search
browser vendors
Trends
- 1
A new community ranking of web platform features is drawing attention among developers, offering a comparative look at which browser capabilities are prioritised for interoperability work in the run-up to 2027. The interactive ranking lets developers see how features like new CSS, JavaScript and rendering APIs are scored across browser engines, and commenters are debating which features deserve priority and whether the rankings reflect real-world web development needs.
- 2High-severity race condition vulnerability patched in Google Chromeโผ๐จ EUVD-2026-93727 ๐ Score: 8.8/10 (CVSS v3.1) ๐ฆ Product: Chrome ๐ข Vendor: Google ๐ Updated: 2026-10-06 ๐ Race condition
Google has addressed a high-severity vulnerability in Chrome, tracked as EUVD-2026-93727, with a CVSS score of 8.8. The flaw was a race condition in the V8 JavaScript engine affecting Chrome versions prior to 155.0.8059.39. It allowed a remote attacker to execute arbitrary code inside the browser sandbox via a crafted HTML page. The fix was reflected in an advisory updated on 6 October 2026, and users are being urged to update their browsers.
- 3Google fixes high-severity Chrome WebRTC flawโผ๐จ EUVD-2026-93843 ๐ Score: 8.8/10 (CVSS v3.1) ๐ฆ Product: Chrome ๐ข Vendor: Google ๐ Updated: 2026-10-06 ๐ Use after free
Google has patched a use-after-free vulnerability in WebRTC in Google Chrome, tracked as EUVD-2026-93843 with a CVSS score of 8.8. The flaw, fixed in Chrome 155.0.8059.39, could have let a remote attacker execute arbitrary code inside the browser's sandbox via a specially crafted HTML page. Security trackers updated the entry on 6 October 2026.
- 4Low-severity Chrome animation flaw disclosed in EUVDโผ๐จ EUVD-2026-93725 ๐ Score: 3.1/10 (CVSS v3.1) ๐ฆ Product: Chrome ๐ข Vendor: Google ๐ Published: 2026-10-06 | Updated: 2026
A vulnerability tracked as EUVD-2026-93725 was published for Google Chrome. Described as an observable discrepancy in the browser's Animation component, it affected versions before 155.0.8059.39 and could have let a remote attacker potentially obtain cross-origin data. It carries a CVSS v3.1 score of 3.1, marking it as low severity, and was updated on 2026-10-07.
- 5Google Chrome extension flaw exposes cross-origin dataโผ๐จ EUVD-2026-93704 ๐ Score: 4.3/10 (CVSS v3.1) ๐ฆ Product: Chrome ๐ข Vendor: Google ๐ Published: 2026-10-06 | Updated: 2026
A medium-severity vulnerability, EUVD-2026-93704, has been published for Google Chrome. The flaw, rated 4.3 out of 10 under CVSS v3.1, involves improper resource exposure in browser extensions. Versions of Chrome prior to 155.0.8059.39 are affected, and a remote attacker could obtain cross-origin data through a crafted request. Users are advised to update their browser to the latest version, released on 6 October 2026 with an update the following day.
- 6High-severity type confusion flaw patched in Chrome browserโผ๐จ EUVD-2026-93844 ๐ Score: 8.8/10 (CVSS v3.1) ๐ฆ Product: Chrome ๐ข Vendor: Google ๐ Updated: 2026-10-06 ๐ Type confusion
Google has updated Chrome to version 155.0.8059.39 to fix a type confusion vulnerability in the V8 engine, tracked as EUVD-2026-93844 with a CVSS score of 8.8. The flaw could have allowed a remote attacker to execute arbitrary code inside the browser's sandbox via a specially crafted HTML page. Security feeds are flagging the update, and users are being urged to install the patched version promptly.
- 7Google Chrome vulnerability allows sandbox code executionโผ๐จ EUVD-2026-93687 ๐ Score: 8.8/10 (CVSS v3.1) ๐ฆ Product: Chrome ๐ข Vendor: Google ๐ Published: 2026-10-06 | Updated: 2026
Google has patched a high-severity Chrome vulnerability, EUVD-2026-93687, with a CVSS score of 8.8. The flaw, a use-after-free in Chrome's Media component, could let a remote attacker execute arbitrary code inside the browser sandbox via crafted content. The fix ships in Chrome 155.0.8059.39, published to advisories on 6 October 2026 and updated a day later.
- 8High-severity Chrome font flaw lets attackers run codeโผ๐จ EUVD-2026-93749 ๐ Score: 8.8/10 (CVSS v3.1) ๐ฆ Product: Chrome ๐ข Vendor: Google ๐ Published: 2026-10-06 | Updated: 2026
A high-severity vulnerability, EUVD-2026-93749, was published for Google Chrome on Windows, scoring 8.8 out of 10 on the CVSS scale. The flaw is a use-after-free bug in Chrome's font handling, and versions before 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the browser sandbox. Google has issued a fix, and users are being urged to update.
- 9Google fixes high-severity Chrome use-after-free flawโผ๐จ EUVD-2026-93846 ๐ Score: 8.8/10 (CVSS v3.1) ๐ฆ Product: Chrome ๐ข Vendor: Google ๐ Updated: 2026-10-06 ๐ Use after free
A high-severity vulnerability, tracked as EUVD-2026-93846 with a CVSS score of 8.8, has been reported in Google Chrome. The use-after-free bug, in media handling, allowed a remote attacker to execute arbitrary code inside the browser's sandbox via a crafted HTML page in versions prior to 155.0.8059.39. Security trackers updated the entry on October 6, 2026, and the fix ships with Chrome 155.0.8059.39.
