17915: Inappropriate implementation in WebView. Reported by Google on 2026-04-25
[TBD][510808598] Low CVE-2026-17916: Insufficient policy enforcement in Settings. Reported by Itzik Chimino on 2026-05-07
[N/A][511816897] Low CVE-2026-17917: Policy bypass in Chrome for iOS. Reported by Google on 2026-05-10
[N/A][513127137] Low CVE-2026-17918: Use after free in Sync. Reported by Google on 2026-05-14
[N/A][513291747] Low CVE-2026-17919: Insufficient policy enforcement in Enterprise. Reported by Google on 2026-05-14
[N/A][513413942] Low CVE-2026-17920: Use after free in V8. Reported by Google on 2026-05-15
[N/A][513503197] Low CVE-2026-17921: Insufficient validation of untrusted input in Navigation. Reported by Google on 2026-05-15
[N/A][513611659] Low CVE-2026-17922: Inappropriate implementation in Enterprise. Reported by Google on 2026-05-15
[N/A][513612928] Low CVE-2026-17923: Policy bypass in Enterprise. Reported by Google on 2026-05-15
[N/A][513714124] Low CVE-2026-17924: Use after free in DNS. Reported by Google on 2026-05-16
[N/A][513719671] Low CVE-2026-17925: Inappropriate implementation in Cast. Reported by Google on 2026-05-16
[N/A][513735900] Low CVE-2026-17926: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-05-16
[N/A][513754837] Low CVE-2026-17927: Insufficient policy enforcement in DevTools. Reported by Google on 2026-05-16
[N/A][513762372] Low CVE-2026-17928: Inappropriate implementation in DataTransfer. Reported by Google on 2026-05-16
[N/A][513768645] Low CVE-2026-17929: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-05-16
[N/A][513769158] Low CVE-2026-17930: Insufficient validation of untrusted input in Extensions. Reported by Google on 2026-05-16
[N/A][513781245] Low CVE-2026-17931: Inappropriate implementation in DevTools. Reported by Google on 2026-05-16
[N/A][513819157] Low CVE-2026-17932: Use after free in DataTransfer. Reported by Google on 2026-05-16
[N/A][513822044] Low CVE-2026-17933: Inappropriate implementation in DOMStorage. Reported by Google on 2026-05-16
[N/A][513838421] Low CVE-2026-17934: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-05-16
[N/A][513863267] Low CVE-2026-17935: Heap buffer overflow in Codecs. Reported by Google on 2026-05-16
[N/A][513864014] Low CVE-2026-17936: Inappropriate implementation in DevTools. Reported by Google on 2026-05-16
[N/A][513866380] Low CVE-2026-17937: Inappropriate implementation in DevTools. Reported by Google on 2026-05-16
[N/A][513989304] Low CVE-2026-17938: Inappropriate implementation in FullScreen. Reported by Google on 2026-05-17
[N/A][514060089] Low CVE-2026-17939: Inappropriate implementation in Passwords. Reported by Google on 2026-05-17
[N/A][514069440] Low CVE-2026-17940: Insufficient validation of untrusted input in Picture-in-Picture. Reported by Google on 2026-05-17
[N/A][514147906] Low CVE-2026-17941: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-18
[N/A][514406198] Low CVE-2026-17942: Side-channel information leakage in SVG. Reported by Google on 2026-05-18
[N/A][514424283] Low CVE-2026-17943: Inappropriate implementation in Parser. Reported by Google on 2026-05-18
[N/A][514510853] Low CVE-2026-17944: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-19
[N/A][514519203] Low CVE-2026-17945: Inappropriate implementation in Navigation. Reported by Google on 2026-05-19
[N/A][515437522] Low CVE-2026-17946: Uninitialized Use in Dawn. Reported by Google on 2026-05-21
[N/A][515438256] Low CVE-2026-17947: Use after free in WebSockets. Reported by Google on 2026-05-21
[N/A][516849257] Low CVE-2026-17948: Type Confusion in V8. Reported by Google on 2026-05-26
[N/A][517000034] Low CVE-2026-17949: Uninitialized Use in GPU. Reported by Google on 2026-05-27
[N/A][517063658] Low CVE-2026-17950: Policy bypass in Safebrowsing. Reported by Google on 2026-05-27
