FAIL › dossier
chrome
PRODUCT· dossier confidence 50%
Google Chrome is a dominant web browser with a massive user base, but its security posture is characterized by a persistent stream of critical vulnerabilities. The internal failure history reveals a pattern of severe flaws, including remote code execution, sandbox escapes, and use-after-free bugs, often requiring urgent patches to mitigate exploitation risks.
PROFILE
CategoryWeb BrowserWhat they doGoogle Chrome is a cross-platform web browser developed by Google.
SECURITY POSTURE
Chrome exhibits a high volume of critical vulnerabilities, predominantly involving sandbox escapes, use-after-free, and insufficient input validation across its renderer process and underlying components like Skia, ANGLE, and V8.
Notable failures
- CVE-2026-14104: Critical RCE0day in WebAppInstalls
- CVE-2026-14106: Critical sandbox escape in Android Text
- CVE-2026-14101: Critical sandbox escape in Mac Sandbox
- CVE-2026-13785: Critical use-after-free in Bluetooth
- CVE-2026-13776: Critical type confusion in Dawn
- CVE-2025-10585: Critical type confusion in V8
Patterns: repeated unpatched sandbox escapes via renderer compromise; repeated use-after-free vulnerabilities across multiple subsystems; repeated insufficient validation of untrusted input in core components
FAILURE HISTORY · 24
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-11-03 | CVE-2020-16017 | high | A use-after-free vulnerability in Google Chrome allowed sandbox escapes via crafted HTML pages after the renderer process was compromised. |
| 2026-06-30 | CVE-2026-14104 | critical | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low) |
| 2026-06-30 | CVE-2026-14106 | critical | Insufficient validation of untrusted input in Text in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) |
| 2026-06-30 | CVE-2026-14101 | critical | Insufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) |
| 2026-06-30 | CVE-2026-13785 | critical | Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) |
| 2026-06-30 | CVE-2026-14120 | critical | Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) |
| 2026-06-30 | CVE-2026-13781 | critical | Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) |
| 2026-06-30 | CVE-2026-13780 | critical | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) |
| 2026-06-30 | CVE-2026-13776 | critical | Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) |
| 2026-06-30 | CVE-2026-13775 | critical | Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) |
| 2026-06-30 | CVE-2026-13782 | critical | Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) |
| 2026-06-30 | CVE-2026-14109 | critical | Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) |
| 2026-06-04 | CVE-2026-11029 | critical | CVE-2026-11029: Insufficient validation of untrusted input in Drag and Drop in Google Chrome on |
| 2026-06-04 | CVE-2026-11120 | critical | CVE-2026-11120: Insufficient validation of untrusted input in Enterprise Reporting in Google Chr |
| 2026-06-04 | CVE-2026-11113 | critical | CVE-2026-11113: Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 14 |
| 2026-06-04 | CVE-2026-10931 | critical | CVE-2026-10931: Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a r |
| 2026-06-04 | CVE-2026-10966 | critical | CVE-2026-10966: Inappropriate implementation in Codecs in Google Chrome prior to 149.0.7827.53 a |
| 2026-06-04 | CVE-2026-10990 | critical | CVE-2026-10990: Use after free in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote |
| 2026-06-04 | CVE-2026-11002 | critical | CVE-2026-11002: Use after free in Autofill in Google Chrome prior to 149.0.7827.53 allowed a rem |
| 2026-06-04 | CVE-2026-10971 | critical | CVE-2026-10971: Insufficient validation of untrusted input in Printing in Google Chrome on Windo |
| 2026-06-04 | CVE-2026-10974 | critical | CVE-2026-10974: Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 14 |
| 2026-06-04 | CVE-2026-10972 | critical | CVE-2026-10972: Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allowed |
| 2026-05-28 | CVE-2026-9874 | critical | CVE-2026-9874: Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote |
| 2025-09-24 | CVE-2025-10585 | critical | CVE-2025-10585: Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote a |
Open questions: What is the exact patch cycle time for Chrome vulnerabilities? · How does Google coordinate with enterprise customers for critical CVEs?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-18 04:01:29.768590+00:00