Browser
This hub aggregates every CVE we track for Browser, a product in the hardware firmware space. Use it to gauge the current risk picture and drill into individual advisories.
43
CVEs tracked
3
Critical
27
High
0
In CISA KEV
Severity distribution
HIGH27MEDIUM13CRITICAL3
Monthly trend
1
0
0
0
2
0
0
0
2
1
2
0
1
0
1
1
0
0
0
0
0
0
2
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Browser.
- CVE-2026-52842Lightpanda:URL parser misidentifies page origin for URLs containing @ in the path - Same-Origin Policy bypass9.3
- CVE-2026-52843Lightpanda: fetch() and XMLHttpRequest attach session cookies to cross-origin requests regardless of credentials mode9.3
- CVE-2025-12046A DLL hijacking vulnerability was reported in the Lenovo App Store and Lenovo Browser applications that could allow a local authenticated user to execute code with elevated privileges under certain...7.8
- CVE-2025-10495A potential vulnerability was reported in the Lenovo PC Manager, Lenovo App Store, Lenovo Browser, and Lenovo Legion Zone client applications that, under certain conditions, could allow an attacker...7.5
- CVE-2025-9201A potential DLL hijacking vulnerability was discovered in Lenovo Browser during an internal security assessment that could allow a local user to execute code with elevated privileges.7.8
- CVE-2025-4657A buffer overflow vulnerability was reported in the Lenovo Protection Driver, prior to version 5.1.1110.4231, used in Lenovo PC Manager, Lenovo Browser, and Lenovo App Store could allow a local att...6.7
- CVE-2025-6248A cross-site scripting (XSS) vulnerability was reported in the Lenovo Browser that could allow an attacker to obtain sensitive information if a user visits a web page with specially crafted content.7.4
- CVE-2025-6152Steel Browser files.routes.ts handleFileUpload path traversal6.3
- CVE-2023-26226A use after free memory corruption issue exists in Yandex Browser for Desktop prior to version 24.4.0.6829.8
- CVE-2021-25262Yandex Browser for Android prior to version 21.3.0 allows remote attackers to perform IDN homograph attack.5.4
- CVE-2024-10254A potential buffer overflow vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to cause a system crash.4.7
- CVE-2024-10253A potential TOCTOU vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to cause a system crash.4.7
- CVE-2024-6473DLL Hijacking in Yandex Browser7.8
- CVE-2023-52263Brave Browser before 1.59.40 does not properly restrict the schema for WebUI factory and redirect. This is related to browser/brave_content_browser_client.cc and browser/ui/webui/brave_web_ui_contr...6.1
- CVE-2023-28364An Open Redirect vulnerability exists prior to version 1.52.117, where the built-in QR scanner in Brave Browser Android navigated to scanned URLs automatically without showing the URL first. Now th...6.1
Product normalization is registry-driven with AI assist and human review. How it works