Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

2,374 CVEs affect a tracked app or OS (Critical, all platforms). 47 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
2,374
Actively exploited
47
Publication window
2007-08-28 → 2026-09-17

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

2,374 entries Critical Clear all
CVE
CVE-2026-93374
CRITICAL 9.6

Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbo…

CVE-2026-93373
CRITICAL 9.6

Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted Chro…

CVE-2026-93372
CRITICAL 9.6

Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a cr…

CVE-2026-91749
CRITICAL 9.6

Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a cra…

CVE-2026-91738
CRITICAL 9.6

Improper input validation in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox …

CVE-2026-91729
CRITICAL 9.6

Use after free in DigitalCredentials in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to execute arbitrary code …

CVE-2026-91728
CRITICAL 9.6

Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. …

CVE-2026-91718
CRITICAL 9.6

Use after free in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.…

CVE-2026-91716
CRITICAL 9.6

Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.…

CVE-2026-91710
CRITICAL 9.6

Use after free in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted …

CVE-2026-92240
CRITICAL 9.1

A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbi…

CVE-2026-92238
CRITICAL 9.8

A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in…

CVE-2026-86881
CRITICAL 9.1

A certificate validation issue was addressed with improved certificate validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS…

CVE-2026-84625
CRITICAL 9.1

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27, watchOS…

CVE-2026-84609
CRITICAL 9.8

A permissions issue was addressed with improved path validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS T…

CVE-2026-84561
CRITICAL 9.8

A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27,…

CVE-2026-84520
CRITICAL 9.8

A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Golden Gate 27. A local attacker may be able to cause unexpected sy…

CVE-2026-65414
CRITICAL 9.8

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden G…

CVE-2026-65381
CRITICAL 10.0

A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed i…

CVE-2026-43790
CRITICAL 9.1

The issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A remote attacker may…

CVE-2026-87654
CRITICAL 9.6

Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a cr…

CVE-2026-87650
CRITICAL 9.6

Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a c…

CVE-2026-87646
CRITICAL 9.6

Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a craf…

CVE-2026-87643
CRITICAL 9.6

Integer overflow in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandb…

CVE-2026-87638
CRITICAL 9.6

Out of bounds write in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a …

CVE-2026-87637
CRITICAL 9.6

Use after free in Extensions in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a cr…

CVE-2026-87634
CRITICAL 9.6

Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via …

CVE-2026-87621
CRITICAL 9.6

Out of bounds write in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the …

CVE-2026-87613
CRITICAL 9.0

Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside th…

CVE-2026-87609
CRITICAL 9.6

Use after free in Sharing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted…

CVE-2026-87607
CRITICAL 9.6

Use after free in Device in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox …

CVE-2026-87595
CRITICAL 9.8

Server-side request forgery in Mobile in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access r…

CVE-2026-87581
CRITICAL 9.6

Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary cod…

CVE-2026-87558
CRITICAL 9.6

Use after free in Payments in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a craf…

CVE-2026-87547
CRITICAL 9.6

Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially exe…

CVE-2026-87544
CRITICAL 9.8

Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged …

CVE-2026-87534
CRITICAL 9.8

Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system…

CVE-2026-87529
CRITICAL 9.6

Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox v…

CVE-2026-87528
CRITICAL 9.6

Type confusion in Rust in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbo…

CVE-2026-87527
CRITICAL 9.6

Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML pag…

CVE-2026-87526
CRITICAL 9.6

Use after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary co…

CVE-2026-87520
CRITICAL 9.6

Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a craf…

CVE-2026-87512
CRITICAL 9.6

Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a cra…

CVE-2026-87504
CRITICAL 9.6

Use after free in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sa…

CVE-2026-87500
CRITICAL 9.6

Improper validation of array index in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the…

CVE-2026-87494
CRITICAL 9.6

Use after free in Browser in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary co…

CVE-2026-87492
CRITICAL 9.6

Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox…

CVE-2026-87488
CRITICAL 9.6

Use after free in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a cra…

CVE-2026-87474
CRITICAL 9.6

Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a cr…

CVE-2026-87470
CRITICAL 9.6

Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside …

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM