CVE-2026-87630
- EPSS 0.25%
- Veröffentlicht 09.09.2026 00:09:44
- Zuletzt bearbeitet 10.09.2026 13:41:00
Integer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-87645
- EPSS 0.24%
- Veröffentlicht 09.09.2026 00:09:44
- Zuletzt bearbeitet 10.09.2026 19:17:38
Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-87466
- EPSS 0.26%
- Veröffentlicht 09.09.2026 00:09:43
- Zuletzt bearbeitet 09.09.2026 20:30:08
Incorrect authorization in Workers in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-87582
- EPSS 0.36%
- Veröffentlicht 09.09.2026 00:09:43
- Zuletzt bearbeitet 10.09.2026 04:18:27
Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity:...
CVE-2026-87603
- EPSS 0.18%
- Veröffentlicht 09.09.2026 00:09:43
- Zuletzt bearbeitet 11.09.2026 13:57:56
Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-87615
- EPSS 0.14%
- Veröffentlicht 09.09.2026 00:09:43
- Zuletzt bearbeitet 10.09.2026 13:43:36
Race condition in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-87642
- EPSS 0.25%
- Veröffentlicht 09.09.2026 00:09:43
- Zuletzt bearbeitet 09.09.2026 19:12:24
Uninitialized resource in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-87652
- EPSS 0.22%
- Veröffentlicht 09.09.2026 00:09:43
- Zuletzt bearbeitet 09.09.2026 19:11:58
Incorrect authorization in PushAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-87471
- EPSS 0.29%
- Veröffentlicht 09.09.2026 00:09:42
- Zuletzt bearbeitet 10.09.2026 20:52:49
Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-87481
- EPSS 0.35%
- Veröffentlicht 09.09.2026 00:09:42
- Zuletzt bearbeitet 10.09.2026 04:18:21
Incorrect authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium s...