CVE Feed

    Dashboard / CVE

    Unknown

    CVE-2026-87577

    Last Modified: 9 Sept 2026

    Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87642

    Last Modified: 9 Sept 2026

    Uninitialized resource in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87615

    Last Modified: 9 Sept 2026

    Race condition in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87603

    Last Modified: 9 Sept 2026

    Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87466

    Last Modified: 9 Sept 2026

    Incorrect authorization in Workers in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87582

    Last Modified: 9 Sept 2026

    Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87652

    Last Modified: 9 Sept 2026

    Incorrect authorization in PushAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87485

    Last Modified: 9 Sept 2026

    Incorrect authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87471

    Last Modified: 9 Sept 2026

    Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87537

    Last Modified: 9 Sept 2026

    Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87481

    Last Modified: 9 Sept 2026

    Incorrect authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87503

    Last Modified: 9 Sept 2026

    Inappropriate implementation in Downloads in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87457

    Last Modified: 9 Sept 2026

    Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87557

    Last Modified: 9 Sept 2026

    Missing authorization in LocalNetworkAccess in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87433

    Last Modified: 9 Sept 2026

    Race condition in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87506

    Last Modified: 9 Sept 2026

    Privilege elevation in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87442

    Last Modified: 9 Sept 2026

    Confused deputy in Prerender in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87547

    Last Modified: 9 Sept 2026

    Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87515

    Last Modified: 9 Sept 2026

    Incorrect authorization in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87465

    Last Modified: 9 Sept 2026

    Incorrect authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87658

    Last Modified: 9 Sept 2026

    Information leak in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87553

    Last Modified: 9 Sept 2026

    Improper input validation in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87456

    Last Modified: 9 Sept 2026

    Uninitialized resource in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87606

    Last Modified: 9 Sept 2026

    Missing authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87611

    Last Modified: 9 Sept 2026

    Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87636

    Last Modified: 9 Sept 2026

    Type confusion in XML in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87588

    Last Modified: 9 Sept 2026

    Use after free in Chromecast in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87453

    Last Modified: 9 Sept 2026

    Confused deputy in BackgroundFetch in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87487

    Last Modified: 9 Sept 2026

    Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87434

    Last Modified: 9 Sept 2026

    Missing authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87657

    Last Modified: 9 Sept 2026

    Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87446

    Last Modified: 9 Sept 2026

    Incomplete cleanup in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87478

    Last Modified: 9 Sept 2026

    Observable discrepancy in Autofill in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87491

    Last Modified: 9 Sept 2026

    Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87640

    Last Modified: 9 Sept 2026

    Out of bounds read in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87504

    Last Modified: 9 Sept 2026

    Use after free in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87474

    Last Modified: 9 Sept 2026

    Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87536

    Last Modified: 9 Sept 2026

    Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87612

    Last Modified: 9 Sept 2026

    Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87480

    Last Modified: 9 Sept 2026

    Use after free in Printing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87581

    Last Modified: 9 Sept 2026

    Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87558

    Last Modified: 9 Sept 2026

    Use after free in Payments in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87607

    Last Modified: 9 Sept 2026

    Use after free in Device in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87499

    Last Modified: 9 Sept 2026

    Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87498

    Last Modified: 9 Sept 2026

    Missing authorization in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87564

    Last Modified: 9 Sept 2026

    Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87587

    Last Modified: 9 Sept 2026

    Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87651

    Last Modified: 9 Sept 2026

    Incorrect authorization in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87552

    Last Modified: 9 Sept 2026

    Missing authorization in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: High)

    Published: 9 Sept 2026
    Unknown

    CVE-2026-87639

    Last Modified: 9 Sept 2026

    Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Sept 2026
    Items Per Page