CVE-2026-103621
- EPSS 0.18%
- Veröffentlicht 02.10.2026 16:16:43
- Zuletzt bearbeitet 05.10.2026 15:05:56
Integer overflow in Compositing in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
CVE-2026-103622
- EPSS 0.27%
- Veröffentlicht 02.10.2026 16:16:43
- Zuletzt bearbeitet 05.10.2026 15:06:37
Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-103623
- EPSS 0.22%
- Veröffentlicht 02.10.2026 16:16:43
- Zuletzt bearbeitet 06.10.2026 19:12:52
Use after free in MediaStream in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-103624
- EPSS 0.28%
- Veröffentlicht 02.10.2026 16:16:43
- Zuletzt bearbeitet 05.10.2026 15:06:56
Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium s...
CVE-2026-103625
- EPSS 0.29%
- Veröffentlicht 02.10.2026 16:16:43
- Zuletzt bearbeitet 05.10.2026 15:06:44
Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-103626
- EPSS 0.29%
- Veröffentlicht 02.10.2026 16:16:43
- Zuletzt bearbeitet 05.10.2026 15:06:29
Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security ...
CVE-2026-103627
- EPSS 0.17%
- Veröffentlicht 02.10.2026 16:16:43
- Zuletzt bearbeitet 06.10.2026 19:12:36
Information leak in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-103628
- EPSS 0.33%
- Veröffentlicht 02.10.2026 16:16:43
- Zuletzt bearbeitet 05.10.2026 15:06:49
Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-102305
- EPSS 0.21%
- Veröffentlicht 29.09.2026 19:45:07
- Zuletzt bearbeitet 30.09.2026 16:43:46
UI misrepresentation in SignIn in Google Chrome on on iOS prior to 154.0.8037.92 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-102314
- EPSS 0.21%
- Veröffentlicht 29.09.2026 19:45:07
- Zuletzt bearbeitet 30.09.2026 15:44:11
UI misrepresentation in TabStrip in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)