CVE-2026-95369
HIGH
CVSS: 8.8
EPSS: 0.4%
CWE-841
Inappropriate implementation in XML in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95373
HIGH
CVSS: 8.8
EPSS: 0.4%
CWE-416
T1203
Use after free in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95380
HIGH
CVSS: 8.8
EPSS: 0.5%
CWE-843
Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95278
HIGH
CVSS: 8.4
EPSS: 0.2%
CWE-862
T1078
Missing authorization in WakeLock in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95285
HIGH
CVSS: 8.4
EPSS: 0.2%
CWE-862
T1078
Missing authorization in WebView in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95274
HIGH
CVSS: 8.3
EPSS: 0.4%
CWE-116
Improper output encoding in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95276
HIGH
CVSS: 8.3
EPSS: 0.5%
CWE-20
T1190
Improper input validation in Themes in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code inside the sandbox via crafted network traffic. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95319
HIGH
CVSS: 8.3
EPSS: 0.4%
CWE-416
T1203
Use after free in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95322
HIGH
CVSS: 8.3
EPSS: 0.4%
CWE-787
T1203
Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95334
HIGH
CVSS: 8.3
EPSS: 0.4%
CWE-706
Incorrect reference resolution in WebProtect in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95335
HIGH
CVSS: 8.3
EPSS: 0.4%
CWE-416
T1203
Use after free in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95341
HIGH
CVSS: 8.3
EPSS: 0.4%
CWE-20
T1190
Improper input validation in Desktop in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95348
HIGH
CVSS: 8.3
EPSS: 0.4%
CWE-416
T1203
Use after free in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95351
HIGH
CVSS: 8.3
EPSS: 0.4%
CWE-416
T1203
Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95354
HIGH
CVSS: 8.3
EPSS: 0.4%
CWE-416
T1203
Use after free in Verifier in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95355
HIGH
CVSS: 8.3
EPSS: 0.4%
CWE-863
T1078
Incorrect authorization in Navigation in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95372
HIGH
CVSS: 8.3
EPSS: 0.4%
CWE-416
T1203
Use after free in Chromecast in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95381
HIGH
CVSS: 8.3
EPSS: 0.4%
CWE-20
T1190
Improper input validation in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95301
HIGH
CVSS: 8.1
EPSS: 0.3%
CWE-862
T1078
Missing authorization in Extensions in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95314
HIGH
CVSS: 8.1
EPSS: 0.3%
CWE-863
T1078
Incorrect authorization in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95333
HIGH
CVSS: 8.1
EPSS: 0.4%
CWE-416
T1203
Use after free in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95344
HIGH
CVSS: 8.0
EPSS: 0.2%
CWE-367
Race condition in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass site isolation via a crafted Chrome extension. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95315
HIGH
CVSS: 7.8
EPSS: 0.1%
CWE-416
T1203
Use after free in Aura in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-100208
HIGH
CVSS: 7.5
EPSS: 0.3%
CWE-190
T1203
Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
Published: 2026-09-25
Mentioned in 1 article(s):
CVE-2026-95280
HIGH
CVSS: 7.5
EPSS: 0.3%
CWE-362
T1068
Race condition in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95275
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-706
Incorrect reference resolution in MediaStream in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95297
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-862
T1078
Missing authorization in Contextual Tasks in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95303
MEDIUM
CVSS: 6.5
EPSS: 0.4%
CWE-459
Incomplete cleanup in SmartCard in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95328
MEDIUM
CVSS: 6.5
EPSS: 0.2%
CWE-441
Confused deputy in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker leveraging social engineering to obtain sensitive information via a co-installed app. (Chromium security severity: Low)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95330
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-754
Improper state validation in Downloads in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95336
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-200
T1005
T1083
Information leak in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95279
MEDIUM
CVSS: 5.4
EPSS: 0.3%
CWE-451
UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95288
MEDIUM
CVSS: 5.4
EPSS: 0.3%
CWE-451
UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95290
MEDIUM
CVSS: 5.4
EPSS: 0.2%
CWE-862
T1078
Missing authorization in NFC in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95291
MEDIUM
CVSS: 5.4
EPSS: 0.3%
CWE-451
UI misrepresentation in SecurityIndicators in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95294
MEDIUM
CVSS: 5.4
EPSS: 0.3%
CWE-451
UI misrepresentation in Browser in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95307
MEDIUM
CVSS: 5.4
EPSS: 0.3%
CWE-451
UI misrepresentation in ExtensionsMenu in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95320
MEDIUM
CVSS: 5.4
EPSS: 0.2%
CWE-862
T1078
Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95321
MEDIUM
CVSS: 5.4
EPSS: 0.3%
CWE-451
UI misrepresentation in Payments in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95323
MEDIUM
CVSS: 5.4
EPSS: 0.3%
CWE-451
UI misrepresentation in Chromium in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95337
MEDIUM
CVSS: 5.4
EPSS: 0.3%
CWE-451
UI misrepresentation in Messages in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95352
MEDIUM
CVSS: 5.4
EPSS: 0.2%
CWE-863
T1078
Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Low)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95363
MEDIUM
CVSS: 5.4
EPSS: 0.2%
CWE-451
UI misrepresentation in FileSystem in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95364
MEDIUM
CVSS: 5.4
EPSS: 0.2%
CWE-20
T1190
Improper input validation in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95370
MEDIUM
CVSS: 5.4
EPSS: 0.2%
CWE-841
Inappropriate implementation in NFC in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95371
MEDIUM
CVSS: 5.4
EPSS: 0.2%
CWE-862
T1078
Missing authorization in Views in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95360
MEDIUM
CVSS: 5.3
EPSS: 0.2%
CWE-367
Race condition in Editing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95367
MEDIUM
CVSS: 5.3
EPSS: 0.3%
CWE-200
T1005
T1083
Information leak in DataTransfer in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95300
MEDIUM
CVSS: 4.8
EPSS: 0.2%
CWE-862
T1078
Missing authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
CVE-2026-95305
MEDIUM
CVSS: 4.8
EPSS: 0.3%
CWE-451
UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic. (Chromium security severity: Low)
Published: 2026-09-29
Mentioned in 1 article(s):