CVE-2026-78966
- EPSS 0.43%
- Veröffentlicht 25.08.2026 20:10:14
- Zuletzt bearbeitet 28.08.2026 14:20:34
Externally controlled reference in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79010
- EPSS 0.66%
- Veröffentlicht 25.08.2026 20:10:14
- Zuletzt bearbeitet 28.08.2026 14:06:07
Operation on a resource after expiration or release in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity...
CVE-2026-79016
- EPSS 0.37%
- Veröffentlicht 25.08.2026 20:10:14
- Zuletzt bearbeitet 31.08.2026 15:03:23
Observable discrepancy in SVG in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79186
- EPSS 0.23%
- Veröffentlicht 25.08.2026 20:10:14
- Zuletzt bearbeitet 31.08.2026 18:59:43
Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79267
- EPSS 0.19%
- Veröffentlicht 25.08.2026 20:10:14
- Zuletzt bearbeitet 31.08.2026 16:50:43
Race condition in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79286
- EPSS 0.09%
- Veröffentlicht 25.08.2026 20:10:14
- Zuletzt bearbeitet 27.08.2026 04:17:58
Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a co-installed app. (Chromium security severity: Medium)
CVE-2026-78958
- EPSS 0.34%
- Veröffentlicht 25.08.2026 20:10:13
- Zuletzt bearbeitet 31.08.2026 18:59:04
Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-78961
- EPSS 0.34%
- Veröffentlicht 25.08.2026 20:10:13
- Zuletzt bearbeitet 28.08.2026 14:21:39
Incorrect authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severi...
CVE-2026-79106
- EPSS 0.24%
- Veröffentlicht 25.08.2026 20:10:13
- Zuletzt bearbeitet 31.08.2026 16:54:35
Improper input validation in Input in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security sev...
CVE-2026-79176
- EPSS 0.31%
- Veröffentlicht 25.08.2026 20:10:13
- Zuletzt bearbeitet 27.08.2026 17:48:34
UI misrepresentation in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium)