CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2026-87515

    Last Modified: 11 Sept 2026

    Incorrect authorization in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    4.3
    Medium

    CVE-2026-87658

    Last Modified: 9 Sept 2026

    Information leak in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    8.3
    High

    CVE-2026-87553

    Last Modified: 9 Sept 2026

    Improper input validation in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    3.4
    Low

    CVE-2026-87456

    Last Modified: 9 Sept 2026

    Uninitialized resource in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    8.1
    High

    CVE-2026-87606

    Last Modified: 11 Sept 2026

    Missing authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    4.2
    Medium

    CVE-2026-87465

    Last Modified: 9 Sept 2026

    Incorrect authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    3.1
    Low

    CVE-2026-87611

    Last Modified: 9 Sept 2026

    Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    5.3
    Medium

    CVE-2026-87453

    Last Modified: 9 Sept 2026

    Confused deputy in BackgroundFetch in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    8.3
    High

    CVE-2026-87487

    Last Modified: 9 Sept 2026

    Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    3.1
    Low

    CVE-2026-87434

    Last Modified: 9 Sept 2026

    Missing authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    8.8
    High

    CVE-2026-87588

    Last Modified: 9 Sept 2026

    Use after free in Chromecast in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    8.8
    High

    CVE-2026-87636

    Last Modified: 9 Sept 2026

    Type confusion in XML in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    6.5
    Medium

    CVE-2026-87446

    Last Modified: 10 Sept 2026

    Incomplete cleanup in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    6.5
    Medium

    CVE-2026-87478

    Last Modified: 9 Sept 2026

    Observable discrepancy in Autofill in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    8.8
    High

    CVE-2026-87491

    Last Modified: 10 Sept 2026

    Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    6.1
    Medium

    CVE-2026-87640

    Last Modified: 10 Sept 2026

    Out of bounds read in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    9.6
    Critical

    CVE-2026-87504

    Last Modified: 9 Sept 2026

    Use after free in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    3.1
    Low

    CVE-2026-87657

    Last Modified: 9 Sept 2026

    Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    9.6
    Critical

    CVE-2026-87474

    Last Modified: 9 Sept 2026

    Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.8
    High

    CVE-2026-87536

    Last Modified: 10 Sept 2026

    Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.3
    High

    CVE-2026-87480

    Last Modified: 9 Sept 2026

    Use after free in Printing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    9.6
    Critical

    CVE-2026-87581

    Last Modified: 9 Sept 2026

    Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    9.6
    Critical

    CVE-2026-87558

    Last Modified: 9 Sept 2026

    Use after free in Payments in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    9.6
    Critical

    CVE-2026-87607

    Last Modified: 9 Sept 2026

    Use after free in Device in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.8
    High

    CVE-2026-87612

    Last Modified: 9 Sept 2026

    Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.8
    High

    CVE-2026-87587

    Last Modified: 9 Sept 2026

    Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    4.3
    Medium

    CVE-2026-87651

    Last Modified: 9 Sept 2026

    Incorrect authorization in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    5.5
    Medium

    CVE-2026-87552

    Last Modified: 10 Sept 2026

    Missing authorization in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.3
    High

    CVE-2026-87639

    Last Modified: 9 Sept 2026

    Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    4.3
    Medium

    CVE-2026-87564

    Last Modified: 9 Sept 2026

    Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.1
    High

    CVE-2026-87499

    Last Modified: 10 Sept 2026

    Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    3.1
    Low

    CVE-2026-87498

    Last Modified: 9 Sept 2026

    Missing authorization in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.8
    High

    CVE-2026-87542

    Last Modified: 9 Sept 2026

    Use after free in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.3
    High

    CVE-2026-87572

    Last Modified: 9 Sept 2026

    Injection in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    9.6
    Critical

    CVE-2026-87500

    Last Modified: 9 Sept 2026

    Improper validation of array index in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    9.6
    Critical

    CVE-2026-87646

    Last Modified: 9 Sept 2026

    Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    3.4
    Low

    CVE-2026-87647

    Last Modified: 9 Sept 2026

    Uninitialized resource in GPU in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.8
    High

    CVE-2026-87460

    Last Modified: 9 Sept 2026

    Use after free in Platform in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    9.6
    Critical

    CVE-2026-87621

    Last Modified: 9 Sept 2026

    Out of bounds write in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.3
    High

    CVE-2026-87604

    Last Modified: 9 Sept 2026

    Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    9.6
    Critical

    CVE-2026-87654

    Last Modified: 9 Sept 2026

    Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    4.3
    Medium

    CVE-2026-87596

    Last Modified: 10 Sept 2026

    Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    9.6
    Critical

    CVE-2026-87650

    Last Modified: 9 Sept 2026

    Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.1
    High

    CVE-2026-87514

    Last Modified: 9 Sept 2026

    Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)

    Published: 9 Sept 2026
    9.6
    Critical

    CVE-2026-87520

    Last Modified: 9 Sept 2026

    Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    9.6
    Critical

    CVE-2026-87492

    Last Modified: 9 Sept 2026

    Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.1
    High

    CVE-2026-87467

    Last Modified: 9 Sept 2026

    Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.1
    High

    CVE-2026-87554

    Last Modified: 9 Sept 2026

    Race condition in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.8
    High

    CVE-2026-87569

    Last Modified: 10 Sept 2026

    Missing authorization in Views in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.3
    High

    CVE-2026-87524

    Last Modified: 9 Sept 2026

    Use after free in Core in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    Items Per Page