[N/A][517180511] Low CVE-2026-17951: Heap buffer overflow in WebRTC. Reported by Google on 2026-05-27
[N/A][517316174] Low CVE-2026-17952: Inappropriate implementation in V8. Reported by Google on 2026-05-28
[N/A][517335150] Low CVE-2026-17953: Insufficient policy enforcement in WebView. Reported by Google on 2026-05-28
[N/A][517383492] Low CVE-2026-17954: Policy bypass in MHTML. Reported by Google on 2026-05-28
[N/A][517385072] Low CVE-2026-17955: Insufficient validation of untrusted input in Payments. Reported by Google on 2026-05-28
[N/A][517436171] Low CVE-2026-17956: Inappropriate implementation in Scheduling. Reported by Google on 2026-05-28
[N/A][517476342] Low CVE-2026-17957: Inappropriate implementation in CORS. Reported by Google on 2026-05-28
[N/A][517538206] Low CVE-2026-17958: Inappropriate implementation in Views. Reported by Google on 2026-05-28
[N/A][517607890] Low CVE-2026-17959: Inappropriate implementation in Network. Reported by Google on 2026-05-28
[N/A][517631680] Low CVE-2026-17960: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-05-28
[N/A][517700791] Low CVE-2026-17961: Inappropriate implementation in Session. Reported by Google on 2026-05-29
[N/A][517757268] Low CVE-2026-17962: Inappropriate implementation in Blink. Reported by Google on 2026-05-29
[N/A][517759257] Low CVE-2026-17963: Inappropriate implementation in SVG. Reported by Google on 2026-05-29
[N/A][518025103] Low CVE-2026-17964: Incorrect security UI in UI. Reported by Google on 2026-05-29
[N/A][518049812] Low CVE-2026-17965: Incorrect security UI in Chrome for iOS. Reported by Google on 2026-05-30
[N/A][518058990] Low CVE-2026-17966: Inappropriate implementation in Views. Reported by Google on 2026-05-30
[N/A][518243858] Low CVE-2026-17967: Use after free in Chrome for iOS. Reported by Google on 2026-05-30
[N/A][518337516] Low CVE-2026-17968: Uninitialized Use in WebXR. Reported by Google on 2026-05-31
[N/A][518812295] Low CVE-2026-17969: Inappropriate implementation in Passwords. Reported by Google on 2026-06-01
[N/A][518814464] Low CVE-2026-17970: Insufficient validation of untrusted input in Passwords. Reported by Google on 2026-06-01
[N/A][518815075] Low CVE-2026-17971: Inappropriate implementation in Frame. Reported by Google on 2026-06-01
[N/A][519202895] Low CVE-2026-17972: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-06-02
[N/A][519230894] Low CVE-2026-17973: Inappropriate implementation in Views. Reported by Google on 2026-06-02
[N/A][519232592] Low CVE-2026-17974: Insufficient policy enforcement in DevTools. Reported by Google on 2026-06-02
[N/A][519233776] Low CVE-2026-17975: Inappropriate implementation in IME. Reported by Google on 2026-06-02
[N/A][519455164] Low CVE-2026-17976: Policy bypass in Extensions. Reported by Google on 2026-06-03
[N/A][519603552] Low CVE-2026-17977: Policy bypass in CSS. Reported by Google on 2026-06-03
[N/A][519610845] Low CVE-2026-17978: Side-channel information leakage in WebCodecs. Reported by Google on 2026-06-03
[N/A][519664497] Low CVE-2026-17979: Race in V8. Reported by Google on 2026-06-04
[N/A][519710361] Low CVE-2026-17980: Inappropriate implementation in UI. Reported by Google on 2026-06-03
[N/A][519719512] Low CVE-2026-17981: Inappropriate implementation in Blink. Reported by Google on 2026-06-03
[N/A][519735808] Low CVE-2026-17982: Insufficient validation of untrusted input in Cast. Reported by Google on 2026-06-04
[N/A][519744561] Low CVE-2026-17983: Incorrect security UI in Global Media Controls. Reported by Google on 2026-06-04
[N/A][519978460] Low CVE-2026-17984: Inappropriate implementation in Browser. Reported by Google on 2026-06-04
[N/A][519981430] Low CVE-2026-17985: Insufficient policy enforcement in Speech. Reported by Google on 2026-06-04
[N/A][519981896] Low CVE-2026-17986: Insufficient policy enforcement in Bluetooth. Reported by Google on 2026-06-04
