CVE-2026-95380
- EPSS 0.4%
- Veröffentlicht 29.09.2026 17:31:59
- Zuletzt bearbeitet 02.10.2026 15:13:11
Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-95319
- EPSS 0.41%
- Veröffentlicht 29.09.2026 17:31:58
- Zuletzt bearbeitet 30.09.2026 16:29:15
Use after free in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-95326
- EPSS 0.25%
- Veröffentlicht 29.09.2026 17:31:58
- Zuletzt bearbeitet 02.10.2026 20:00:10
Incomplete cleanup in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-95368
- EPSS 0.22%
- Veröffentlicht 29.09.2026 17:31:58
- Zuletzt bearbeitet 01.10.2026 13:56:52
Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-95385
- EPSS 0.23%
- Veröffentlicht 29.09.2026 17:31:58
- Zuletzt bearbeitet 02.10.2026 15:12:16
Inappropriate implementation in PlatformIntegration in Google Chrome on on Windows prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severit...
CVE-2026-95279
- EPSS 0.26%
- Veröffentlicht 29.09.2026 17:31:57
- Zuletzt bearbeitet 30.09.2026 15:08:26
UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-95292
- EPSS 0.21%
- Veröffentlicht 29.09.2026 17:31:57
- Zuletzt bearbeitet 30.09.2026 16:30:03
Incorrect authorization in Safebrowsing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: Low)
CVE-2026-95308
- EPSS 0.23%
- Veröffentlicht 29.09.2026 17:31:57
- Zuletzt bearbeitet 30.09.2026 20:18:53
Integer overflow in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-95352
- EPSS 0.21%
- Veröffentlicht 29.09.2026 17:31:57
- Zuletzt bearbeitet 30.09.2026 16:26:43
Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Low)
CVE-2026-95367
- EPSS 0.26%
- Veröffentlicht 29.09.2026 17:31:57
- Zuletzt bearbeitet 01.10.2026 13:56:56
Information leak in DataTransfer in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security s...