PAN-SA-2026-0011 Chromium: Monthly Vulnerability Update (August 2026)
Exploit Maturity
UNREPORTED
Response Effort
MODERATE
Recovery
USER
Value Density
DIFFUSE
Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
NONE
Automatable
NO
User Interaction
NONE
Product Confidentiality
HIGH
Product Integrity
HIGH
Product Availability
HIGH
Privileges Required
NONE
Subsequent Confidentiality
NONE
Subsequent Integrity
NONE
Subsequent Availability
NONE
Description
Palo Alto Networks incorporated the following Chromium security fixes into our products:
- https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html
- https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01320465736.html
- https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html
- https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_049796704.html
- https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0353146366.html
- https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html
- https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop.html
| CVE | Summary |
|---|---|
| CVE-2026-13774 | Use after free in Extensions |
| CVE-2026-13775 | Use after free in GPU |
| CVE-2026-13776 | Type Confusion in Dawn |
| CVE-2026-13777 | Insufficient validation of untrusted input in iOSWeb |
| CVE-2026-13778 | Use after free in WebUSB |
| CVE-2026-13779 | Use after free in Chromoting |
| CVE-2026-13780 | Insufficient validation of untrusted input in ANGLE |
| CVE-2026-13781 | Insufficient validation of untrusted input in Skia |
| CVE-2026-13782 | Use after free in Browser |
| CVE-2026-13783 | Use after free in Views |
| CVE-2026-13784 | Use after free in Views |
| CVE-2026-13785 | Use after free in Bluetooth |
| CVE-2026-13786 | Use after free in Ozone |
| CVE-2026-13787 | Use after free in Chromoting |
| CVE-2026-13788 | Use after free in Fullscreen |
| CVE-2026-13789 | Use after free in GPU |
| CVE-2026-13790 | Side-channel information leakage in Scroll |
| CVE-2026-13791 | Insufficient validation of untrusted input in Downloads |
| CVE-2026-13792 | Use after free in Touchbar |
| CVE-2026-13793 | Insufficient policy enforcement in SVG |
| CVE-2026-13794 | Insufficient validation of untrusted input in WebAppInstalls |
| CVE-2026-13795 | Insufficient policy enforcement in Chrome for iOS |
| CVE-2026-13796 | Integer overflow in Chromecast |
| CVE-2026-13797 | Insufficient validation of untrusted input in Chromecast |
| CVE-2026-13798 | Heap buffer overflow in Chromecast |
| CVE-2026-13799 | Use after free in QUIC |
| CVE-2026-13800 | Inappropriate implementation in Updater |
| CVE-2026-13801 | Integer overflow in Chromecast |
| CVE-2026-13802 | Use after free in Views |
| CVE-2026-13803 | Type Confusion in Chrome Tabs |
| CVE-2026-13804 | Use after free in Chromecast |
| CVE-2026-13805 | Use after free in GFX |
| CVE-2026-13806 | Insufficient validation of untrusted input in Accessibility |
| CVE-2026-13807 | Use after free in Import |
| CVE-2026-13808 | Insufficient data validation in Chrome for iOS |
| CVE-2026-13809 | Side-channel information leakage in Safe Browsing |
| CVE-2026-13810 | Inappropriate implementation in Input |
| CVE-2026-13811 | Use after free in IME |
| CVE-2026-13812 | Insufficient validation of untrusted input in Chrome for iOS |
| CVE-2026-13813 | Insufficient policy enforcement in Chrome for iOS |
| CVE-2026-13814 | Use after free in Views |
| CVE-2026-13815 | Use after free in Blink |
| CVE-2026-13816 | Insufficient validation of untrusted input in File Input |
| CVE-2026-13817 | Insufficient validation of untrusted input in Glic |
| CVE-2026-13818 | Inappropriate implementation in Passwords |
| CVE-2026-13819 | Out of bounds read in ANGLE |
| CVE-2026-13820 | Out of bounds read in Skia |
| CVE-2026-13821 | Use after free in Canvas |
| CVE-2026-13822 | Inappropriate implementation in Extensions |
| CVE-2026-13823 | Use after free in Glic |
| CVE-2026-13824 | Insufficient policy enforcement in Extensions |
| CVE-2026-13825 | Uninitialized Use in Dawn |
| CVE-2026-13826 | Inappropriate implementation in Autofill |
| CVE-2026-13827 | Use after free in Updater |
| CVE-2026-13828 | Inappropriate implementation in Enterprise |
| CVE-2026-13829 | Insufficient validation of untrusted input in Settings |
| CVE-2026-13830 | Use after free in Chromoting |
| CVE-2026-13831 | Out of bounds read and write in GPU |
| CVE-2026-13832 | Use after free in Headless |
| CVE-2026-13833 | Uninitialized Use in ANGLE |
| CVE-2026-13834 | Insufficient validation of untrusted input in ANGLE |
| CVE-2026-13835 | Inappropriate implementation in XML |
| CVE-2026-13836 | Inappropriate implementation in CSS |
| CVE-2026-13837 | Inappropriate implementation in CSS |
| CVE-2026-13838 | Inappropriate implementation in CSS |
| CVE-2026-13839 | Inappropriate implementation in CSS |
| CVE-2026-13840 | Insufficient policy enforcement in Canvas |
| CVE-2026-13841 | Integer overflow in Skia |
| CVE-2026-13842 | Inappropriate implementation in Chrome for iOS |
| CVE-2026-13843 | Insufficient validation of untrusted input in Chrome for iOS |
| CVE-2026-13844 | Use after free in Updater |
| CVE-2026-13845 | Use after free in DOM |
| CVE-2026-13846 | Use after free in USB |
| CVE-2026-13847 | Insufficient validation of untrusted input in Chrome for iOS |
| CVE-2026-13848 | Use after free in Forms |
| CVE-2026-13849 | Insufficient validation of untrusted input in Chromoting |
| CVE-2026-13850 | Insufficient validation of untrusted input in Chrome for iOS |
| CVE-2026-13851 | Insufficient validation of untrusted input in WebAppInstalls |
| CVE-2026-13852 | Insufficient validation of untrusted input in WebAppInstalls |
| CVE-2026-13853 | Use after free in Journeys |
| CVE-2026-13854 | Use after free in Ozone |
| CVE-2026-13855 | Use after free in Ozone |
| CVE-2026-13856 | Insufficient validation of untrusted input in Speech |
| CVE-2026-13857 | Inappropriate implementation in Geometry |
| CVE-2026-13858 | Out of bounds read in FFmpeg |
| CVE-2026-13859 | Inappropriate implementation in ANGLE |
| CVE-2026-13860 | Incorrect security UI in Autofill |
| CVE-2026-13861 | Use after free in Core |
| CVE-2026-13862 | Insufficient policy enforcement in Web Authentication (Passkeys & Security Keys) |
| CVE-2026-13863 | Insufficient validation of untrusted input in CustomTabs |
| CVE-2026-13864 | Insufficient policy enforcement in WebHID |
| CVE-2026-13865 | Insufficient validation of untrusted input in Enterprise |
| CVE-2026-13866 | Inappropriate implementation in Input |
| CVE-2026-13867 | Inappropriate implementation in Geolocation |
| CVE-2026-13868 | Inappropriate implementation in Network |
| CVE-2026-13869 | Use after free in Device |
| CVE-2026-13870 | Use after free in WebView |
| CVE-2026-13871 | Insufficient policy enforcement in GuestView |
| CVE-2026-13872 | Insufficient validation of untrusted input in WebAppInstalls |
| CVE-2026-13873 | Out of bounds read in Layout |
| CVE-2026-13874 | Race in DataTransfer |
| CVE-2026-13875 | Insufficient validation of untrusted input in GPU |
| CVE-2026-13876 | Inappropriate implementation in Network |
| CVE-2026-13877 | Insufficient validation of untrusted input in ANGLE |
| CVE-2026-13878 | Use after free in Bluetooth |
| CVE-2026-13879 | Use after free in Bluetooth |
| CVE-2026-13880 | Use after free in USB |
| CVE-2026-13881 | Inappropriate implementation in WebAppInstalls |
| CVE-2026-13882 | Race in USB |
| CVE-2026-13883 | Type Confusion in ANGLE |
| CVE-2026-13884 | Integer overflow in Chromecast |
| CVE-2026-13885 | Use after free in Skia |
| CVE-2026-13886 | Insufficient policy enforcement in Isolated Web Apps |
| CVE-2026-13887 | Inappropriate implementation in NFC |
| CVE-2026-13888 | Use after free in Extensions |
| CVE-2026-13889 | Side-channel information leakage in WebAuthentication |
| CVE-2026-13890 | Out of bounds read in Chromecast |
| CVE-2026-13891 | Insufficient validation of untrusted input in Extensions |
| CVE-2026-13892 | Inappropriate implementation in Chrome for iOS |
| CVE-2026-13893 | Insufficient validation of untrusted input in WebUI |
| CVE-2026-13894 | Insufficient policy enforcement in Network |
| CVE-2026-13895 | Inappropriate implementation in Autofill |
| CVE-2026-13896 | Insufficient policy enforcement in Glic |
| CVE-2026-13897 | Insufficient policy enforcement in Chromecast |
| CVE-2026-13898 | Use after free in Cast Receiver |
| CVE-2026-13899 | Use after free in HTML |
| CVE-2026-13900 | Inappropriate implementation in Chromecast |
| CVE-2026-13901 | Insufficient policy enforcement in Serial |
| CVE-2026-13902 | Inappropriate implementation in Chrome for iOS |
| CVE-2026-13903 | Insufficient policy enforcement in Bluetooth |
| CVE-2026-13904 | Inappropriate implementation in Safe Browsing |
| CVE-2026-13905 | Race in Chrome for iOS |
| CVE-2026-13906 | Out of bounds read in Codecs |
| CVE-2026-13907 | Inappropriate implementation in iOSWeb |
| CVE-2026-13908 | Insufficient validation of untrusted input in Omnibox |
| CVE-2026-13909 | Insufficient policy enforcement in DevTools |
| CVE-2026-13910 | Insufficient policy enforcement in WebXR |
| CVE-2026-13911 | Insufficient policy enforcement in Spellcheck |
| CVE-2026-13912 | Inappropriate implementation in Safe Browsing |
| CVE-2026-13913 | Insufficient policy enforcement in Autofill |
| CVE-2026-13914 | Inappropriate implementation in Passwords |
| CVE-2026-13915 | Use after free in Chrome for iOS |
| CVE-2026-13916 | Inappropriate implementation in Chrome for iOS |
| CVE-2026-13917 | Insufficient validation of untrusted input in Chrome for iOS |
| CVE-2026-13918 | Use after free in Chrome for iOS |
| CVE-2026-13919 | Insufficient policy enforcement in Extensions |
| CVE-2026-13920 | Insufficient validation of untrusted input in Media |
| CVE-2026-13921 | Insufficient validation of untrusted input in DeviceBoundSessionCredentials |
| CVE-2026-13922 | Side-channel information leakage in Paint |
| CVE-2026-13923 | Uninitialized Use in GPU |
| CVE-2026-13924 | Insufficient validation of untrusted input in WebView |
| CVE-2026-13925 | Inappropriate implementation in Downloads |
| CVE-2026-13926 | Insufficient validation of untrusted input in Network |
| CVE-2026-13927 | Insufficient validation of untrusted input in UI |
| CVE-2026-13928 | Insufficient validation of untrusted input in Enterprise |
| CVE-2026-13929 | Insufficient policy enforcement in DevTools |
| CVE-2026-13930 | Insufficient policy enforcement in Actor |
| CVE-2026-13931 | Inappropriate implementation in Media |
| CVE-2026-13932 | Inappropriate implementation in Sharing |
| CVE-2026-13933 | Insufficient policy enforcement in Passwords |
| CVE-2026-13934 | Insufficient validation of untrusted input in Dawn |
| CVE-2026-13935 | Side-channel information leakage in ComputePressure |
| CVE-2026-13936 | Inappropriate implementation in Passwords |
| CVE-2026-13937 | Insufficient policy enforcement in Passwords |
| CVE-2026-13938 | Integer overflow in Fonts |
| CVE-2026-13939 | Insufficient validation of untrusted input in WebShare |
| CVE-2026-13940 | Uninitialized Use in Cast |
| CVE-2026-13941 | Inappropriate implementation in SiteSettings |
| CVE-2026-13942 | Inappropriate implementation in Video Capture |
| CVE-2026-13943 | Uninitialized Use in CSS |
| CVE-2026-13944 | Inappropriate implementation in DataTransfer |
| CVE-2026-13945 | Insufficient policy enforcement in Extensions |
| CVE-2026-13946 | Inappropriate implementation in ScriptInjections |
| CVE-2026-13947 | Uninitialized Use in XR |
| CVE-2026-13948 | Insufficient policy enforcement in Extensions |
| CVE-2026-13949 | Insufficient policy enforcement in Payments |
| CVE-2026-13950 | Uninitialized Use in GPU |
| CVE-2026-13951 | Insufficient policy enforcement in USB |
| CVE-2026-13952 | Inappropriate implementation in PerformanceAPIs |
| CVE-2026-13953 | Inappropriate implementation in SplitView |
| CVE-2026-13954 | Insufficient policy enforcement in XML |
| CVE-2026-13955 | Insufficient validation of untrusted input in CustomTabs |
| CVE-2026-13956 | Incorrect security UI in PageInfo |
| CVE-2026-13957 | Incorrect security UI in Extensions |
| CVE-2026-13958 | Uninitialized Use in Codecs |
| CVE-2026-13959 | Insufficient validation of untrusted input in Blink |
| CVE-2026-13960 | Inappropriate implementation in Passwords |
| CVE-2026-13961 | Insufficient validation of untrusted input in DevTools |
| CVE-2026-13962 | Insufficient data validation in PDF |
| CVE-2026-13963 | Inappropriate implementation in DevTools |
| CVE-2026-13964 | Insufficient policy enforcement in WebView |
| CVE-2026-13965 | Use after free in Oilpan |
| CVE-2026-13966 | Inappropriate implementation in History |
| CVE-2026-13967 | Heap buffer overflow in V8 |
| CVE-2026-13968 | Insufficient validation of untrusted input in DevTools |
| CVE-2026-13969 | Uninitialized Use in UI |
| CVE-2026-13970 | Uninitialized Use in Media |
| CVE-2026-13971 | Uninitialized Use in Skia |
| CVE-2026-13972 | Inappropriate implementation in Paint |
| CVE-2026-13973 | Inappropriate implementation in UI |
| CVE-2026-13974 | Integer overflow in Safe Browsing |
| CVE-2026-13975 | Out of bounds read in ANGLE |
| CVE-2026-13976 | Insufficient data validation in Storage |
| CVE-2026-13977 | Inappropriate implementation in HTMLParser |
| CVE-2026-13978 | Insufficient policy enforcement in PageInfo |
| CVE-2026-13979 | Inappropriate implementation in Paint |
| CVE-2026-13980 | Inappropriate implementation in Chrome for iOS |
| CVE-2026-13981 | Inappropriate implementation in Chrome for iOS |
| CVE-2026-13982 | Incorrect security UI in Passwords |
| CVE-2026-13983 | Inappropriate implementation in Chrome for iOS |
| CVE-2026-13984 | Incorrect security UI in TabStrip |
| CVE-2026-13985 | Inappropriate implementation in MediaCapture |
| CVE-2026-13986 | Inappropriate implementation in Media UI |
| CVE-2026-13987 | Incorrect security UI in Mobile |
| CVE-2026-13988 | Inappropriate implementation in Paint |
| CVE-2026-13989 | Inappropriate implementation in PageInfo |
| CVE-2026-13990 | Insufficient validation of untrusted input in DataTransfer |
| CVE-2026-13991 | Insufficient validation of untrusted input in Chrome for iOS |
| CVE-2026-13992 | Inappropriate implementation in UI |
| CVE-2026-13993 | Incorrect security UI in WebAppInstalls |
| CVE-2026-13994 | Inappropriate implementation in Credential Management |
| CVE-2026-13995 | Insufficient validation of untrusted input in Autofill |
| CVE-2026-13996 | Inappropriate implementation in Permissions |
| CVE-2026-13997 | Incorrect security UI in Extensions |
| CVE-2026-13998 | Incorrect security UI in File Input |
| CVE-2026-13999 | Insufficient validation of untrusted input in Extensions |
| CVE-2026-14000 | Inappropriate implementation in XML |
| CVE-2026-14001 | Inappropriate implementation in Network |
| CVE-2026-14002 | Inappropriate implementation in Geolocation |
| CVE-2026-14003 | Insufficient policy enforcement in Extensions |
| CVE-2026-14004 | Inappropriate implementation in CSS |
| CVE-2026-14005 | Use after free in Omnibox |
| CVE-2026-14006 | Use after free in Navigation |
| CVE-2026-14007 | Insufficient policy enforcement in PermissionsPolicy |
| CVE-2026-14008 | Uninitialized Use in WebXR |
| CVE-2026-14009 | Inappropriate implementation in Passwords |
| CVE-2026-14010 | Uninitialized Use in Codecs |
| CVE-2026-14011 | Out of bounds read in SurfaceCapture |
| CVE-2026-14012 | Side-channel information leakage in CSS |
| CVE-2026-14013 | Inappropriate implementation in SVG |
| CVE-2026-14014 | Inappropriate implementation in Paint |
| CVE-2026-14015 | Race in WebRTC |
| CVE-2026-14016 | Inappropriate implementation in SVG |
| CVE-2026-14017 | Inappropriate implementation in Navigation |
| CVE-2026-14018 | Use after free in Updater |
| CVE-2026-14019 | Inappropriate implementation in Passwords |
| CVE-2026-14020 | Insufficient validation of untrusted input in WebXR |
| CVE-2026-14021 | Insufficient policy enforcement in StorageAccessAPI |
| CVE-2026-14022 | Insufficient validation of untrusted input in Network |
| CVE-2026-14023 | Insufficient validation of untrusted input in SanitizerAPI |
| CVE-2026-14024 | Use after free in Ozone |
| CVE-2026-14025 | Use after free in Views |
| CVE-2026-14026 | Incorrect security UI in SplitView |
| CVE-2026-14027 | Use after free in SignIn |
| CVE-2026-14028 | Incorrect security UI in Chrome for iOS |
| CVE-2026-14030 | Inappropriate implementation in SplitView |
| CVE-2026-14031 | Inappropriate implementation in File Input |
