CVE-2026-87601
- EPSS 0.18%
- Veröffentlicht 09.09.2026 00:10:06
- Zuletzt bearbeitet 10.09.2026 04:18:27
Race condition in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-87602
- EPSS 0.17%
- Veröffentlicht 09.09.2026 00:10:06
- Zuletzt bearbeitet 09.09.2026 20:22:25
Out of bounds read in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-87608
- EPSS 0.15%
- Veröffentlicht 09.09.2026 00:10:06
- Zuletzt bearbeitet 14.09.2026 21:43:36
Improper certificate validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)
CVE-2026-87461
- EPSS 0.16%
- Veröffentlicht 09.09.2026 00:10:05
- Zuletzt bearbeitet 09.09.2026 20:30:39
Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted Chrome extension. (Chromium security severity: Low)
CVE-2026-87469
- EPSS 0.22%
- Veröffentlicht 09.09.2026 00:10:05
- Zuletzt bearbeitet 15.09.2026 17:20:56
Improper input validation in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy into a privileged page via crafted network traffic. (Chromium security severity: Low)
CVE-2026-87473
- EPSS 0.27%
- Veröffentlicht 09.09.2026 00:10:05
- Zuletzt bearbeitet 15.09.2026 17:21:54
Incorrect authorization in FileHandling in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-87489
- EPSS 0.23%
- Veröffentlicht 09.09.2026 00:10:05
- Zuletzt bearbeitet 10.09.2026 04:18:21
Memory corruption in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)
CVE-2026-87575
- EPSS 0.17%
- Veröffentlicht 09.09.2026 00:10:05
- Zuletzt bearbeitet 14.09.2026 13:18:59
Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-87631
- EPSS 0.22%
- Veröffentlicht 09.09.2026 00:10:05
- Zuletzt bearbeitet 09.09.2026 17:28:51
Missing authorization in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-87490
- EPSS 0.21%
- Veröffentlicht 09.09.2026 00:10:04
- Zuletzt bearbeitet 09.09.2026 18:11:12
Information leak in Transactions Platform in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)