CVE-2026-87628
- EPSS 0.17%
- Veröffentlicht 09.09.2026 00:09:31
- Zuletzt bearbeitet 10.09.2026 04:18:29
Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Critical)
CVE-2026-87464
- EPSS 0.45%
- Veröffentlicht 09.09.2026 00:09:30
- Zuletzt bearbeitet 10.09.2026 17:17:06
Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-87488
- EPSS 0.49%
- Veröffentlicht 09.09.2026 00:09:30
- Zuletzt bearbeitet 10.09.2026 04:18:21
Use after free in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-85044
- EPSS 0.26%
- Veröffentlicht 03.09.2026 19:26:14
- Zuletzt bearbeitet 08.09.2026 16:20:21
Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-85047
- EPSS 0.35%
- Veröffentlicht 03.09.2026 19:26:14
- Zuletzt bearbeitet 08.09.2026 16:19:18
Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-85049
- EPSS 0.31%
- Veröffentlicht 03.09.2026 19:26:14
- Zuletzt bearbeitet 08.09.2026 16:18:44
Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-85051
- EPSS 0.34%
- Veröffentlicht 03.09.2026 19:26:14
- Zuletzt bearbeitet 08.09.2026 16:18:03
Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-85042
- EPSS 0.35%
- Veröffentlicht 03.09.2026 19:26:13
- Zuletzt bearbeitet 08.09.2026 16:27:28
Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-85045
- EPSS 0.24%
- Veröffentlicht 03.09.2026 19:26:13
- Zuletzt bearbeitet 08.09.2026 16:19:32
Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-85048
- EPSS 0.33%
- Veröffentlicht 03.09.2026 19:26:13
- Zuletzt bearbeitet 08.09.2026 16:19:00
Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)