| CVE-2026-14032 | Use after free in Bluetooth |
| CVE-2026-14033 | Insufficient policy enforcement in Media |
| CVE-2026-14034 | Inappropriate implementation in WebXR |
| CVE-2026-14035 | Insufficient policy enforcement in Bluetooth |
| CVE-2026-14036 | Insufficient policy enforcement in Bluetooth |
| CVE-2026-14037 | Insufficient policy enforcement in GPU |
| CVE-2026-14038 | Insufficient validation of untrusted input in New Tab Page |
| CVE-2026-14039 | Insufficient policy enforcement in GetUserMedia |
| CVE-2026-14040 | Use after free in BrowserTag |
| CVE-2026-14041 | Insufficient policy enforcement in Serial |
| CVE-2026-14042 | Inappropriate implementation in Isolated Web Apps |
| CVE-2026-14043 | Use after free in GetUserMedia |
| CVE-2026-14044 | Use after free in ANGLE |
| CVE-2026-14045 | Insufficient validation of untrusted input in Network |
| CVE-2026-14046 | Inappropriate implementation in CustomTabs |
| CVE-2026-14047 | Insufficient policy enforcement in Extensions |
| CVE-2026-14048 | Use after free in Chromecast |
| CVE-2026-14049 | Inappropriate implementation in GPU |
| CVE-2026-14050 | Insufficient policy enforcement in Passwords |
| CVE-2026-14051 | Uninitialized Use in GamepadAPI |
| CVE-2026-14052 | Insufficient policy enforcement in FileSystem |
| CVE-2026-14053 | Insufficient policy enforcement in Extensions |
| CVE-2026-14054 | Insufficient policy enforcement in Network |
| CVE-2026-14055 | Insufficient validation of untrusted input in Device Trust |
| CVE-2026-14056 | Insufficient validation of untrusted input in Media |
| CVE-2026-14057 | Inappropriate implementation in FedCM |
| CVE-2026-14058 | Insufficient policy enforcement in Parser |
| CVE-2026-14059 | Insufficient policy enforcement in Related-Website-Sets |
| CVE-2026-14060 | Insufficient validation of untrusted input in Chromoting |
| CVE-2026-14061 | Inappropriate implementation in Dawn |
| CVE-2026-14062 | Inappropriate implementation in Views |
| CVE-2026-14063 | Out of bounds read in Chromecast |
| CVE-2026-14064 | Use after free in PageInfo |
| CVE-2026-14065 | Insufficient validation of untrusted input in PageInfo |
| CVE-2026-14066 | Insufficient validation of untrusted input in Chrome for iOS |
| CVE-2026-14067 | Use after free in Chrome for iOS |
| CVE-2026-14068 | Inappropriate implementation in Omnibox |
| CVE-2026-14069 | Integer overflow in WebNN |
| CVE-2026-14070 | Integer overflow in WebNN |
| CVE-2026-14071 | Side-channel information leakage in WebAudio |
| CVE-2026-14072 | Inappropriate implementation in SplitView |
| CVE-2026-14073 | Insufficient validation of untrusted input in WebXR |
| CVE-2026-14074 | Side-channel information leakage in WebAuthentication |
| CVE-2026-14075 | Insufficient policy enforcement in Chrome for iOS |
| CVE-2026-14076 | Insufficient policy enforcement in Network |
| CVE-2026-14077 | Inappropriate implementation in Select |
| CVE-2026-14078 | Insufficient validation of untrusted input in WebRTC |
| CVE-2026-14079 | Insufficient policy enforcement in Network |
| CVE-2026-14080 | Insufficient validation of untrusted input in TabSwitcher |
| CVE-2026-14081 | Insufficient policy enforcement in DevTools |
| CVE-2026-14082 | Race in Storage |
| CVE-2026-14083 | Insufficient validation of untrusted input in HTML |
| CVE-2026-14084 | Insufficient validation of untrusted input in Chromoting |
| CVE-2026-14085 | Side-channel information leakage in CSS |
| CVE-2026-14086 | Insufficient policy enforcement in HID |
| CVE-2026-14087 | Heap buffer overflow in WebNN |
| CVE-2026-14088 | Uninitialized Use in Canvas |
| CVE-2026-14089 | Insufficient validation of untrusted input in PopupBlocker |
| CVE-2026-14090 | Insufficient validation of untrusted input in CameraCapture |
| CVE-2026-14091 | Use after free in DevTools |
| CVE-2026-14092 | Insufficient policy enforcement in Privacy |
| CVE-2026-14093 | Use after free in Cast |
| CVE-2026-14094 | Use after free in Installer |
| CVE-2026-14095 | Insufficient policy enforcement in Browser |
| CVE-2026-14096 | Inappropriate implementation in Input |
| CVE-2026-14097 | Inappropriate implementation in WebAppInstalls |
| CVE-2026-14098 | Inappropriate implementation in CSS |
| CVE-2026-14099 | Use after free in Chrome for iOS |
| CVE-2026-14100 | Insufficient data validation in NetworkCache |
| CVE-2026-14101 | Insufficient policy enforcement in Sandbox |
| CVE-2026-14102 | Use after free in Passwords |
| CVE-2026-14103 | Use after free in SSL |
| CVE-2026-14104 | Insufficient validation of untrusted input in WebAppInstalls |
| CVE-2026-14105 | Insufficient policy enforcement in Speech |
| CVE-2026-14106 | Insufficient validation of untrusted input in Text |
| CVE-2026-14107 | Use after free in Scheduling |
| CVE-2026-14108 | Use after free in PDFium |
| CVE-2026-14109 | Insufficient policy enforcement in Mojo |
| CVE-2026-14110 | Inappropriate implementation in DarkMode |
| CVE-2026-14111 | Use after free in WebProtect |
| CVE-2026-14112 | Inappropriate implementation in Enterprise |
| CVE-2026-14113 | Use after free in Updater |
| CVE-2026-14114 | Inappropriate implementation in WebAppInstalls |
| CVE-2026-14115 | Insufficient validation of untrusted input in Cast |
| CVE-2026-14116 | Insufficient validation of untrusted input in DevTools |
| CVE-2026-14117 | Insufficient validation of untrusted input in DevTools |
| CVE-2026-14118 | Insufficient data validation in DevTools |
| CVE-2026-14119 | Type Confusion in Bluetooth |
| CVE-2026-14120 | Inappropriate implementation in DevTools |
| CVE-2026-14121 | Use after free in Chromoting |
| CVE-2026-14122 | Insufficient validation of untrusted input in WebAppInstalls |
| CVE-2026-14123 | Incorrect security UI in Chrome for iOS |
| CVE-2026-14124 | Inappropriate implementation in CredentialProvider |
| CVE-2026-14125 | Uninitialized Use in ANGLE |
| CVE-2026-14126 | Incorrect security UI in UI |
| CVE-2026-14127 | Inappropriate implementation in Printing |
| CVE-2026-14128 | Inappropriate implementation in Chrome for iOS |
| CVE-2026-14129 | Inappropriate implementation in PreviewTab |
| CVE-2026-14130 | Incorrect security UI in Omnibox |
| CVE-2026-14131 | Insufficient validation of untrusted input in WebAppInstalls |
| CVE-2026-14132 | Inappropriate implementation in WebXR |
| CVE-2026-14133 | Race in History Embeddings |
| CVE-2026-14134 | Inappropriate implementation in Autofill |
| CVE-2026-14135 | Insufficient validation of untrusted input in Network |
| CVE-2026-14136 | Insufficient validation of untrusted input in Chrome for iOS |
| CVE-2026-14137 | Insufficient validation of untrusted input in Chrome for iOS |
| CVE-2026-14138 | Inappropriate implementation in WebAppInstalls |
| CVE-2026-14139 | Inappropriate implementation in TabStrip |
| CVE-2026-14140 | Insufficient validation of untrusted input in Input |
| CVE-2026-14141 | Incorrect security UI in Document Picture-in-Picture |
| CVE-2026-14142 | Inappropriate implementation in Extensions |
| CVE-2026-14143 | Incorrect security UI in Passwords |
| CVE-2026-14144 | Incorrect security UI in Views |
| CVE-2026-14145 | Inappropriate implementation in CSS |
| CVE-2026-14146 | Inappropriate implementation in CSS |
| CVE-2026-14147 | Inappropriate implementation in CSS |
| CVE-2026-14148 | Type Confusion in CSS |
| CVE-2026-14149 | Use after free in Audio |
| CVE-2026-14150 | Insufficient validation of untrusted input in Speech |
| CVE-2026-14151 | Inappropriate implementation in AI |
| CVE-2026-14152 | Out of bounds read and write in ANGLE |
| CVE-2026-14153 | Inappropriate implementation in Glic |
| CVE-2026-14154 | Inappropriate implementation in DevTools |
| CVE-2026-14155 | Insufficient policy enforcement in StorageAccessAPI |
| CVE-2026-14156 | Insufficient policy enforcement in StorageAccessAPI |
| CVE-2026-15107 | Use after free in IndexedDB |
| CVE-2026-15108 | Integer overflow in Extensions API |
| CVE-2026-15109 | Uninitialized Use in ANGLE |
| CVE-2026-15110 | Use after free in Extensions |
| CVE-2026-15111 | Use after free in Views |
| CVE-2026-15112 | Use after free in Ozone |
| CVE-2026-15113 | Use after free in Autofill |
| CVE-2026-15114 | Out of bounds read and write in Codecs |
| CVE-2026-15115 | Insufficient validation of untrusted input in WebAppInstalls |
| CVE-2026-15116 | Use after free in Actor |
| CVE-2026-15117 | Use after free in Payments |
| CVE-2026-15118 | Use after free in Input |
| CVE-2026-15119 | Race in GetUserMedia |
| CVE-2026-15120 | Use after free in Core |
| CVE-2026-15121 | Use after free in WebRTC |
| CVE-2026-15122 | Insufficient validation of untrusted input in Codecs |
| CVE-2026-15123 | Inappropriate implementation in DOM |
| CVE-2026-15124 | Insufficient policy enforcement in Passwords |
| CVE-2026-15125 | Inappropriate implementation in Forms |
| CVE-2026-15126 | Use after free in Forms |
| CVE-2026-15127 | Inappropriate implementation in WebGL |
| CVE-2026-15128 | Inappropriate implementation in Forms |
| CVE-2026-15129 | Use after free in Views |
| CVE-2026-15130 | Insufficient policy enforcement in Navigation |
| CVE-2026-15131 | Inappropriate implementation in Navigation |
| CVE-2026-15132 | Uninitialized Use in V8 |
| CVE-2026-15133 | Use after free in InterestGroups |
| CVE-2026-15764 | Use after free in Ozone |
| CVE-2026-15765 | Use after free in Ozone |
| CVE-2026-15766 | Uninitialized Use in Skia |
| CVE-2026-15767 | Heap buffer overflow in libyuv |
| CVE-2026-15768 | Insufficient policy enforcement in HTML-in-Canvas |
| CVE-2026-15769 | Insufficient validation of untrusted input in Linux Toolkit Theming |
| CVE-2026-15770 | Uninitialized Use in V8 |
| CVE-2026-15771 | Insufficient validation of untrusted input in Media |
| CVE-2026-15772 | Use after free in GPU |
| CVE-2026-15773 | Use after free in Core |
| CVE-2026-15774 | Use after free in Skia |
| CVE-2026-15775 | Inappropriate implementation in V8 |
| CVE-2026-15776 | Inappropriate implementation in V8 |
| CVE-2026-15777 | Use after free in UI |
| CVE-2026-15778 | Insufficient validation of untrusted input in Navigation |
| CVE-2026-15899 | Use after free in CameraCapture |
| CVE-2026-15900 | Use after free in GPU |
| CVE-2026-15901 | Use after free in Network |
| CVE-2026-15902 | Use after free in Cast |
| CVE-2026-15903 | Out of bounds read and write in V8 |
| CVE-2026-15904 | Use after free in Ozone |
| CVE-2026-15905 | Use after free in Aura |
| CVE-2026-16413 | Out of bounds write in ANGLE |
| CVE-2026-16414 | Insufficient validation of untrusted input in Chromecast |
| CVE-2026-16415 | Insufficient validation of untrusted input in Extensions |
| CVE-2026-16416 | Integer overflow in Chromecast |
| CVE-2026-16417 | Uninitialized Use in Skia |
| CVE-2026-16418 | Stack buffer overflow in V8 |
| CVE-2026-16419 | Out of bounds read and write in ANGLE |
| CVE-2026-16420 | Type Confusion in WebAudio |
| CVE-2026-16421 | Inappropriate implementation in WebAudio |
| CVE-2026-16422 | Insufficient validation of untrusted input in Certificate |
| CVE-2026-16423 | Use after free in UI |
| CVE-2026-16424 | Use after free in GPU |
| CVE-2026-16804 | Use after free in Input |
| CVE-2026-16805 | Use after free in Blink |
| CVE-2026-16806 | Use after free in WebMCP |
| CVE-2026-16807 | Out of bounds write in Codecs |
| CVE-2026-0290 | Prisma Browser: Sensitive Information Disclosure Vulnerability in Prisma Browser |
| CVE-2026-0289 | Prisma Browser: Inappropriate Implementation in Account Protection |
Product Status
| Versions | Affected | Unaffected |
|---|---|---|
| Prisma Browser | < 148.18.4.217 | >= 150.49.8.187 |
Required Configuration for Exposure
No special configuration is required to be affected by this issue.
Severity: HIGH, Suggested Urgency: MODERATE
CVSS-BT: 7.2 / CVSS-B: 9.2 (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber)
Exploitation Status
Palo Alto Networks is not aware of any malicious exploitation of this issue.
Solution
| CVE | Prisma Browser |
|---|---|
| CVE-2026-13774 | 150.41.2.115 |
| CVE-2026-13775 | 150.41.2.115 |
| CVE-2026-13776 | 150.41.2.115 |
| CVE-2026-13777 | 150.41.2.115 |
| CVE-2026-13778 | 150.41.2.115 |
| CVE-2026-13779 | 150.41.2.115 |
| CVE-2026-13780 | 150.41.2.115 |
| CVE-2026-13781 | 150.41.2.115 |
| CVE-2026-13782 | 150.41.2.115 |
| CVE-2026-13783 | 150.41.2.115 |
| CVE-2026-13784 | 150.41.2.115 |
| CVE-2026-13785 | 150.41.2.115 |
| CVE-2026-13786 | 150.41.2.115 |
| CVE-2026-13787 | 150.41.2.115 |
| CVE-2026-13788 | 150.41.2.115 |
| CVE-2026-13789 | 150.41.2.115 |
| CVE-2026-13790 | 150.41.2.115 |
| CVE-2026-13791 | 150.41.2.115 |
| CVE-2026-13792 | 150.41.2.115 |
| CVE-2026-13793 | 150.41.2.115 |
| CVE-2026-13794 | 150.41.2.115 |
| CVE-2026-13795 | 150.41.2.115 |
| CVE-2026-13796 | 150.41.2.115 |
| CVE-2026-13797 | 150.41.2.115 |
| CVE-2026-13798 | 150.41.2.115 |
| CVE-2026-13799 | 150.41.2.115 |
| CVE-2026-13800 | 150.41.2.115 |
| CVE-2026-13801 | 150.41.2.115 |
| CVE-2026-13802 | 150.41.2.115 |
| CVE-2026-13803 | 150.41.2.115 |
| CVE-2026-13804 | 150.41.2.115 |
| CVE-2026-13805 | 150.41.2.115 |
| CVE-2026-13806 | 150.41.2.115 |
| CVE-2026-13807 | 150.41.2.115 |
| CVE-2026-13808 | 150.41.2.115 |
| CVE-2026-13809 | 150.41.2.115 |
| CVE-2026-13810 | 150.41.2.115 |
| CVE-2026-13811 | 150.41.2.115 |
| CVE-2026-13812 | 150.41.2.115 |
| CVE-2026-13813 | 150.41.2.115 |
| CVE-2026-13814 | 150.41.2.115 |
| CVE-2026-13815 | 150.41.2.115 |
| CVE-2026-13816 | 150.41.2.115 |
| CVE-2026-13817 | 150.41.2.115 |
| CVE-2026-13818 | 150.41.2.115 |
| CVE-2026-13819 | 150.41.2.115 |
| CVE-2026-13820 | 150.41.2.115 |
| CVE-2026-13821 | 150.41.2.115 |
| CVE-2026-13822 | 150.41.2.115 |
| CVE-2026-13823 | 150.41.2.115 |
| CVE-2026-13824 | 150.41.2.115 |
| CVE-2026-13825 | 150.41.2.115 |
| CVE-2026-13826 | 150.41.2.115 |
| CVE-2026-13827 | 150.41.2.115 |
| CVE-2026-13828 | 150.41.2.115 |
| CVE-2026-13829 | 150.41.2.115 |
| CVE-2026-13830 | 150.41.2.115 |
| CVE-2026-13831 | 150.41.2.115 |
| CVE-2026-13832 | 150.41.2.115 |
| CVE-2026-13833 | 150.41.2.115 |
| CVE-2026-13834 | 150.41.2.115 |
| CVE-2026-13835 | 150.41.2.115 |
| CVE-2026-13836 | 150.41.2.115 |
| CVE-2026-13837 | 150.41.2.115 |
| CVE-2026-13838 | 150.41.2.115 |
| CVE-2026-13839 | 150.41.2.115 |
| CVE-2026-13840 | 150.41.2.115 |
| CVE-2026-13841 | 150.41.2.115 |
| CVE-2026-13842 | 150.41.2.115 |
| CVE-2026-13843 | 150.41.2.115 |
| CVE-2026-13844 | 150.41.2.115 |
| CVE-2026-13845 | 150.41.2.115 |
| CVE-2026-13846 | 150.41.2.115 |
| CVE-2026-13847 | 150.41.2.115 |
| CVE-2026-13848 | 150.41.2.115 |
| CVE-2026-13849 | 150.41.2.115 |
| CVE-2026-13850 | 150.41.2.115 |
| CVE-2026-13851 | 150.41.2.115 |
| CVE-2026-13852 | 150.41.2.115 |
| CVE-2026-13853 | 150.41.2.115 |
| CVE-2026-13854 | 150.41.2.115 |
| CVE-2026-13855 | 150.41.2.115 |
| CVE-2026-13856 | 150.41.2.115 |
| CVE-2026-13857 | 150.41.2.115 |
| CVE-2026-13858 | 150.41.2.115 |
| CVE-2026-13859 | 150.41.2.115 |
| CVE-2026-13860 | 150.41.2.115 |
| CVE-2026-13861 | 150.41.2.115 |
| CVE-2026-13862 | 150.41.2.115 |
| CVE-2026-13863 | 150.41.2.115 |
| CVE-2026-13864 | 150.41.2.115 |
| CVE-2026-13865 | 150.41.2.115 |
| CVE-2026-13866 | 150.41.2.115 |
| CVE-2026-13867 | 150.41.2.115 |
| CVE-2026-13868 | 150.41.2.115 |
| CVE-2026-13869 | 150.41.2.115 |
| CVE-2026-13870 | 150.41.2.115 |
| CVE-2026-13871 | 150.41.2.115 |
| CVE-2026-13872 | 150.41.2.115 |
| CVE-2026-13873 | 150.41.2.115 |
| CVE-2026-13874 | 150.41.2.115 |
| CVE-2026-13875 | 150.41.2.115 |
| CVE-2026-13876 | 150.41.2.115 |
| CVE-2026-13877 | 150.41.2.115 |
| CVE-2026-13878 | 150.41.2.115 |
| CVE-2026-13879 | 150.41.2.115 |
| CVE-2026-13880 | 150.41.2.115 |
| CVE-2026-13881 | 150.41.2.115 |
| CVE-2026-13882 | 150.41.2.115 |
| CVE-2026-13883 | 150.41.2.115 |
| CVE-2026-13884 | 150.41.2.115 |
| CVE-2026-13885 | 150.41.2.115 |
| CVE-2026-13886 | 150.41.2.115 |
| CVE-2026-13887 | 150.41.2.115 |
| CVE-2026-13888 | 150.41.2.115 |
| CVE-2026-13889 | 150.41.2.115 |
| CVE-2026-13890 | 150.41.2.115 |
| CVE-2026-13891 | 150.41.2.115 |
| CVE-2026-13892 | 150.41.2.115 |
| CVE-2026-13893 | 150.41.2.115 |
| CVE-2026-13894 | 150.41.2.115 |
| CVE-2026-13895 | 150.41.2.115 |
| CVE-2026-13896 | 150.41.2.115 |
| CVE-2026-13897 | 150.41.2.115 |
| CVE-2026-13898 | 150.41.2.115 |
| CVE-2026-13899 | 150.41.2.115 |
| CVE-2026-13900 | 150.41.2.115 |
| CVE-2026-13901 | 150.41.2.115 |
| CVE-2026-13902 | 150.41.2.115 |
| CVE-2026-13903 | 150.41.2.115 |
| CVE-2026-13904 | 150.41.2.115 |
| CVE-2026-13905 | 150.41.2.115 |
| CVE-2026-13906 | 150.41.2.115 |
| CVE-2026-13907 | 150.41.2.115 |
| CVE-2026-13908 | 150.41.2.115 |
