You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cpe mapping
About this tag
The cpe mapping tag covers discussions about how Common Platform Enumeration (CPE) entries are assigned to vulnerabilities, particularly for Chromium-based browsers like Google Chrome on various platforms. Threads examine cases where NVD mappings may be incomplete or ambiguous, such as Chrome on Android vulnerabilities that lack platform-specific CPEs or Chromium flaws affecting multiple browsers and operating systems. The tag highlights challenges in asset management, vulnerability scanning, and SBOM correlation when CPE taxonomies do not cleanly fit modern browser ecosystems. Topics include CVE-2026-11097, CVE-2026-11263, and CVE-2026-8009, with a focus on practical implications for security teams.
CVE-2026-11097 is a medium-severity Chrome for Android WebView vulnerability published on June 4, 2026, affecting Google Chrome on Android before 149.0.7827.53 and allowing a remote attacker to leak cross-origin data through a crafted HTML page. The short answer is yes: the current...
CVE-2026-11263 is a low-severity Chromium WebAuthentication flaw affecting Google Chrome on Android before version 149.0.7827.53, published by NVD on June 4, 2026, and mapped by NIST on June 8 to Chrome running on Android. The short answer to the CPE question is: probably not. The interesting...
CVE-2026-8009 is a low-severity Chromium Cast vulnerability fixed in Google Chrome 148.0.7778.96 for Linux and 148.0.7778.96/97 for Windows and macOS, with NVD adding a Chrome application CPE constrained by Windows, Linux, and macOS platform CPEs on May 7, 2026. The answer to the narrow CPE...