CVE Tools

Browser

43 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Browser, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.

Browser CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Browser CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-012
2025-020
2025-030
2025-040
2025-052
2025-061
2025-072
2025-080
2025-091
2025-100
2025-111
2025-121
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-072
2026-080
2026-090

Severity

How the 43 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical37%
  • High2763%
  • Medium1330%

Latest CVEs

The 15 most recently published vulnerabilities affecting Browser.

  1. CVE-2026-52842Lightpanda:URL parser misidentifies page origin for URLs containing @ in the path - Same-Origin Policy bypass9.3
  2. CVE-2026-52843Lightpanda: fetch() and XMLHttpRequest attach session cookies to cross-origin requests regardless of credentials mode9.3
  3. CVE-2025-12046A DLL hijacking vulnerability was reported in the Lenovo App Store and Lenovo Browser applications that could allow a local authenticated user to execute code with elevated privileges under certain...7.8
  4. CVE-2025-10495A potential vulnerability was reported in the Lenovo PC Manager, Lenovo App Store, Lenovo Browser, and Lenovo Legion Zone client applications that, under certain conditions, could allow an attacker...7.5
  5. CVE-2025-9201A potential DLL hijacking vulnerability was discovered in Lenovo Browser during an internal security assessment that could allow a local user to execute code with elevated privileges.7.8
  6. CVE-2025-4657A buffer overflow vulnerability was reported in the Lenovo Protection Driver, prior to version 5.1.1110.4231, used in Lenovo PC Manager, Lenovo Browser, and Lenovo App Store could allow a local att...6.7
  7. CVE-2025-6248A cross-site scripting (XSS) vulnerability was reported in the Lenovo Browser that could allow an attacker to obtain sensitive information if a user visits a web page with specially crafted content.7.4
  8. CVE-2025-6152Steel Browser files.routes.ts handleFileUpload path traversal6.3
  9. CVE-2023-26226A use after free memory corruption issue exists in Yandex Browser for Desktop prior to version 24.4.0.6829.8
  10. CVE-2021-25262Yandex Browser for Android prior to version 21.3.0 allows remote attackers to perform IDN homograph attack.5.4
  11. CVE-2024-10254A potential buffer overflow vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to cause a system crash.4.7
  12. CVE-2024-10253A potential TOCTOU vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to cause a system crash.4.7
  13. CVE-2024-6473DLL Hijacking in Yandex Browser7.8
  14. CVE-2023-52263Brave Browser before 1.59.40 does not properly restrict the schema for WebUI factory and redirect. This is related to browser/brave_content_browser_client.cc and browser/ui/webui/brave_web_ui_contr...6.1
  15. CVE-2023-28364An Open Redirect vulnerability exists prior to version 1.52.117, where the built-in QR scanner in Brave Browser Android navigated to scanned URLs automatically without showing the URL first. Now th...6.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store