CVE-2026-85050
- EPSS 0.35%
- Veröffentlicht 03.09.2026 19:26:13
- Zuletzt bearbeitet 08.09.2026 16:18:19
Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-85053
- EPSS 0.31%
- Veröffentlicht 03.09.2026 19:26:13
- Zuletzt bearbeitet 08.09.2026 16:17:19
Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-85043
- EPSS 0.32%
- Veröffentlicht 03.09.2026 19:26:12
- Zuletzt bearbeitet 08.09.2026 16:27:14
Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: High)
CVE-2026-85046
- EPSS 0.89%
- Veröffentlicht 03.09.2026 19:26:12
- Zuletzt bearbeitet 21.09.2026 13:17:10
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-85052
- EPSS 0.2%
- Veröffentlicht 03.09.2026 19:26:12
- Zuletzt bearbeitet 08.09.2026 16:17:47
Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-84331
- EPSS 0.16%
- Veröffentlicht 01.09.2026 23:42:30
- Zuletzt bearbeitet 03.09.2026 17:10:37
Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-84350
- EPSS 0.21%
- Veröffentlicht 01.09.2026 23:42:30
- Zuletzt bearbeitet 03.09.2026 17:37:49
Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Low)
CVE-2026-84356
- EPSS 0.14%
- Veröffentlicht 01.09.2026 23:42:30
- Zuletzt bearbeitet 03.09.2026 17:25:55
UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-84327
- EPSS 0.18%
- Veröffentlicht 01.09.2026 23:42:29
- Zuletzt bearbeitet 08.09.2026 17:56:03
Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-84329
- EPSS 0.16%
- Veröffentlicht 01.09.2026 23:42:29
- Zuletzt bearbeitet 03.09.2026 17:11:25
Confused deputy in CredentialProvider in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)