- 10Pwn2Own Ireland 2026: Day Two Results ReleasedโPwn2Own Ireland 2026 - Day Two Results https:// packetstorm.news/news/view/449 05 # news
Results from day two of the Pwn2Own Ireland 2026 hacking competition have been published, detailing which zero-day exploits were successfully demonstrated and the prize money awarded to researchers. Pwn2Own events draw significant attention in the cybersecurity community, as successful hacks against phones, browsers, and other systems often lead to vendor patches and reveal previously unknown vulnerabilities.
- 11High-severity Chrome use-after-free flaw patched in V8 engineโผ๐จ EUVD-2026-93847 ๐ Score: 8.8/10 (CVSS v3.1) ๐ฆ Product: Chrome ๐ข Vendor: Google ๐ Updated: 2026-10-06 ๐ Use after free
Google has addressed a use-after-free vulnerability in Chrome's V8 JavaScript engine, tracked as EUVD-2026-93847 with a CVSS score of 8.8. The flaw, present in versions prior to 155.0.8059.39, could let a remote attacker execute arbitrary code inside the browser sandbox via a crafted HTML page. The fix rolled out with the updated release on October 6, and security trackers are flagging it for users to update promptly.
- 12High-severity Chrome use-after-free vulnerability patchedโผ๐จ EUVD-2026-93848 ๐ Score: 8.8/10 (CVSS v3.1) ๐ฆ Product: Chrome ๐ข Vendor: Google ๐ Updated: 2026-10-06 ๐ Use after free
Google has fixed a high-severity use-after-free vulnerability in Chrome's PDF component, tracked as EUVD-2026-93848 with a CVSS score of 8.8. The flaw, present in versions prior to 155.0.8059.39, could have allowed a remote attacker to execute arbitrary code inside the browser's sandbox via a crafted HTML page. Security researchers are urging users to update Chrome promptly.
- 13Google Chrome patch fixes medium-severity data leak flawโ๐จ EUVD-2026-93845 ๐ Score: 4.3/10 (CVSS v3.1) ๐ฆ Product: Chrome ๐ข Vendor: Google ๐ Published: 2026-10-06 | Updated: 2026
Google has patched a vulnerability in Chrome, tracked as EUVD-2026-93845, with a CVSS score of 4.3 out of 10. The flaw involved an uninitialized resource in the browser's Media component, which could have let a remote attacker access cross-origin data using a crafted HTML page. Users should update Chrome to version 155.0.8059.39 or later.
- 14Google Chrome security flaw disclosed in Google Lensโ๐จ EUVD-2026-93689 ๐ Score: 3.1/10 (CVSS v3.1) ๐ฆ Product: Chrome ๐ข Vendor: Google ๐ Published: 2026-10-06 | Updated: 2026
A low-severity vulnerability, EUVD-2026-93689, has been published for Google Chrome, scoring 3.1 out of 10 on the CVSS v3.1 scale. The flaw involves missing authorization in Google Lens and could have allowed a remote attacker who had already compromised the renderer process to take further action. Google fixed the issue in Chrome version 155.0.8059.39, and users are advised to update their browsers.
- 15Google Chrome security flaw could leak cross-origin dataโ๐จ EUVD-2026-93828 ๐ Score: 4.3/10 (CVSS v3.1) ๐ฆ Product: Chrome ๐ข Vendor: Google ๐ Published: 2026-10-06 | Updated: 2026
Google has fixed a security vulnerability in its Chrome browser, tracked as EUVD-2026-93828, published on 6 October 2026. The flaw involves an uninitialized resource in the Skia graphics library and allowed a remote attacker to obtain cross-origin data through a crafted HTML page. The issue carries a CVSS score of 4.3 out of 10 and is resolved in Chrome version 155.0.8059.39.
- 16High-severity Chrome flaw allows code execution, patch releasedโ๐จ EUVD-2026-93674 ๐ Score: 8.8/10 (CVSS v3.1) ๐ฆ Product: Chrome ๐ข Vendor: Google ๐ Published: 2026-10-06 | Updated: 2026
A high-severity vulnerability in Google Chrome, tracked as EUVD-2026-93674 with a CVSS score of 8.8, was published on 6 October and updated the following day. The flaw is a use-after-free bug in the browser's garbage collection that let a remote attacker execute arbitrary code inside the sandbox. It affects Chrome versions before 155.0.8059.39, and security trackers are urging users to update their browsers promptly.
- 17High-severity Chrome vulnerability flagged with 8.8 CVSS scoreโ๐จ EUVD-2026-93673 ๐ Score: 8.8/10 (CVSS v3.1) ๐ฆ Product: Chrome ๐ข Vendor: Google ๐ Published: 2026-10-06 | Updated: 2026
A use-after-free vulnerability in the streaming component of Google Chrome, tracked as EUVD-2026-93673, was published on October 6, 2026 and carries a CVSS v3.1 score of 8.8. The flaw allowed a remote attacker, using social engineering, to potentially execute code in Chrome versions prior to 155.0.8059.39. Google has addressed the issue in the updated release, and security watchers are urging users to update their browsers promptly.
- 18WordPress app builder plugin hit by stored XSS flawโผ๐จ EUVD-2026-91951 ๐ Score: 5.4/10 (CVSS v3.1) ๐ฆ Product: WPMobile.App โ Android and iOS App Builder ๐ข Vendor: amauric ๐
A medium-severity vulnerability, tracked as EUVD-2026-91951 with a CVSS score of 5.4, has been disclosed in the WPMobile.App โ Android and iOS App Builder WordPress plugin by vendor amauric. The flaw is a stored cross-site scripting issue reachable via the REQUEST_URI parameter, meaning attackers could inject malicious scripts that persist and run in visitors' browsers. Administrators running the plugin are advised to check for an updated version.