CVE-2026-79272
- EPSS 0.23%
- Veröffentlicht 25.08.2026 20:10:32
- Zuletzt bearbeitet 31.08.2026 15:46:25
Improper input validation in FindInPage in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-78953
- EPSS 0.35%
- Veröffentlicht 25.08.2026 20:10:31
- Zuletzt bearbeitet 19.09.2026 14:16:59
Missing authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: Medium)
CVE-2026-79002
- EPSS 0.38%
- Veröffentlicht 25.08.2026 20:10:31
- Zuletzt bearbeitet 28.08.2026 14:41:08
Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79214
- EPSS 0.24%
- Veröffentlicht 25.08.2026 20:10:31
- Zuletzt bearbeitet 28.08.2026 14:35:42
Improper input validation in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79228
- EPSS 0.27%
- Veröffentlicht 25.08.2026 20:10:31
- Zuletzt bearbeitet 28.08.2026 14:35:25
Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation into a privileged page via a crafted HTML page. (Chromium security severity: ...
CVE-2026-79229
- EPSS 0.29%
- Veröffentlicht 25.08.2026 20:10:31
- Zuletzt bearbeitet 31.08.2026 13:34:10
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-78912
- EPSS 0.22%
- Veröffentlicht 25.08.2026 20:10:30
- Zuletzt bearbeitet 28.08.2026 15:57:43
UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-78955
- EPSS 0.37%
- Veröffentlicht 25.08.2026 20:10:30
- Zuletzt bearbeitet 31.08.2026 18:58:41
Observable discrepancy in PerformanceAPIs in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-78967
- EPSS 0.38%
- Veröffentlicht 25.08.2026 20:10:30
- Zuletzt bearbeitet 31.08.2026 13:40:19
Missing authorization in BFCache in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79143
- EPSS 0.27%
- Veröffentlicht 25.08.2026 20:10:30
- Zuletzt bearbeitet 31.08.2026 16:53:12
Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)