CVE-2026-91721
- EPSS 0.34%
- Veröffentlicht 15.09.2026 20:41:26
- Zuletzt bearbeitet 17.09.2026 13:38:44
Use after free in Internals in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-91749
- EPSS 0.33%
- Veröffentlicht 15.09.2026 20:41:26
- Zuletzt bearbeitet 24.09.2026 14:12:37
Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-91726
- EPSS 0.24%
- Veröffentlicht 15.09.2026 20:41:25
- Zuletzt bearbeitet 17.09.2026 17:53:45
Out of bounds read in WebGL in Google Chrome on on Android prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-87430
- EPSS 0.51%
- Veröffentlicht 09.09.2026 00:10:07
- Zuletzt bearbeitet 10.09.2026 04:18:18
Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-87544
- EPSS 0.17%
- Veröffentlicht 09.09.2026 00:10:07
- Zuletzt bearbeitet 18.09.2026 14:19:01
Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-87593
- EPSS 0.21%
- Veröffentlicht 09.09.2026 00:10:07
- Zuletzt bearbeitet 09.09.2026 17:48:16
Information leak in Editing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-87437
- EPSS 0.29%
- Veröffentlicht 09.09.2026 00:10:06
- Zuletzt bearbeitet 09.09.2026 16:36:22
Information leak in Frames in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-87477
- EPSS 0.29%
- Veröffentlicht 09.09.2026 00:10:06
- Zuletzt bearbeitet 09.09.2026 17:15:26
Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-87551
- EPSS 0.18%
- Veröffentlicht 09.09.2026 00:10:06
- Zuletzt bearbeitet 14.09.2026 13:18:58
Improper certificate validation in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)
CVE-2026-87571
- EPSS 0.13%
- Veröffentlicht 09.09.2026 00:10:06
- Zuletzt bearbeitet 14.09.2026 13:18:58
Improper certificate validation in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)