Skip to main content

CWE archive

CWE-693 CVEs

Programmatic archive

675 CVEs tagged with CWE-693101 Critical, 234 High, 298 Medium, 42 Low, 0 Unrated.

CVE-2026-18015

Published Jul 30, 2026

Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chr…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-17943

Published Jul 30, 2026

Inappropriate implementation in Parser in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium secur…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17936

Published Jul 30, 2026

Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigat…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17931

Published Jul 30, 2026

Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium sec…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17923

Published Jul 30, 2026

Policy bypass in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted domain name. (Chromium security sever…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17919

Published Jul 30, 2026

Insufficient policy enforcement in Enterprise in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via physical access to the de…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17899

Published Jul 30, 2026

Insufficient policy enforcement in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to perform privilege…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-17882

Published Jul 30, 2026

Policy bypass in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to bypass site isolation via a crafte…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17865

Published Jul 30, 2026

Inappropriate implementation in Crypto in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a s…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-17856

Published Jul 30, 2026

Inappropriate implementation in Network in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-17779

Published Jul 30, 2026

Inappropriate implementation in Site Isolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium securi…

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17776

Published Jul 30, 2026

Policy bypass in Receiver in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a…

CVSS 5.8 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17764

Published Jul 30, 2026

Inappropriate implementation in FedCM in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security se…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17710

Published Jul 30, 2026

Inappropriate implementation in MHTML in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sa…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-17695

Published Jul 30, 2026

Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Ch…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-17677

Published Jul 30, 2026

Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-17676

Published Jul 30, 2026

Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-17674

Published Jul 30, 2026

Inappropriate implementation in HTML in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium securit…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17669

Published Jul 30, 2026

Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-17659

Published Jul 30, 2026

Inappropriate implementation in SiteIsolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass site isolation v…

CVSS 4.2 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-67427

Published Jul 29, 2026

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, the workflow engine variable resolver expands ${env.VAR} for any host environment variab…

CVSS 8.6 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-64708

Published Jul 27, 2026

A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may bypass Gatekeeper che…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-28912

Published Jul 27, 2026

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A user may be able to elevate privileges.

CVSS 7.8 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-28900

Published Jul 27, 2026

A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A maliciously crafted ZIP archive may bypass Gatek…

CVSS 5.5 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 675 CVEsPage 1 of 27