VendorsYandexyandex_browserall versions
Vulnerabilities

Yandex Yandex Browser

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

22CVEs
CVE-2023-26226
A use after free memory corruption issue exists in Yandex Browser for Desktop prior to version 24.4.0.682
Published 2025-05-30 · Analyzed
9.8EPSS 0.004
CVE-2024-6473
DLL Hijacking in Yandex Browser
Published 2024-09-03 · Analyzed
8.4EPSS 0.007
CVE-2021-25255
Yandex Browser Lite for Android prior to version 21.1.0 allows remote attackers to cause a denial of service.
Published 2025-05-21 · Analyzed
8.3EPSS 0.008
CVE-2021-25254
Yandex Browser Lite for Android before 21.1.0 allows remote attackers to spoof the address bar.
Published 2025-05-21 · Analyzed
8.2EPSS 0.005
CVE-2017-7327
Yandex Browser installer for Desktop before 17.4.1 has a DLL Hijacking Vulnerability because an untrusted search path is used for dnsapi.dll, winmm.dll, ntmarta.dll, cryptbase.dll or profapi.dll.
Published 2018-01-19 · Modified
7.8EPSS 0.014
CVE-2021-25261
Local privilege vulnerability in Yandex Browser for Windows prior to 22.5.0.862 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating symlinks to installation file during Yandex Browser update process.
Published 2022-06-15 · Modified
7.8EPSS 0.005
CVE-2022-28225
Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.684 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating symlinks to installation file during Yandex Browser update process.
Published 2022-06-15 · Modified
7.8EPSS 0.005
CVE-2021-25263
Local privilege vulnerability in Yandex Browser for Windows prior to 21.9.0.390 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating files in directory with insecure permissions during Yandex Browser update process.
Published 2021-08-17 · Modified
7.8EPSS 0.004
CVE-2022-28226
Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.801 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating temporary files in directory with insecure permissions during Yandex Browser update process.
Published 2022-06-15 · Modified
7.8EPSS 0.004
CVE-2017-7325
Yandex Browser before 16.9.0 allows remote attackers to spoof the address bar via window.open.
Published 2018-01-19 · Modified
7.5EPSS 0.011
CVE-2017-7326
Race condition issue in Yandex Browser for Android before 17.4.0.16 allowed a remote attacker to potentially exploit memory corruption via a crafted HTML page
Published 2018-01-19 · Modified
7.5EPSS 0.008
CVE-2020-27969
Yandex Browser for Android 20.8.4 allows remote attackers to perform SOP bypass and addresss bar spoofing
Published 2021-09-13 · Modified
7.5EPSS 0.005
CVE-2016-8503
Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 16.7 to 16.9 could be used by remote attacker for brute-forcing passwords from important web-resource with special JavaScript.
Published 2016-10-26 · Modified
7.3EPSS 0.010
CVE-2016-8502
Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 15.12.0 to 16.2 could be used by remote attacker for brute-forcing passwords from important web-resource with special JavaScript.
Published 2016-10-26 · Modified
7.3EPSS 0.010
CVE-2021-25262
Yandex Browser for Android prior to version 21.3.0 allows remote attackers to perform IDN homograph attack.
Published 2025-05-21 · Analyzed
6.9EPSS 0.004
CVE-2016-8508
Yandex Browser for desktop before 17.1.1.227 does not show Protect (similar to Safebrowsing in Chromium) warnings in web-sites with special content-type, which could be used by remote attacker for prevention Protect warning on own malicious web-site.
Published 2017-03-01 · Modified
6.5EPSS 0.016
CVE-2016-8507
Yandex Browser for iOS before 16.10.0.2357 does not properly restrict processing of facetime:// URLs, which allows remote attackers to initiate facetime-call without user's approval and obtain video and audio data from a device via a crafted web site.
Published 2017-03-01 · Modified
6.5EPSS 0.015
CVE-2016-8506
XSS in Yandex Browser Translator in Yandex browser for desktop for versions from 15.12 to 16.2 could be used by remote attacker for evaluation arbitrary javascript code.
Published 2016-10-26 · Modified
6.1EPSS 0.009
CVE-2020-27970
Yandex Browser before 20.10.0 allows remote attackers to spoof the address bar
Published 2021-09-13 · Modified
5.3EPSS 0.013
CVE-2016-8501
Security WiFi bypass in Yandex Browser from version 15.10 to 15.12 allows remote attacker to sniff traffic in open or WEP-protected wi-fi networks despite of special security mechanism is enabled.
Published 2016-10-26 · Modified
5.3EPSS 0.013
CVE-2020-7369
Yandex Browser Address Bar Spooofing
Published 2020-10-20 · Modified
4.3EPSS 0.010
CVE-2016-8504
CSRF of synchronization form in Yandex Browser for desktop before version 16.6 could be used by remote attacker to steal saved data in browser profile.
Published 2016-10-26 · Modified
4.3EPSS 0.006