CVE-2026-87449
- EPSS 0.21%
- Veröffentlicht 09.09.2026 00:09:44
- Zuletzt bearbeitet 09.09.2026 20:29:53
Cross-site request forgery in DeviceBoundSessionCredentials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-87577
- EPSS 0.2%
- Veröffentlicht 09.09.2026 00:09:44
- Zuletzt bearbeitet 10.09.2026 13:49:30
Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-87590
- EPSS 0.19%
- Veröffentlicht 09.09.2026 00:09:44
- Zuletzt bearbeitet 11.09.2026 14:14:22
Improper input validation in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially leak sensitive information via crafted network traffic. (Chromium security severity: Medium)
- EPSS 0.35%
- Veröffentlicht 09.09.2026 00:09:44
- Zuletzt bearbeitet 10.09.2026 04:18:28
Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
CVE-2026-87630
- EPSS 0.25%
- Veröffentlicht 09.09.2026 00:09:44
- Zuletzt bearbeitet 10.09.2026 13:41:00
Integer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-87645
- EPSS 0.24%
- Veröffentlicht 09.09.2026 00:09:44
- Zuletzt bearbeitet 10.09.2026 19:17:38
Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-87466
- EPSS 0.26%
- Veröffentlicht 09.09.2026 00:09:43
- Zuletzt bearbeitet 09.09.2026 20:30:08
Incorrect authorization in Workers in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-87582
- EPSS 0.36%
- Veröffentlicht 09.09.2026 00:09:43
- Zuletzt bearbeitet 10.09.2026 04:18:27
Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity:...
CVE-2026-87603
- EPSS 0.18%
- Veröffentlicht 09.09.2026 00:09:43
- Zuletzt bearbeitet 11.09.2026 13:57:56
Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-87615
- EPSS 0.14%
- Veröffentlicht 09.09.2026 00:09:43
- Zuletzt bearbeitet 10.09.2026 13:43:36
Race condition in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)