| CVE-2026-13909 | 150.41.2.115 |
| CVE-2026-13910 | 150.41.2.115 |
| CVE-2026-13911 | 150.41.2.115 |
| CVE-2026-13912 | 150.41.2.115 |
| CVE-2026-13913 | 150.41.2.115 |
| CVE-2026-13914 | 150.41.2.115 |
| CVE-2026-13915 | 150.41.2.115 |
| CVE-2026-13916 | 150.41.2.115 |
| CVE-2026-13917 | 150.41.2.115 |
| CVE-2026-13918 | 150.41.2.115 |
| CVE-2026-13919 | 150.41.2.115 |
| CVE-2026-13920 | 150.41.2.115 |
| CVE-2026-13921 | 150.41.2.115 |
| CVE-2026-13922 | 150.41.2.115 |
| CVE-2026-13923 | 150.41.2.115 |
| CVE-2026-13924 | 150.41.2.115 |
| CVE-2026-13925 | 150.41.2.115 |
| CVE-2026-13926 | 150.41.2.115 |
| CVE-2026-13927 | 150.41.2.115 |
| CVE-2026-13928 | 150.41.2.115 |
| CVE-2026-13929 | 150.41.2.115 |
| CVE-2026-13930 | 150.41.2.115 |
| CVE-2026-13931 | 150.41.2.115 |
| CVE-2026-13932 | 150.41.2.115 |
| CVE-2026-13933 | 150.41.2.115 |
| CVE-2026-13934 | 150.41.2.115 |
| CVE-2026-13935 | 150.41.2.115 |
| CVE-2026-13936 | 150.41.2.115 |
| CVE-2026-13937 | 150.41.2.115 |
| CVE-2026-13938 | 150.41.2.115 |
| CVE-2026-13939 | 150.41.2.115 |
| CVE-2026-13940 | 150.41.2.115 |
| CVE-2026-13941 | 150.41.2.115 |
| CVE-2026-13942 | 150.41.2.115 |
| CVE-2026-13943 | 150.41.2.115 |
| CVE-2026-13944 | 150.41.2.115 |
| CVE-2026-13945 | 150.41.2.115 |
| CVE-2026-13946 | 150.41.2.115 |
| CVE-2026-13947 | 150.41.2.115 |
| CVE-2026-13948 | 150.41.2.115 |
| CVE-2026-13949 | 150.41.2.115 |
| CVE-2026-13950 | 150.41.2.115 |
| CVE-2026-13951 | 150.41.2.115 |
| CVE-2026-13952 | 150.41.2.115 |
| CVE-2026-13953 | 150.41.2.115 |
| CVE-2026-13954 | 150.41.2.115 |
| CVE-2026-13955 | 150.41.2.115 |
| CVE-2026-13956 | 150.41.2.115 |
| CVE-2026-13957 | 150.41.2.115 |
| CVE-2026-13958 | 150.41.2.115 |
| CVE-2026-13959 | 150.41.2.115 |
| CVE-2026-13960 | 150.41.2.115 |
| CVE-2026-13961 | 150.41.2.115 |
| CVE-2026-13962 | 150.41.2.115 |
| CVE-2026-13963 | 150.41.2.115 |
| CVE-2026-13964 | 150.41.2.115 |
| CVE-2026-13965 | 150.41.2.115 |
| CVE-2026-13966 | 150.41.2.115 |
| CVE-2026-13967 | 150.41.2.115 |
| CVE-2026-13968 | 150.41.2.115 |
| CVE-2026-13969 | 150.41.2.115 |
| CVE-2026-13970 | 150.41.2.115 |
| CVE-2026-13971 | 150.41.2.115 |
| CVE-2026-13972 | 150.41.2.115 |
| CVE-2026-13973 | 150.41.2.115 |
| CVE-2026-13974 | 150.41.2.115 |
| CVE-2026-13975 | 150.41.2.115 |
| CVE-2026-13976 | 150.41.2.115 |
| CVE-2026-13977 | 150.41.2.115 |
| CVE-2026-13978 | 150.41.2.115 |
| CVE-2026-13979 | 150.41.2.115 |
| CVE-2026-13980 | 150.41.2.115 |
| CVE-2026-13981 | 150.41.2.115 |
| CVE-2026-13982 | 150.41.2.115 |
| CVE-2026-13983 | 150.41.2.115 |
| CVE-2026-13984 | 150.41.2.115 |
| CVE-2026-13985 | 150.41.2.115 |
| CVE-2026-13986 | 150.41.2.115 |
| CVE-2026-13987 | 150.41.2.115 |
| CVE-2026-13988 | 150.41.2.115 |
| CVE-2026-13989 | 150.41.2.115 |
| CVE-2026-13990 | 150.41.2.115 |
| CVE-2026-13991 | 150.41.2.115 |
| CVE-2026-13992 | 150.41.2.115 |
| CVE-2026-13993 | 150.41.2.115 |
| CVE-2026-13994 | 150.41.2.115 |
| CVE-2026-13995 | 150.41.2.115 |
| CVE-2026-13996 | 150.41.2.115 |
| CVE-2026-13997 | 150.41.2.115 |
| CVE-2026-13998 | 150.41.2.115 |
| CVE-2026-13999 | 150.41.2.115 |
| CVE-2026-14000 | 150.41.2.115 |
| CVE-2026-14001 | 150.41.2.115 |
| CVE-2026-14002 | 150.41.2.115 |
| CVE-2026-14003 | 150.41.2.115 |
| CVE-2026-14004 | 150.41.2.115 |
| CVE-2026-14005 | 150.41.2.115 |
| CVE-2026-14006 | 150.41.2.115 |
| CVE-2026-14007 | 150.41.2.115 |
| CVE-2026-14008 | 150.41.2.115 |
| CVE-2026-14009 | 150.41.2.115 |
| CVE-2026-14010 | 150.41.2.115 |
| CVE-2026-14011 | 150.41.2.115 |
| CVE-2026-14012 | 150.41.2.115 |
| CVE-2026-14013 | 150.41.2.115 |
| CVE-2026-14014 | 150.41.2.115 |
| CVE-2026-14015 | 150.41.2.115 |
| CVE-2026-14016 | 150.41.2.115 |
| CVE-2026-14017 | 150.41.2.115 |
| CVE-2026-14018 | 150.41.2.115 |
| CVE-2026-14019 | 150.41.2.115 |
| CVE-2026-14020 | 150.41.2.115 |
| CVE-2026-14021 | 150.41.2.115 |
| CVE-2026-14022 | 150.41.2.115 |
| CVE-2026-14023 | 150.41.2.115 |
| CVE-2026-14024 | 150.41.2.115 |
| CVE-2026-14025 | 150.41.2.115 |
| CVE-2026-14026 | 150.41.2.115 |
| CVE-2026-14027 | 150.41.2.115 |
| CVE-2026-14028 | 150.41.2.115 |
| CVE-2026-14030 | 150.41.2.115 |
| CVE-2026-14031 | 150.41.2.115 |
| CVE-2026-14032 | 150.41.2.115 |
| CVE-2026-14033 | 150.41.2.115 |
| CVE-2026-14034 | 150.41.2.115 |
| CVE-2026-14035 | 150.41.2.115 |
| CVE-2026-14036 | 150.41.2.115 |
| CVE-2026-14037 | 150.41.2.115 |
| CVE-2026-14038 | 150.41.2.115 |
| CVE-2026-14039 | 150.41.2.115 |
| CVE-2026-14040 | 150.41.2.115 |
| CVE-2026-14041 | 150.41.2.115 |
| CVE-2026-14042 | 150.41.2.115 |
| CVE-2026-14043 | 150.41.2.115 |
| CVE-2026-14044 | 150.41.2.115 |
| CVE-2026-14045 | 150.41.2.115 |
| CVE-2026-14046 | 150.41.2.115 |
| CVE-2026-14047 | 150.41.2.115 |
| CVE-2026-14048 | 150.41.2.115 |
| CVE-2026-14049 | 150.41.2.115 |
| CVE-2026-14050 | 150.41.2.115 |
| CVE-2026-14051 | 150.41.2.115 |
| CVE-2026-14052 | 150.41.2.115 |
| CVE-2026-14053 | 150.41.2.115 |
| CVE-2026-14054 | 150.41.2.115 |
| CVE-2026-14055 | 150.41.2.115 |
| CVE-2026-14056 | 150.41.2.115 |
| CVE-2026-14057 | 150.41.2.115 |
| CVE-2026-14058 | 150.41.2.115 |
| CVE-2026-14059 | 150.41.2.115 |
| CVE-2026-14060 | 150.41.2.115 |
| CVE-2026-14061 | 150.41.2.115 |
| CVE-2026-14062 | 150.41.2.115 |
| CVE-2026-14063 | 150.41.2.115 |
| CVE-2026-14064 | 150.41.2.115 |
| CVE-2026-14065 | 150.41.2.115 |
| CVE-2026-14066 | 150.41.2.115 |
| CVE-2026-14067 | 150.41.2.115 |
| CVE-2026-14068 | 150.41.2.115 |
| CVE-2026-14069 | 150.41.2.115 |
| CVE-2026-14070 | 150.41.2.115 |
| CVE-2026-14071 | 150.41.2.115 |
