CVE-2026-103625
- EPSS 0.29%
- Veröffentlicht 02.10.2026 16:16:43
- Zuletzt bearbeitet 05.10.2026 15:06:44
Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-103626
- EPSS 0.29%
- Veröffentlicht 02.10.2026 16:16:43
- Zuletzt bearbeitet 05.10.2026 15:06:29
Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security ...
CVE-2026-103627
- EPSS 0.17%
- Veröffentlicht 02.10.2026 16:16:43
- Zuletzt bearbeitet 06.10.2026 19:12:36
Information leak in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-103628
- EPSS 0.33%
- Veröffentlicht 02.10.2026 16:16:43
- Zuletzt bearbeitet 05.10.2026 15:06:49
Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-102305
- EPSS 0.21%
- Veröffentlicht 29.09.2026 19:45:07
- Zuletzt bearbeitet 30.09.2026 16:43:46
UI misrepresentation in SignIn in Google Chrome on on iOS prior to 154.0.8037.92 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-102314
- EPSS 0.21%
- Veröffentlicht 29.09.2026 19:45:07
- Zuletzt bearbeitet 30.09.2026 15:44:11
UI misrepresentation in TabStrip in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-102327
- EPSS 0.27%
- Veröffentlicht 29.09.2026 19:45:07
- Zuletzt bearbeitet 30.09.2026 13:15:30
Incorrect authorization in WebView in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium s...
CVE-2026-102330
- EPSS 0.23%
- Veröffentlicht 29.09.2026 19:45:07
- Zuletzt bearbeitet 30.09.2026 19:31:16
Incorrect authorization in SiteIsolation in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-102302
- EPSS 0.31%
- Veröffentlicht 29.09.2026 19:45:06
- Zuletzt bearbeitet 01.10.2026 17:27:56
Buffer overflow in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-102310
- EPSS 0.24%
- Veröffentlicht 29.09.2026 19:45:06
- Zuletzt bearbeitet 30.09.2026 21:09:52
Missing authorization in Payments in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)