CVE-2026-95297
- EPSS 0.31%
- Veröffentlicht 29.09.2026 17:31:45
- Zuletzt bearbeitet 01.10.2026 15:07:23
Missing authorization in Contextual Tasks in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-95302
- EPSS 0.11%
- Veröffentlicht 29.09.2026 17:31:45
- Zuletzt bearbeitet 30.09.2026 15:03:06
Incorrect authorization in WebAPKs in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to obtain cross-origin data via a co-installed app. (Chromium security severity: Medium)
CVE-2026-95331
- EPSS 0.46%
- Veröffentlicht 29.09.2026 17:31:45
- Zuletzt bearbeitet 30.09.2026 16:28:12
Out of bounds write in ANGLE in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-95375
- EPSS 0.21%
- Veröffentlicht 29.09.2026 17:31:45
- Zuletzt bearbeitet 01.10.2026 14:07:03
Incorrect authorization in BrowserTag in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-95287
- EPSS 0.22%
- Veröffentlicht 29.09.2026 17:31:44
- Zuletzt bearbeitet 30.09.2026 16:30:35
Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-95366
- EPSS 0.3%
- Veröffentlicht 29.09.2026 17:31:44
- Zuletzt bearbeitet 01.10.2026 14:21:30
Use of released resource in Core in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-95381
- EPSS 0.4%
- Veröffentlicht 29.09.2026 17:31:44
- Zuletzt bearbeitet 02.10.2026 15:12:59
Improper input validation in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security sev...
CVE-2026-95382
- EPSS 0.28%
- Veröffentlicht 29.09.2026 17:31:44
- Zuletzt bearbeitet 02.10.2026 15:12:44
Improper input validation in Auth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security ...
CVE-2026-95299
- EPSS 0.46%
- Veröffentlicht 29.09.2026 17:31:43
- Zuletzt bearbeitet 30.09.2026 19:52:52
Use after free in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-95304
- EPSS 0.41%
- Veröffentlicht 29.09.2026 17:31:43
- Zuletzt bearbeitet 30.09.2026 19:51:21
Out of bounds write in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)