| CVE-2026-14072 | 150.41.2.115 |
| CVE-2026-14073 | 150.41.2.115 |
| CVE-2026-14074 | 150.41.2.115 |
| CVE-2026-14075 | 150.41.2.115 |
| CVE-2026-14076 | 150.41.2.115 |
| CVE-2026-14077 | 150.41.2.115 |
| CVE-2026-14078 | 150.41.2.115 |
| CVE-2026-14079 | 150.41.2.115 |
| CVE-2026-14080 | 150.41.2.115 |
| CVE-2026-14081 | 150.41.2.115 |
| CVE-2026-14082 | 150.41.2.115 |
| CVE-2026-14083 | 150.41.2.115 |
| CVE-2026-14084 | 150.41.2.115 |
| CVE-2026-14085 | 150.41.2.115 |
| CVE-2026-14086 | 150.41.2.115 |
| CVE-2026-14087 | 150.41.2.115 |
| CVE-2026-14088 | 150.41.2.115 |
| CVE-2026-14089 | 150.41.2.115 |
| CVE-2026-14090 | 150.41.2.115 |
| CVE-2026-14091 | 150.41.2.115 |
| CVE-2026-14092 | 150.41.2.115 |
| CVE-2026-14093 | 150.41.2.115 |
| CVE-2026-14094 | 150.41.2.115 |
| CVE-2026-14095 | 150.41.2.115 |
| CVE-2026-14096 | 150.41.2.115 |
| CVE-2026-14097 | 150.41.2.115 |
| CVE-2026-14098 | 150.41.2.115 |
| CVE-2026-14099 | 150.41.2.115 |
| CVE-2026-14100 | 150.41.2.115 |
| CVE-2026-14101 | 150.41.2.115 |
| CVE-2026-14102 | 150.41.2.115 |
| CVE-2026-14103 | 150.41.2.115 |
| CVE-2026-14104 | 150.41.2.115 |
| CVE-2026-14105 | 150.41.2.115 |
| CVE-2026-14106 | 150.41.2.115 |
| CVE-2026-14107 | 150.41.2.115 |
| CVE-2026-14108 | 150.41.2.115 |
| CVE-2026-14109 | 150.41.2.115 |
| CVE-2026-14110 | 150.41.2.115 |
| CVE-2026-14111 | 150.41.2.115 |
| CVE-2026-14112 | 150.41.2.115 |
| CVE-2026-14113 | 150.41.2.115 |
| CVE-2026-14114 | 150.41.2.115 |
| CVE-2026-14115 | 150.41.2.115 |
| CVE-2026-14116 | 150.41.2.115 |
| CVE-2026-14117 | 150.41.2.115 |
| CVE-2026-14118 | 150.41.2.115 |
| CVE-2026-14119 | 150.41.2.115 |
| CVE-2026-14120 | 150.41.2.115 |
| CVE-2026-14121 | 150.41.2.115 |
| CVE-2026-14122 | 150.41.2.115 |
| CVE-2026-14123 | 150.41.2.115 |
| CVE-2026-14124 | 150.41.2.115 |
| CVE-2026-14125 | 150.41.2.115 |
| CVE-2026-14126 | 150.41.2.115 |
| CVE-2026-14127 | 150.41.2.115 |
| CVE-2026-14128 | 150.41.2.115 |
| CVE-2026-14129 | 150.41.2.115 |
| CVE-2026-14130 | 150.41.2.115 |
| CVE-2026-14131 | 150.41.2.115 |
| CVE-2026-14132 | 150.41.2.115 |
| CVE-2026-14133 | 150.41.2.115 |
| CVE-2026-14134 | 150.41.2.115 |
| CVE-2026-14135 | 150.41.2.115 |
| CVE-2026-14136 | 150.41.2.115 |
| CVE-2026-14137 | 150.41.2.115 |
| CVE-2026-14138 | 150.41.2.115 |
| CVE-2026-14139 | 150.41.2.115 |
| CVE-2026-14140 | 150.41.2.115 |
| CVE-2026-14141 | 150.41.2.115 |
| CVE-2026-14142 | 150.41.2.115 |
| CVE-2026-14143 | 150.41.2.115 |
| CVE-2026-14144 | 150.41.2.115 |
| CVE-2026-14145 | 150.41.2.115 |
| CVE-2026-14146 | 150.41.2.115 |
| CVE-2026-14147 | 150.41.2.115 |
| CVE-2026-14148 | 150.41.2.115 |
| CVE-2026-14149 | 150.41.2.115 |
| CVE-2026-14150 | 150.41.2.115 |
| CVE-2026-14151 | 150.41.2.115 |
| CVE-2026-14152 | 150.41.2.115 |
| CVE-2026-14153 | 150.41.2.115 |
| CVE-2026-14154 | 150.41.2.115 |
| CVE-2026-14155 | 150.41.2.115 |
| CVE-2026-14156 | 150.41.2.115 |
| CVE-2026-15107 | 150.41.2.115 |
| CVE-2026-15108 | 150.41.2.115 |
| CVE-2026-15109 | 150.41.2.115 |
| CVE-2026-15110 | 150.41.2.115 |
| CVE-2026-15111 | 150.41.2.115 |
| CVE-2026-15112 | 150.41.2.115 |
| CVE-2026-15113 | 150.41.2.115 |
| CVE-2026-15114 | 150.41.2.115 |
| CVE-2026-15115 | 150.41.2.115 |
| CVE-2026-15116 | 150.41.2.115 |
| CVE-2026-15117 | 150.41.2.115 |
| CVE-2026-15118 | 150.41.2.115 |
| CVE-2026-15119 | 150.41.2.115 |
| CVE-2026-15120 | 150.41.2.115 |
| CVE-2026-15121 | 150.41.2.115 |
| CVE-2026-15122 | 150.41.2.115 |
| CVE-2026-15123 | 150.41.2.115 |
| CVE-2026-15124 | 150.41.2.115 |
| CVE-2026-15125 | 150.41.2.115 |
| CVE-2026-15126 | 150.41.2.115 |
| CVE-2026-15127 | 150.41.2.115 |
| CVE-2026-15128 | 150.41.2.115 |
| CVE-2026-15129 | 150.41.2.115 |
| CVE-2026-15130 | 150.41.2.115 |
| CVE-2026-15131 | 150.41.2.115 |
| CVE-2026-15132 | 150.41.2.115 |
| CVE-2026-15133 | 150.41.2.115 |
| CVE-2026-15764 | 150.49.4.125 |
| CVE-2026-15765 | 150.49.4.125 |
| CVE-2026-15766 | 150.49.4.125 |
| CVE-2026-15767 | 150.49.4.125 |
| CVE-2026-15768 | 150.49.4.125 |
| CVE-2026-15769 | 150.49.4.125 |
| CVE-2026-15770 | 150.49.4.125 |
| CVE-2026-15771 | 150.49.4.125 |
| CVE-2026-15772 | 150.49.4.125 |
| CVE-2026-15773 | 150.49.4.125 |
| CVE-2026-15774 | 150.49.4.125 |
| CVE-2026-15775 | 150.49.4.125 |
| CVE-2026-15776 | 150.49.4.125 |
| CVE-2026-15777 | 150.49.4.125 |
| CVE-2026-15778 | 150.49.4.125 |
| CVE-2026-15899 | 150.49.6.129 |
| CVE-2026-15900 | 150.49.6.129 |
| CVE-2026-15901 | 150.49.6.129 |
| CVE-2026-15902 | 150.49.6.129 |
| CVE-2026-15903 | 150.49.6.129 |
| CVE-2026-15904 | 150.49.6.129 |
| CVE-2026-15905 | 150.49.6.129 |
| CVE-2026-16413 | 150.49.7.182 |
| CVE-2026-16414 | 150.49.7.182 |
| CVE-2026-16415 | 150.49.7.182 |
| CVE-2026-16416 | 150.49.7.182 |
| CVE-2026-16417 | 150.49.7.182 |
| CVE-2026-16418 | 150.49.7.182 |
| CVE-2026-16419 | 150.49.7.182 |
| CVE-2026-16420 | 150.49.7.182 |
| CVE-2026-16421 | 150.49.7.182 |
| CVE-2026-16422 | 150.49.7.182 |
| CVE-2026-16423 | 150.49.7.182 |
| CVE-2026-16424 | 150.49.7.182 |
| CVE-2026-16804 | 150.49.8.187 |
| CVE-2026-16805 | 150.49.8.187 |
| CVE-2026-16806 | 150.49.8.187 |
| CVE-2026-16807 | 150.49.8.187 |
| CVE-2026-0290 | 148.18.4.217 |
| CVE-2026-0289 | 150.49.4.125 |
Workarounds and Mitigations
No known workarounds exist for this issue.
Acknowledgments
Palo Alto Networks thanks Thomas Villanueva for discovering and reporting CVE-2026-0290 and CVE-2026-0289.
CPE Applicability
- cpe:2.3:a:palo_alto_networks:prisma_browser:*:*:*:*:*:*:*:* is vulnerable from (including)150.49.8 and up to (excluding)150.49.8.187
Timeline
Initial Publication