<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent vulnerabilities from the Google CNA root</title>
    <link>https://127.0.0.1:10001</link>
    <description>Latest vulnerabilities published by the CNAs operating under the Google root of the CVE Program.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:09:09 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-103627 (Chrome)</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-103627</link>
      <description>Information leak in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)</description>
      <content:encoded>Information leak in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-103627</guid>
      <pubDate>Fri, 02 Oct 2026 16:07:56 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-103631 (Chrome)</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-103631</link>
      <description>Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)</description>
      <content:encoded>Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-103631</guid>
      <pubDate>Fri, 02 Oct 2026 16:07:56 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-103623 (Chrome)</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-103623</link>
      <description>Use after free in MediaStream in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)</description>
      <content:encoded>Use after free in MediaStream in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-103623</guid>
      <pubDate>Fri, 02 Oct 2026 16:07:56 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-103622 (Chrome)</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-103622</link>
      <description>Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)</description>
      <content:encoded>Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-103622</guid>
      <pubDate>Fri, 02 Oct 2026 16:07:55 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-103629 (Chrome)</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-103629</link>
      <description>Integer overflow in Skia in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)</description>
      <content:encoded>Integer overflow in Skia in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-103629</guid>
      <pubDate>Fri, 02 Oct 2026 16:07:55 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-103624 (Chrome)</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-103624</link>
      <description>Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)</description>
      <content:encoded>Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-103624</guid>
      <pubDate>Fri, 02 Oct 2026 16:07:55 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-103625 (Chrome)</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-103625</link>
      <description>Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)</description>
      <content:encoded>Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-103625</guid>
      <pubDate>Fri, 02 Oct 2026 16:07:55 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-103630 (Chrome)</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-103630</link>
      <description>Use after free in FedCM in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)</description>
      <content:encoded>Use after free in FedCM in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-103630</guid>
      <pubDate>Fri, 02 Oct 2026 16:07:54 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-103621 (Chrome)</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-103621</link>
      <description>Integer overflow in Compositing in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)</description>
      <content:encoded>Integer overflow in Compositing in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-103621</guid>
      <pubDate>Fri, 02 Oct 2026 16:07:54 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-103626 (Chrome)</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-103626</link>
      <description>Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)</description>
      <content:encoded>Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-103626</guid>
      <pubDate>Fri, 02 Oct 2026 16:07:54 +0000</pubDate>
    </item>
  </channel>
</rss>