[N/A][519988071] Low CVE-2026-17987: Insufficient validation of untrusted input in Notifications. Reported by Google on 2026-06-04
[N/A][520005624] Low CVE-2026-17988: Insufficient validation of untrusted input in Navigation. Reported by Google on 2026-06-04
[N/A][520017306] Low CVE-2026-17989: Type Confusion in V8. Reported by Google on 2026-06-04
[N/A][520018012] Low CVE-2026-17990: Insufficient validation of untrusted input in WebAuthn. Reported by Google on 2026-06-04
[N/A][520110535] Low CVE-2026-17991: Insufficient validation of untrusted input in AI. Reported by Google on 2026-06-04
[N/A][520506316] Low CVE-2026-17992: Uninitialized Use in Skia. Reported by Google on 2026-06-05
[N/A][520532191] Low CVE-2026-17993: Race in Updater. Reported by Google on 2026-06-05
[N/A][520663771] Low CVE-2026-17994: Inappropriate implementation in Media. Reported by Google on 2026-06-06
[TBD][520972775] Low CVE-2026-17995: Out of bounds read in Dawn. Reported by sm1ee, ksw9722 on 2026-06-07
[N/A][521473427] Low CVE-2026-17996: Inappropriate implementation in Browser. Reported by Google on 2026-06-08
[N/A][521476960] Low CVE-2026-17997: Inappropriate implementation in Passwords. Reported by Google on 2026-06-08
[N/A][521601450] Low CVE-2026-17998: Incorrect security UI in Extensions. Reported by Google on 2026-06-09
[N/A][521615681] Low CVE-2026-17999: Incorrect security UI in PictureInPicture. Reported by Google on 2026-06-09
[N/A][521623907] Low CVE-2026-18000: Insufficient policy enforcement in USB. Reported by Google on 2026-06-09
[N/A][521757779] Low CVE-2026-18001: Inappropriate implementation in WebGL. Reported by Google on 2026-06-09
[N/A][521864362] Low CVE-2026-18002: Insufficient validation of untrusted input in Google Lens. Reported by Google on 2026-06-09
[N/A][521934304] Low CVE-2026-18003: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-06-09
[N/A][522280805] Low CVE-2026-18004: Insufficient policy enforcement in Speech. Reported by Google on 2026-06-10
[N/A][522300211] Low CVE-2026-18005: Inappropriate implementation in WebXR. Reported by Google on 2026-06-10
[N/A][522396262] Low CVE-2026-18006: Inappropriate implementation in Google Lens. Reported by Google on 2026-06-10
[N/A][522404101] Low CVE-2026-18007: Inappropriate implementation in Input. Reported by Google on 2026-06-10
[N/A][522412676] Low CVE-2026-18008: Inappropriate implementation in Settings. Reported by Google on 2026-06-10
[N/A][522419718] Low CVE-2026-18009: Insufficient validation of untrusted input in Passwords. Reported by Google on 2026-06-10
[N/A][522419819] Low CVE-2026-18010: Inappropriate implementation in Passwords. Reported by Google on 2026-06-10
[N/A][522479633] Low CVE-2026-18011: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-06-11
[N/A][522938824] Low CVE-2026-18012: Use after free in PDFium. Reported by Google on 2026-06-11
[N/A][523245998] Low CVE-2026-18013: Inappropriate implementation in Chrome for iOS. Reported by Google on 2026-06-12
[N/A][523248021] Low CVE-2026-18014: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-06-12
[N/A][523698428] Low CVE-2026-18015: Inappropriate implementation in Tint. Reported by Google on 2026-06-13
[N/A][523708527] Low CVE-2026-18016: Insufficient policy enforcement in Chrome for iOS. Reported by Google on 2026-06-13
[N/A][523731236] Low CVE-2026-18017: Use after free in Dawn. Reported by Google on 2026-06-14
[N/A][524467747] Low CVE-2026-18018: Inappropriate implementation in Updater. Reported by Google on 2026-06-16
[N/A][525691898] Low CVE-2026-18019: Side-channel information leakage in Media. Reported by Google on 2026-06-19
We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.
Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.
Krishna Govind
Google Chrome