CVE-2026-95324
- EPSS 0.25%
- Veröffentlicht 29.09.2026 17:31:39
- Zuletzt bearbeitet 30.09.2026 16:28:31
Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-95372
- EPSS 0.38%
- Veröffentlicht 29.09.2026 17:31:39
- Zuletzt bearbeitet 02.10.2026 13:19:21
Use after free in Chromecast in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Hi...
CVE-2026-95291
- EPSS 0.26%
- Veröffentlicht 29.09.2026 17:31:38
- Zuletzt bearbeitet 30.09.2026 16:30:12
UI misrepresentation in SecurityIndicators in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: High)
CVE-2026-95298
- EPSS 0.17%
- Veröffentlicht 29.09.2026 17:31:38
- Zuletzt bearbeitet 30.09.2026 19:54:19
Use after free in Browser in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)
CVE-2026-95315
- EPSS 0.14%
- Veröffentlicht 29.09.2026 17:31:38
- Zuletzt bearbeitet 30.09.2026 16:29:40
Use after free in Aura in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)
CVE-2026-95355
- EPSS 0.39%
- Veröffentlicht 29.09.2026 17:31:38
- Zuletzt bearbeitet 30.09.2026 16:26:19
Incorrect authorization in Navigation in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium se...
CVE-2026-95301
- EPSS 0.3%
- Veröffentlicht 29.09.2026 17:31:37
- Zuletzt bearbeitet 01.10.2026 15:06:48
Missing authorization in Extensions in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
CVE-2026-95310
- EPSS 0.46%
- Veröffentlicht 29.09.2026 17:31:37
- Zuletzt bearbeitet 30.09.2026 20:30:00
Use after free in AdFilter in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-95329
- EPSS 0.46%
- Veröffentlicht 29.09.2026 17:31:37
- Zuletzt bearbeitet 30.09.2026 14:59:03
Out of bounds write in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-95356
- EPSS 0.46%
- Veröffentlicht 29.09.2026 17:31:37
- Zuletzt bearbeitet 30.09.2026 16:25:44
Use after free in WindowDialog in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)