5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87499 — Incorrect: authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87499

Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.1 (HIGH) · EPSS 7th percentile

CWECWE 863TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87494 — Use: after free in Browser in Google Chrome on on Windows prior to 153.0.8010.36

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87494

Use after free in Browser in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87492 — Incorrect: authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87492

Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 863TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87491 — Out: of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87491

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 787TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87489 — Memory: corruption in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87489

Memory corruption in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87488 — Use: after free in WebGL in Google Chrome on on Android prior to 153.0.8010.36

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87488

Use after free in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87487 — FileSystem: Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87487

Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.3 (HIGH)

CWECWE 862VNDFilesystemTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
728 × 90 / responsive · programmatic ad slot
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87481 — Incorrect: authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87481

Incorrect authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.3 (HIGH)

CWECWE 863TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87480 — Use: after free in Printing in Google Chrome prior to 153.0.8010.36 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87480

Use after free in Printing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87479 — Extensions: Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87479

Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.3 (HIGH)

CWECWE 807VNDExtensionsTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87474 — Use: after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87474

Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87471 — Incorrect: authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87471

Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.1 (HIGH) · EPSS 22th percentile

CWECWE 863TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87470 — Tint: Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.0.8010.36

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87470

Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 1284VNDTintTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87467 — Race: condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87467

Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) CVSSv3.1 8.1 (HIGH)

CWECWE 362VNDRaceTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87464 — Use: after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87464

Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87460 — Use: after free in Platform in Google Chrome prior to 153.0.8010.36 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87460

Use after free in Platform in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87457 — Race: condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87457

Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium) CVSSv3.1 8.1 (HIGH)

CWECWE 367VNDRaceTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87455 — Use: after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87455

Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87448 — Use: after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87448

Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87444 — Memory: corruption in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87444

Memory corruption in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87440 — Out: of bounds read in Media in Google Chrome prior to 153.0.8010.36 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87440

Out of bounds read in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 125TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87438 — Out: of bounds write in WebGL in Google Chrome on on Android prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87438

Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 9.6 (CRITICAL)

CWECWE 787TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:16Z
HIGH

CVE-2026-87433 — Google Chrome: Race condition in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87433

Race condition in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH) · EPSS 16th percentile

CWECWE 367VNDGoogleVNDRaceTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-09 01:16Z
HIGH

CVE-2026-87430 — Buffer: overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87430

Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDBufferTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-09 00:47Z
CRIT

LSPromise — Android complete exploit chain that enables privilege escalation from a local untrusted app to root/kernel, combination

GitHub · LPE exploits·github.comGITHUB POCCVE-2026-49881CVE-2026-432840day

LSPromise is a complete Android privilege escalation exploit chain combining a 0-day logic bug in Android 17's Telecom service (CVE-2026-49881) with the DirtyFrag kernel vulnerability (CVE-2026-43284). The chain achieves arbitrary code execution in system_server via a malicious AppComponentFactory, then pivots through the network stack to exploit DirtyFrag for kernel-level code execution and SELinux bypass, ultimately achieving root access with 100% success rate on vulnerable devices.

SRFOsTACTA0004TACTA0005OSAndroidTYPExploitSTGPrivescSTGExecutionTECT1548
95
Edit Score