CVE Feed

    Dashboard / CVE

    9.6
    Critical

    CVE-2026-87637

    Last Modified: 9 Sept 2026

    Use after free in Extensions in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    3.1
    Low

    CVE-2026-87531

    Last Modified: 9 Sept 2026

    Information leak in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    5.3
    Medium

    CVE-2026-87435

    Last Modified: 9 Sept 2026

    Information leak in ControlledFrame in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    8.3
    High

    CVE-2026-87510

    Last Modified: 9 Sept 2026

    Improper input validation in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    4.3
    Medium

    CVE-2026-87563

    Last Modified: 9 Sept 2026

    Origin validation error in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    8.8
    High

    CVE-2026-87625

    Last Modified: 9 Sept 2026

    Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    6.5
    Medium

    CVE-2026-87493

    Last Modified: 11 Sept 2026

    Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    7.5
    High

    CVE-2026-87431

    Last Modified: 10 Sept 2026

    Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    6.5
    Medium

    CVE-2026-87468

    Last Modified: 11 Sept 2026

    Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    4.2
    Medium

    CVE-2026-87641

    Last Modified: 10 Sept 2026

    Race condition in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    8.1
    High

    CVE-2026-87533

    Last Modified: 10 Sept 2026

    Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    8.3
    High

    CVE-2026-87644

    Last Modified: 9 Sept 2026

    Incorrect authorization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    6.5
    Medium

    CVE-2026-87535

    Last Modified: 10 Sept 2026

    Information loss or omission in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    5.4
    Medium

    CVE-2026-87635

    Last Modified: 9 Sept 2026

    UI misrepresentation in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    8.3
    High

    CVE-2026-87616

    Last Modified: 9 Sept 2026

    Improper initialization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    6.5
    Medium

    CVE-2026-87454

    Last Modified: 9 Sept 2026

    Information leak in Enterprise in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    6.5
    Medium

    CVE-2026-87483

    Last Modified: 10 Sept 2026

    Incorrect authorization in Browser in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    9.6
    Critical

    CVE-2026-87494

    Last Modified: 9 Sept 2026

    Use after free in Browser in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    4.3
    Medium

    CVE-2026-87550

    Last Modified: 9 Sept 2026

    Improper encoding or escaping of output in CSS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    8.1
    High

    CVE-2026-87530

    Last Modified: 9 Sept 2026

    Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    5.4
    Medium

    CVE-2026-87484

    Last Modified: 10 Sept 2026

    UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    6.5
    Medium

    CVE-2026-87589

    Last Modified: 11 Sept 2026

    Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    5.3
    Medium

    CVE-2026-87518

    Last Modified: 9 Sept 2026

    Observable discrepancy in Safebrowsing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    5.3
    Medium

    CVE-2026-87594

    Last Modified: 9 Sept 2026

    Incorrect authorization in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    5.4
    Medium

    CVE-2026-87540

    Last Modified: 10 Sept 2026

    Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    4.3
    Medium

    CVE-2026-87622

    Last Modified: 9 Sept 2026

    Missing authorization in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    8.1
    High

    CVE-2026-87505

    Last Modified: 10 Sept 2026

    Incorrect authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    7.5
    High

    CVE-2026-87450

    Last Modified: 10 Sept 2026

    Incorrect authorization in Permissions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    5.3
    Medium

    CVE-2026-87439

    Last Modified: 9 Sept 2026

    Information leak in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    6.5
    Medium

    CVE-2026-87532

    Last Modified: 10 Sept 2026

    Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    6.5
    Medium

    CVE-2026-87600

    Last Modified: 11 Sept 2026

    Improper input validation in Safebrowsing in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    4.7
    Medium

    CVE-2026-87555

    Last Modified: 9 Sept 2026

    Uninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    8.8
    High

    CVE-2026-87570

    Last Modified: 10 Sept 2026

    Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted file. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    3.1
    Low

    CVE-2026-87451

    Last Modified: 9 Sept 2026

    Information leak in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    6.5
    Medium

    CVE-2026-87541

    Last Modified: 10 Sept 2026

    Information leak in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    4.3
    Medium

    CVE-2026-87495

    Last Modified: 9 Sept 2026

    Information leak in Scroll in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    5.4
    Medium

    CVE-2026-87458

    Last Modified: 9 Sept 2026

    UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    6.5
    Medium

    CVE-2026-87549

    Last Modified: 10 Sept 2026

    Incomplete cleanup in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    6.5
    Medium

    CVE-2026-87441

    Last Modified: 10 Sept 2026

    Missing authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    5.4
    Medium

    CVE-2026-87496

    Last Modified: 10 Sept 2026

    UI misrepresentation in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    4.3
    Medium

    CVE-2026-87567

    Last Modified: 9 Sept 2026

    UI misrepresentation in UrlFormatting in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof address bar via a crafted domain name. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    4.3
    Medium

    CVE-2026-87574

    Last Modified: 9 Sept 2026

    Information leak in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    5.4
    Medium

    CVE-2026-87445

    Last Modified: 10 Sept 2026

    UI misrepresentation in Session in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    5.4
    Medium

    CVE-2026-87649

    Last Modified: 10 Sept 2026

    UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    5.4
    Medium

    CVE-2026-87462

    Last Modified: 9 Sept 2026

    UI misrepresentation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    5.4
    Medium

    CVE-2026-87655

    Last Modified: 9 Sept 2026

    Clickjacking in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    4
    Medium

    CVE-2026-87486

    Last Modified: 10 Sept 2026

    Clickjacking in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to spoof address bar via a co-installed app. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    4.2
    Medium

    CVE-2026-87472

    Last Modified: 10 Sept 2026

    Improper input validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    4.2
    Medium

    CVE-2026-87559

    Last Modified: 9 Sept 2026

    UI misrepresentation in UI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    5.4
    Medium

    CVE-2026-87507

    Last Modified: 10 Sept 2026

    UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Items Per Page