CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2026-87588

    Last Modified: 9 Sept 2026

    Use after free in Chromecast in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    8.8
    High

    CVE-2026-87636

    Last Modified: 9 Sept 2026

    Type confusion in XML in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    6.5
    Medium

    CVE-2026-87446

    Last Modified: 10 Sept 2026

    Incomplete cleanup in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    6.5
    Medium

    CVE-2026-87478

    Last Modified: 9 Sept 2026

    Observable discrepancy in Autofill in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    8.8
    High

    CVE-2026-87491

    Last Modified: 10 Sept 2026

    Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    6.1
    Medium

    CVE-2026-87640

    Last Modified: 10 Sept 2026

    Out of bounds read in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    9.6
    Critical

    CVE-2026-87504

    Last Modified: 9 Sept 2026

    Use after free in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    3.1
    Low

    CVE-2026-87657

    Last Modified: 9 Sept 2026

    Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    9.6
    Critical

    CVE-2026-87474

    Last Modified: 9 Sept 2026

    Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.8
    High

    CVE-2026-87536

    Last Modified: 10 Sept 2026

    Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.3
    High

    CVE-2026-87480

    Last Modified: 9 Sept 2026

    Use after free in Printing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    9.6
    Critical

    CVE-2026-87581

    Last Modified: 9 Sept 2026

    Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    9.6
    Critical

    CVE-2026-87558

    Last Modified: 9 Sept 2026

    Use after free in Payments in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    9.6
    Critical

    CVE-2026-87607

    Last Modified: 9 Sept 2026

    Use after free in Device in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.8
    High

    CVE-2026-87612

    Last Modified: 9 Sept 2026

    Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.8
    High

    CVE-2026-87587

    Last Modified: 9 Sept 2026

    Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    4.3
    Medium

    CVE-2026-87651

    Last Modified: 9 Sept 2026

    Incorrect authorization in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    5.5
    Medium

    CVE-2026-87552

    Last Modified: 10 Sept 2026

    Missing authorization in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.3
    High

    CVE-2026-87639

    Last Modified: 9 Sept 2026

    Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    4.3
    Medium

    CVE-2026-87564

    Last Modified: 9 Sept 2026

    Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.1
    High

    CVE-2026-87499

    Last Modified: 10 Sept 2026

    Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    3.1
    Low

    CVE-2026-87498

    Last Modified: 9 Sept 2026

    Missing authorization in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.8
    High

    CVE-2026-87542

    Last Modified: 9 Sept 2026

    Use after free in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.3
    High

    CVE-2026-87572

    Last Modified: 9 Sept 2026

    Injection in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    9.6
    Critical

    CVE-2026-87500

    Last Modified: 9 Sept 2026

    Improper validation of array index in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    9.6
    Critical

    CVE-2026-87646

    Last Modified: 9 Sept 2026

    Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    3.4
    Low

    CVE-2026-87647

    Last Modified: 9 Sept 2026

    Uninitialized resource in GPU in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.8
    High

    CVE-2026-87460

    Last Modified: 9 Sept 2026

    Use after free in Platform in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    9.6
    Critical

    CVE-2026-87621

    Last Modified: 9 Sept 2026

    Out of bounds write in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.3
    High

    CVE-2026-87604

    Last Modified: 9 Sept 2026

    Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    9.6
    Critical

    CVE-2026-87654

    Last Modified: 9 Sept 2026

    Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    4.3
    Medium

    CVE-2026-87596

    Last Modified: 10 Sept 2026

    Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    9.6
    Critical

    CVE-2026-87650

    Last Modified: 9 Sept 2026

    Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.1
    High

    CVE-2026-87514

    Last Modified: 9 Sept 2026

    Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)

    Published: 9 Sept 2026
    9.6
    Critical

    CVE-2026-87520

    Last Modified: 9 Sept 2026

    Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    9.6
    Critical

    CVE-2026-87492

    Last Modified: 9 Sept 2026

    Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.1
    High

    CVE-2026-87467

    Last Modified: 9 Sept 2026

    Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.1
    High

    CVE-2026-87554

    Last Modified: 9 Sept 2026

    Race condition in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.8
    High

    CVE-2026-87569

    Last Modified: 10 Sept 2026

    Missing authorization in Views in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.3
    High

    CVE-2026-87524

    Last Modified: 9 Sept 2026

    Use after free in Core in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    3.1
    Low

    CVE-2026-87517

    Last Modified: 9 Sept 2026

    Race condition in Mobile in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.3
    High

    CVE-2026-87578

    Last Modified: 9 Sept 2026

    Use after free in Receiver in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)

    Published: 9 Sept 2026
    2.7
    Low

    CVE-2026-87525

    Last Modified: 10 Sept 2026

    Out of bounds read in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to read memory outside the sandbox via a local program. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.6
    High

    CVE-2026-87633

    Last Modified: 9 Sept 2026

    Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.8
    High

    CVE-2026-87440

    Last Modified: 9 Sept 2026

    Out of bounds read in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    6.5
    Medium

    CVE-2026-87447

    Last Modified: 11 Sept 2026

    Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.8
    High

    CVE-2026-87444

    Last Modified: 9 Sept 2026

    Memory corruption in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.8
    High

    CVE-2026-87585

    Last Modified: 9 Sept 2026

    Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)

    Published: 9 Sept 2026
    9.6
    Critical

    CVE-2026-87512

    Last Modified: 9 Sept 2026

    Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    8.3
    High

    CVE-2026-87628

    Last Modified: 9 Sept 2026

    Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Critical)

    Published: 9 Sept 2026
    Items Per Page