Nixpkgs Security Tracker

Login with GitHub

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
updated 1 month ago by @emilylange Activity log
  • Created automatic suggestion
  • @emilylange dismissed
Insufficient policy enforcement in Omnibox in Google Chrome prior to …

Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

References

Affected products

Chrome
  • <79.0.3945.79

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin
Old CVE, long fixed
updated 1 month ago by @emilylange Activity log
  • Created automatic suggestion
  • @emilylange dismissed
Inappropriate implementation in navigation in Google Chrome on iOS prior …

Inappropriate implementation in navigation in Google Chrome on iOS prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

References

Affected products

Chrome
  • <78.0.3904.70

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin
Old CVE, long fixed, iOS-only
updated 1 month ago by @emilylange Activity log
  • Created automatic suggestion
  • @emilylange dismissed
Insufficient policy enforcement in audio in Google Chrome prior to …

Insufficient policy enforcement in audio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

References

Affected products

Chrome
  • <79.0.3945.79

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin
Old CVE, long fixed
updated 1 month ago by @emilylange Activity log
  • Created automatic suggestion
  • @emilylange dismissed
Use-after-free in WebAudio in Google Chrome prior to 79.0.3945.79 allowed …

Use-after-free in WebAudio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

References

Affected products

Chrome
  • <79.0.3945.79

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin
Old CVE, long fixed
updated 1 month ago by @emilylange Activity log
  • Created automatic suggestion
  • @emilylange dismissed
Insufficient policy enforcement in JavaScript in Google Chrome prior to …

Insufficient policy enforcement in JavaScript in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

References

Affected products

Chrome
  • <78.0.3904.70

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin
Old CVE, long fixed
updated 1 month ago by @emilylange Activity log
  • Created automatic suggestion
  • @emilylange dismissed
Insufficient policy enforcement in navigation in Google Chrome prior to …

Insufficient policy enforcement in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass content security policy via a crafted HTML page.

References

Affected products

Chrome
  • <78.0.3904.70

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin
Old CVE, long fixed
updated 1 month ago by @emilylange Activity log
  • Created automatic suggestion
  • @emilylange dismissed
Insufficient policy enforcement in extensions in Google Chrome prior to …

Insufficient policy enforcement in extensions in Google Chrome prior to 78.0.3904.70 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension.

References

Affected products

Chrome
  • <78.0.3904.70

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin
Old CVE, long fixed
updated 1 month ago by @emilylange Activity log
  • Created automatic suggestion
  • @emilylange dismissed
Out of bounds write in SQLite in Google Chrome prior …

Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

References

Affected products

Chrome
  • <79.0.3945.79

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin
Old CVE, long fixed
updated 1 month ago by @emilylange Activity log
  • Created automatic suggestion
  • @emilylange dismissed
Integer overflow in PDFium in Google Chrome prior to 79.0.3945.79 …

Integer overflow in PDFium in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

References

Affected products

Chrome
  • <79.0.3945.79

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin
Old CVE, long fixed
updated 1 month ago by @emilylange Activity log
  • Created automatic suggestion
  • @emilylange dismissed
Insufficient policy enforcement in JavaScript in Google Chrome prior to …

Insufficient policy enforcement in JavaScript in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

References

Affected products

Chrome
  • <78.0.3904.70

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin
Old CVE, long fixed