CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2026-87599

    Last Modified: 10 Sept 2026

    Improper input validation in Interstitials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    4.3
    Medium

    CVE-2026-87516

    Last Modified: 9 Sept 2026

    Observable discrepancy in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    4.3
    Medium

    CVE-2026-87548

    Last Modified: 10 Sept 2026

    Improper state validation in Installer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    5.4
    Medium

    CVE-2026-87501

    Last Modified: 10 Sept 2026

    UI misrepresentation in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    3.1
    Low

    CVE-2026-87452

    Last Modified: 9 Sept 2026

    Incorrect authorization in GPU in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    4.3
    Medium

    CVE-2026-87573

    Last Modified: 9 Sept 2026

    Improper input validation in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    9.6
    Critical

    CVE-2026-87643

    Last Modified: 9 Sept 2026

    Integer overflow in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    4.3
    Medium

    CVE-2026-87508

    Last Modified: 9 Sept 2026

    Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    4.3
    Medium

    CVE-2026-87556

    Last Modified: 10 Sept 2026

    Missing authorization in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    4.3
    Medium

    CVE-2026-87562

    Last Modified: 9 Sept 2026

    Incorrect reference resolution in Accessibility in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    9.8
    Critical

    CVE-2026-87534

    Last Modified: 11 Sept 2026

    Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    8.3
    High

    CVE-2026-87648

    Last Modified: 9 Sept 2026

    Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    3.1
    Low

    CVE-2026-87539

    Last Modified: 10 Sept 2026

    Observable discrepancy in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    3.1
    Low

    CVE-2026-87521

    Last Modified: 9 Sept 2026

    Information leak in WebMCP in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    4.3
    Medium

    CVE-2026-87560

    Last Modified: 10 Sept 2026

    Missing authorization in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    4.2
    Medium

    CVE-2026-87432

    Last Modified: 9 Sept 2026

    Incorrect authorization in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    6.5
    Medium

    CVE-2026-87513

    Last Modified: 11 Sept 2026

    Missing authorization in ControlledFrame in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    8.3
    High

    CVE-2026-87479

    Last Modified: 9 Sept 2026

    Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    6.5
    Medium

    CVE-2026-87436

    Last Modified: 11 Sept 2026

    Incomplete cleanup in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    6.5
    Medium

    CVE-2026-87475

    Last Modified: 10 Sept 2026

    Missing authorization in Omnibox in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    3.4
    Low

    CVE-2026-87576

    Last Modified: 9 Sept 2026

    Uninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    8.8
    High

    CVE-2026-87579

    Last Modified: 9 Sept 2026

    Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    5.9
    Medium

    CVE-2026-87482

    Last Modified: 11 Sept 2026

    Cleartext transmission of sensitive data in HttpsUpgrades in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via crafted network traffic. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    6.5
    Medium

    CVE-2026-87580

    Last Modified: 11 Sept 2026

    Incorrect authorization in WebAppInstalls in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    4.3
    Medium

    CVE-2026-87497

    Last Modified: 10 Sept 2026

    Uninitialized resource in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    6.5
    Medium

    CVE-2026-87476

    Last Modified: 9 Sept 2026

    Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    5.9
    Medium

    CVE-2026-87590

    Last Modified: 11 Sept 2026

    Improper input validation in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially leak sensitive information via crafted network traffic. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    4.3
    Medium

    CVE-2026-87630

    Last Modified: 10 Sept 2026

    Integer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    9
    Critical

    CVE-2026-87613

    Last Modified: 9 Sept 2026

    Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    4.3
    Medium

    CVE-2026-87449

    Last Modified: 9 Sept 2026

    Cross-site request forgery in DeviceBoundSessionCredentials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    4.3
    Medium

    CVE-2026-87577

    Last Modified: 10 Sept 2026

    Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    6.5
    Medium

    CVE-2026-87443

    Last Modified: 9 Sept 2026

    Missing authorization in Actor in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    5.4
    Medium

    CVE-2026-87645

    Last Modified: 10 Sept 2026

    Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    4.3
    Medium

    CVE-2026-87642

    Last Modified: 9 Sept 2026

    Uninitialized resource in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    5.4
    Medium

    CVE-2026-87615

    Last Modified: 10 Sept 2026

    Race condition in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    6.5
    Medium

    CVE-2026-87603

    Last Modified: 11 Sept 2026

    Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    4.3
    Medium

    CVE-2026-87466

    Last Modified: 9 Sept 2026

    Incorrect authorization in Workers in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    8.3
    High

    CVE-2026-87582

    Last Modified: 9 Sept 2026

    Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    3.1
    Low

    CVE-2026-87652

    Last Modified: 9 Sept 2026

    Incorrect authorization in PushAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    3.1
    Low

    CVE-2026-87485

    Last Modified: 9 Sept 2026

    Incorrect authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    8.1
    High

    CVE-2026-87537

    Last Modified: 10 Sept 2026

    Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    8.3
    High

    CVE-2026-87481

    Last Modified: 9 Sept 2026

    Incorrect authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    6.5
    Medium

    CVE-2026-87503

    Last Modified: 11 Sept 2026

    Inappropriate implementation in Downloads in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    8.1
    High

    CVE-2026-87471

    Last Modified: 10 Sept 2026

    Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    8.1
    High

    CVE-2026-87457

    Last Modified: 9 Sept 2026

    Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    4.3
    Medium

    CVE-2026-87557

    Last Modified: 10 Sept 2026

    Missing authorization in LocalNetworkAccess in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    8.8
    High

    CVE-2026-87433

    Last Modified: 10 Sept 2026

    Race condition in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    8.3
    High

    CVE-2026-87506

    Last Modified: 9 Sept 2026

    Privilege elevation in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    3.1
    Low

    CVE-2026-87442

    Last Modified: 10 Sept 2026

    Confused deputy in Prerender in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    9.6
    Critical

    CVE-2026-87547

    Last Modified: 9 Sept 2026

    Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Items Per Page