CVE-2026-95359
- EPSS 0.25%
- Veröffentlicht 29.09.2026 17:31:46
- Zuletzt bearbeitet 30.09.2026 14:04:47
Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-95362
- EPSS 0.2%
- Veröffentlicht 29.09.2026 17:31:46
- Zuletzt bearbeitet 01.10.2026 13:57:14
Cross-site request forgery in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-95369
- EPSS 0.37%
- Veröffentlicht 29.09.2026 17:31:46
- Zuletzt bearbeitet 01.10.2026 13:56:47
Inappropriate implementation in XML in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- EPSS 0.17%
- Veröffentlicht 29.09.2026 17:31:46
- Zuletzt bearbeitet 01.10.2026 14:05:52
Externally controlled reference in DevTools in Google Chrome prior to 154.0.8037.57 allowed an adjacent attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)
CVE-2026-95297
- EPSS 0.31%
- Veröffentlicht 29.09.2026 17:31:45
- Zuletzt bearbeitet 01.10.2026 15:07:23
Missing authorization in Contextual Tasks in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-95302
- EPSS 0.11%
- Veröffentlicht 29.09.2026 17:31:45
- Zuletzt bearbeitet 30.09.2026 15:03:06
Incorrect authorization in WebAPKs in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to obtain cross-origin data via a co-installed app. (Chromium security severity: Medium)
CVE-2026-95331
- EPSS 0.46%
- Veröffentlicht 29.09.2026 17:31:45
- Zuletzt bearbeitet 30.09.2026 16:28:12
Out of bounds write in ANGLE in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-95375
- EPSS 0.21%
- Veröffentlicht 29.09.2026 17:31:45
- Zuletzt bearbeitet 01.10.2026 14:07:03
Incorrect authorization in BrowserTag in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-95287
- EPSS 0.22%
- Veröffentlicht 29.09.2026 17:31:44
- Zuletzt bearbeitet 30.09.2026 16:30:35
Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-95366
- EPSS 0.3%
- Veröffentlicht 29.09.2026 17:31:44
- Zuletzt bearbeitet 01.10.2026 14:21:30
Use of released resource in Core in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)