5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87579 — Buffer: overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87579

Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDBufferTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87578 — Use: after free in Receiver in Google Chrome prior to 153.0.8010.36 allowed an adjacent

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87578

Use after free in Receiver in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87572 — Injection: in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87572

Injection in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 74TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87570 — Google Chrome: Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87570

Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted file. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87569 — Google Chrome: Missing authorization in Views in Google Chrome prior to 153.0.8010.36 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87569

Missing authorization in Views in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDGoogleVNDViewsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87558 — Use: after free in Payments in Google Chrome on on Mac prior to 153.0.8010.36

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87558

Use after free in Payments in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87554 — Race: condition in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87554

Race condition in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) CVSSv3.1 8.1 (HIGH)

CWECWE 367VNDRaceTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87553 — SiteIsolation: Improper input validation in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87553

Improper input validation in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.3 (HIGH)

CWECWE 20VNDSiteisolationTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87547 — Incorrect: reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87547

Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 706TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87544 — Google Chrome: Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87544

Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 9.8 (CRITICAL) · EPSS 6th percentile

CWECWE 863VNDGoogleTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87542 — Use: after free in Input in Google Chrome prior to 153.0.8010.36 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87542

Use after free in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87537 — Extensions: Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87537

Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium) CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDExtensionsTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87536 — Use: after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87536

Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87534 — Google Chrome: Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87534

Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium) CVSSv3.1 9.8 (CRITICAL) · EPSS 7th percentile

CWECWE 862VNDGoogleVNDWebviewTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87533 — Use: after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a local

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87533

Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium) CVSSv3.1 8.1 (HIGH)

CWECWE 416TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87530 — Uncontrolled: search path element in CredentialProvider in Google Chrome on on Windows prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87530

Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium) CVSSv3.1 8.1 (HIGH)

CWECWE 427VNDUncontrolledTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87529 — Numeric: truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87529

Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 197VNDNumericTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87528 — Type: confusion in Rust in Google Chrome on on Windows prior to 153.0.8010.36 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87528

Type confusion in Rust in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 843VNDTypeTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87527 — Buffer: overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87527

Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 9.6 (CRITICAL)

CWECWE 122VNDBufferTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87526 — Use: after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87526

Use after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87524 — Use: after free in Core in Google Chrome on on Windows prior to 153.0.8010.36

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87524

Use after free in Core in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87520 — Use: after free in Dawn in Google Chrome on on Android prior to 153.0.8010.36

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87520

Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87514 — Use: after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87514

Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) CVSSv3.1 8.1 (HIGH)

CWECWE 416TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87512 — Use: after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87512

Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87510 — FileAPI: Improper input validation in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87510

Improper input validation in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.3 (HIGH)

CWECWE 20VNDFileapiTYPVulnerability
8.3
CVSS v3.1
92
Edit Score