CVE-2026-87438
- EPSS 0.55%
- Veröffentlicht 09.09.2026 00:09:31
- Zuletzt bearbeitet 10.09.2026 04:18:18
Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-87512
- EPSS 0.49%
- Veröffentlicht 09.09.2026 00:09:31
- Zuletzt bearbeitet 10.09.2026 04:18:23
Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-87527
- EPSS 0.47%
- Veröffentlicht 09.09.2026 00:09:31
- Zuletzt bearbeitet 10.09.2026 04:18:23
Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-87585
- EPSS 0.28%
- Veröffentlicht 09.09.2026 00:09:31
- Zuletzt bearbeitet 10.09.2026 04:18:27
Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)
CVE-2026-87628
- EPSS 0.17%
- Veröffentlicht 09.09.2026 00:09:31
- Zuletzt bearbeitet 10.09.2026 04:18:29
Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Critical)
CVE-2026-87464
- EPSS 0.45%
- Veröffentlicht 09.09.2026 00:09:30
- Zuletzt bearbeitet 10.09.2026 17:17:06
Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-87488
- EPSS 0.49%
- Veröffentlicht 09.09.2026 00:09:30
- Zuletzt bearbeitet 10.09.2026 04:18:21
Use after free in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-85044
- EPSS 0.26%
- Veröffentlicht 03.09.2026 19:26:14
- Zuletzt bearbeitet 08.09.2026 16:20:21
Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-85047
- EPSS 0.35%
- Veröffentlicht 03.09.2026 19:26:14
- Zuletzt bearbeitet 08.09.2026 16:19:18
Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-85049
- EPSS 0.31%
- Veröffentlicht 03.09.2026 19:26:14
- Zuletzt bearbeitet 08.09.2026 16:18:44
Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)