CVE-2026-13920
Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had com
CVSS
9.6
Critical
EPSS
0.3%
p24
KEV
—
Exploit Today
7
0-100
Published: Jun 30, 2026 · Last modified: Jul 1, 2026 · CWE-20
0.2%EPSS · 30 days0.3%
2026-07-012026-07-21
Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-16422——
——0Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an attacker in a privileged network position to perform domain spoofing via malicious network traffic. (Chromium security severity: High)2hCVE-2026-16415——
——0Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)2hCVE-2026-16414——
——0Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)2hCVE-2026-648778.4 HIG—
——0An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.5hCVE-2026-15792——
——0A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.7hCVE-2026-157248.7 HIG—
——0In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directories, or determine whether specific files exist on the server.7h