CVE-2026-87649
MEDIUM
CVSS: 5.4
EPSS: 0.2%
CWE-451
UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87648
HIGH
CVSS: 8.3
EPSS: 0.4%
CWE-416
T1203
Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87647
LOW
CVSS: 3.4
EPSS: 0.3%
CWE-908
T1005
Uninitialized resource in GPU in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87646
CRITICAL
CVSS: 9.6
EPSS: 0.5%
CWE-416
T1203
Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87645
MEDIUM
CVSS: 5.4
EPSS: 0.2%
CWE-754
Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87644
HIGH
CVSS: 8.3
EPSS: 0.4%
CWE-863
T1078
Incorrect authorization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87642
MEDIUM
CVSS: 4.3
EPSS: 0.3%
CWE-908
T1005
Uninitialized resource in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87641
MEDIUM
CVSS: 4.2
EPSS: 0.2%
CWE-362
T1068
Race condition in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87639
HIGH
CVSS: 8.3
EPSS: 0.4%
CWE-416
T1203
Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87638
CRITICAL
CVSS: 9.6
EPSS: 0.5%
CWE-787
T1203
Out of bounds write in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87637
CRITICAL
CVSS: 9.6
EPSS: 0.5%
CWE-416
T1203
Use after free in Extensions in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87636
HIGH
CVSS: 8.8
EPSS: 0.5%
CWE-843
Type confusion in XML in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87635
MEDIUM
CVSS: 5.4
EPSS: 0.3%
CWE-451
UI misrepresentation in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87634
CRITICAL
CVSS: 9.6
EPSS: 0.5%
CWE-416
T1203
Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87633
HIGH
CVSS: 8.6
EPSS: 0.2%
CWE-416
T1203
Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87632
MEDIUM
CVSS: 4.3
EPSS: 0.3%
CWE-79
T1189
Cross-site scripting in SanitizerAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87631
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-862
T1078
Missing authorization in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87630
MEDIUM
CVSS: 4.3
EPSS: 0.3%
CWE-190
T1203
Integer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87629
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-863
T1078
Incorrect authorization in Sources in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87628
HIGH
CVSS: 8.3
EPSS: 0.2%
CWE-416
T1203
Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Critical)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87627
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-436
Interpretation conflict in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted file. (Chromium security severity: Low)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87626
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-863
T1078
Incorrect authorization in DeviceBoundSessionCredentials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via crafted network traffic. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87625
HIGH
CVSS: 8.8
EPSS: 0.4%
CWE-416
T1203
Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87624
MEDIUM
CVSS: 4.2
EPSS: 0.2%
CWE-451
UI misrepresentation in Passwords in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87623
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-203
Observable discrepancy in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87622
MEDIUM
CVSS: 4.3
EPSS: 0.3%
CWE-862
T1078
Missing authorization in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87621
CRITICAL
CVSS: 9.6
EPSS: 0.5%
CWE-787
T1203
Out of bounds write in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87620
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-203
Observable discrepancy in SVG in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87619
MEDIUM
CVSS: 4.3
EPSS: 0.3%
CWE-203
Observable discrepancy in Prefetch in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87618
HIGH
CVSS: 8.3
EPSS: 0.4%
CWE-706
Incorrect reference resolution in Storage in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87617
HIGH
CVSS: 8.8
EPSS: 0.4%
CWE-416
T1203
Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87616
HIGH
CVSS: 8.3
EPSS: 0.4%
CWE-665
Improper initialization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87615
MEDIUM
CVSS: 5.4
EPSS: 0.2%
CWE-362
T1068
Race condition in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87614
LOW
CVSS: 3.1
EPSS: 0.2%
CWE-863
T1078
Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87613
CRITICAL
CVSS: 9.0
EPSS: 0.5%
CWE-706
Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87612
HIGH
CVSS: 8.8
EPSS: 0.5%
CWE-843
Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87611
LOW
CVSS: 3.1
EPSS: 0.2%
CWE-862
T1078
Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87610
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-863
T1078
Incorrect authorization in Omnibox in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87609
CRITICAL
CVSS: 9.6
EPSS: 0.4%
CWE-416
T1203
Use after free in Sharing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87608
HIGH
CVSS: 7.5
EPSS: 0.3%
CWE-295
T1557
Improper certificate validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87606
HIGH
CVSS: 8.1
EPSS: 0.3%
CWE-862
T1078
Missing authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87605
MEDIUM
CVSS: 5.3
EPSS: 0.3%
CWE-862
T1078
Missing authorization in Contacts in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87604
HIGH
CVSS: 8.3
EPSS: 0.4%
CWE-125
T1005
Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87603
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-862
T1078
Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87602
MEDIUM
CVSS: 4.7
EPSS: 0.3%
CWE-125
T1005
Out of bounds read in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87601
HIGH
CVSS: 7.5
EPSS: 0.3%
CWE-362
T1068
Race condition in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87600
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-20
T1190
Improper input validation in Safebrowsing in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87599
MEDIUM
CVSS: 5.4
EPSS: 0.2%
CWE-20
T1190
Improper input validation in Interstitials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87598
MEDIUM
CVSS: 4.3
EPSS: 0.3%
CWE-863
T1078
Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87596
MEDIUM
CVSS: 4.3
EPSS: 0.2%
CWE-125
T1005
Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-09
Mentioned in 1 article(s):