5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87643 — Integer: overflow in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87643

Integer overflow in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 190TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87639 — Use: after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87639

Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87638 — Out: of bounds write in Media in Google Chrome prior to 153.0.8010.36 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87638

Out of bounds write in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 787TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87637 — Use: after free in Extensions in Google Chrome on on Mac prior to 153.0.8010.36

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87637

Use after free in Extensions in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87636 — Type: confusion in XML in Google Chrome prior to 153.0.8010.36 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87636

Type confusion in XML in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 843VNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87634 — Use: after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87634

Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87633 — Use: after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87633

Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High) CVSSv3.1 8.6 (HIGH)

CWECWE 416TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
728 × 90 / responsive · programmatic ad slot
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87628 — Use: after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjacent

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87628

Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Critical) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87625 — Use: after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87625

Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87621 — Out: of bounds write in ANGLE in Google Chrome on on Windows prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87621

Out of bounds write in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 787TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87618 — Incorrect: reference resolution in Storage in Google Chrome on on Windows prior to 153.0.8010.36

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87618

Incorrect reference resolution in Storage in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.3 (HIGH)

CWECWE 706TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87617 — Use: after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87617

Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87616 — Views: Improper initialization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87616

Improper initialization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.3 (HIGH)

CWECWE 665VNDViewsTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87613 — Incorrect: reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87613

Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium) CVSSv3.1 9.0 (CRITICAL)

CWECWE 706TYPVulnerability
9.0
CVSS v3.1
95
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87612 — Type: confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87612

Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 843VNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87609 — Use: after free in Sharing in Google Chrome on on iOS prior to 153.0.8010.36

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87609

Use after free in Sharing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87607 — Use: after free in Device in Google Chrome on on Mac prior to 153.0.8010.36

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87607

Use after free in Device in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87606 — SiteIsolation: Missing authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87606

Missing authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.1 (HIGH) · EPSS 7th percentile

CWECWE 862VNDSiteisolationTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87604 — Out: of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87604

Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 125TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87588 — Use: after free in Chromecast in Google Chrome prior to 153.0.8010.36 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87588

Use after free in Chromecast in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87587 — Use: after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87587

Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87585 — Double: free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87585

Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 415VNDDoubleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87582 — Confused: deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87582

Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.3 (HIGH)

CWECWE 441VNDConfusedTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87581 — Use: after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87581

Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87579 — Buffer: overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87579

Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDBufferTYPVulnerability
8.8
CVSS v3.1
94
Edit Score