CVE-2026-95353
- EPSS 0.41%
- Veröffentlicht 29.09.2026 17:31:50
- Zuletzt bearbeitet 30.09.2026 16:26:36
Use after free in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-95363
- EPSS 0.23%
- Veröffentlicht 29.09.2026 17:31:50
- Zuletzt bearbeitet 02.10.2026 13:34:14
UI misrepresentation in FileSystem in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-95371
- EPSS 0.21%
- Veröffentlicht 29.09.2026 17:31:50
- Zuletzt bearbeitet 30.09.2026 20:29:20
Missing authorization in Views in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security seve...
CVE-2026-95276
- EPSS 0.47%
- Veröffentlicht 29.09.2026 17:31:49
- Zuletzt bearbeitet 30.09.2026 16:33:18
Improper input validation in Themes in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code inside the sandbox via crafted network traffic. (Chromium security se...
CVE-2026-95295
- EPSS 0.12%
- Veröffentlicht 29.09.2026 17:31:49
- Zuletzt bearbeitet 01.10.2026 17:29:54
Information leak in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a local attacker to leak sensitive information via physical access. (Chromium security severity: Medium)
CVE-2026-95314
- EPSS 0.22%
- Veröffentlicht 29.09.2026 17:31:49
- Zuletzt bearbeitet 02.10.2026 19:57:12
Incorrect authorization in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-95360
- EPSS 0.21%
- Veröffentlicht 29.09.2026 17:31:49
- Zuletzt bearbeitet 02.10.2026 13:43:31
Race condition in Editing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-95303
- EPSS 0.25%
- Veröffentlicht 29.09.2026 17:31:48
- Zuletzt bearbeitet 02.10.2026 19:51:21
Incomplete cleanup in SmartCard in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-95317
- EPSS 0.21%
- Veröffentlicht 29.09.2026 17:31:48
- Zuletzt bearbeitet 30.09.2026 16:29:27
Incorrect authorization in MediaCapture in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)
CVE-2026-95330
- EPSS 0.31%
- Veröffentlicht 29.09.2026 17:31:48
- Zuletzt bearbeitet 01.10.2026 17:29:28
Improper state validation in Downloads in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)