5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87554 — Race: condition in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87554

Race condition in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) CVSSv3.1 8.1 (HIGH)

CWECWE 367VNDRaceTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87553 — SiteIsolation: Improper input validation in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87553

Improper input validation in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.3 (HIGH)

CWECWE 20VNDSiteisolationTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87547 — Incorrect: reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87547

Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 706TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87544 — Google Chrome: Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87544

Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 9.8 (CRITICAL) · EPSS 6th percentile

CWECWE 863VNDGoogleTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87542 — Use: after free in Input in Google Chrome prior to 153.0.8010.36 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87542

Use after free in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87537 — Extensions: Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87537

Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium) CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDExtensionsTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87536 — Use: after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87536

Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87534 — Google Chrome: Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87534

Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium) CVSSv3.1 9.8 (CRITICAL) · EPSS 7th percentile

CWECWE 862VNDGoogleVNDWebviewTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87533 — Use: after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a local

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87533

Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium) CVSSv3.1 8.1 (HIGH)

CWECWE 416TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87530 — Uncontrolled: search path element in CredentialProvider in Google Chrome on on Windows prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87530

Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium) CVSSv3.1 8.1 (HIGH)

CWECWE 427VNDUncontrolledTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87529 — Numeric: truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87529

Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 197VNDNumericTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87528 — Type: confusion in Rust in Google Chrome on on Windows prior to 153.0.8010.36 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87528

Type confusion in Rust in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 843VNDTypeTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87527 — Buffer: overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87527

Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 9.6 (CRITICAL)

CWECWE 122VNDBufferTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87526 — Use: after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87526

Use after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87524 — Use: after free in Core in Google Chrome on on Windows prior to 153.0.8010.36

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87524

Use after free in Core in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87520 — Use: after free in Dawn in Google Chrome on on Android prior to 153.0.8010.36

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87520

Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87514 — Use: after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87514

Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) CVSSv3.1 8.1 (HIGH)

CWECWE 416TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87512 — Use: after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87512

Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87510 — FileAPI: Improper input validation in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87510

Improper input validation in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.3 (HIGH)

CWECWE 20VNDFileapiTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87509 — Incorrect: authorization in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87509

Incorrect authorization in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Low) CVSSv3.1 8.1 (HIGH)

CWECWE 863TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87506 — Privilege: elevation in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87506

Privilege elevation in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.3 (HIGH)

CWECWE 250TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87505 — Incorrect: authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87505

Incorrect authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: Medium) CVSSv3.1 8.1 (HIGH) · EPSS 6th percentile

CWECWE 863TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87504 — Use: after free in Core in Google Chrome prior to 153.0.8010.36 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87504

Use after free in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87500 — Improper validation of array index in ANGLE in Google Chrome prior to 153.0.8010.36 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87500

Improper validation of array index in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 129TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87499 — Incorrect: authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87499

Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.1 (HIGH) · EPSS 7th percentile

CWECWE 863TYPVulnerability
8.1
CVSS v3.1
91
Edit Score