CVE-2026-87477
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-200
T1005
T1083
Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87476
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-863
T1078
Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87475
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-862
T1078
Missing authorization in Omnibox in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87474
CRITICAL
CVSS: 9.6
EPSS: 0.5%
CWE-416
T1203
Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87473
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-863
T1078
Incorrect authorization in FileHandling in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87472
MEDIUM
CVSS: 4.2
EPSS: 0.2%
CWE-20
T1190
Improper input validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87471
HIGH
CVSS: 8.1
EPSS: 0.3%
CWE-863
T1078
Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87470
CRITICAL
CVSS: 9.6
EPSS: 0.5%
CWE-1284
Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87469
MEDIUM
CVSS: 4.3
EPSS: 0.2%
CWE-20
T1190
Improper input validation in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy into a privileged page via crafted network traffic. (Chromium security severity: Low)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87468
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-863
T1078
Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87467
HIGH
CVSS: 8.1
EPSS: 0.1%
CWE-362
T1068
Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87466
MEDIUM
CVSS: 4.3
EPSS: 0.3%
CWE-863
T1078
Incorrect authorization in Workers in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87465
MEDIUM
CVSS: 4.2
EPSS: 0.2%
CWE-863
T1078
Incorrect authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87463
MEDIUM
CVSS: 4.8
EPSS: 0.2%
CWE-863
T1078
Incorrect authorization in Certificate in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to potentially spoof address bar via crafted network traffic. (Chromium security severity: Low)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87462
MEDIUM
CVSS: 5.4
EPSS: 0.3%
CWE-451
UI misrepresentation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87461
MEDIUM
CVSS: 4.3
EPSS: 0.2%
CWE-200
T1005
T1083
Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted Chrome extension. (Chromium security severity: Low)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87460
HIGH
CVSS: 8.8
EPSS: 0.4%
CWE-416
T1203
Use after free in Platform in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87459
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-203
Observable discrepancy in Select in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87458
MEDIUM
CVSS: 5.4
EPSS: 0.3%
CWE-451
UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87457
HIGH
CVSS: 8.1
EPSS: 0.1%
CWE-367
Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87456
LOW
CVSS: 3.4
EPSS: 0.3%
CWE-908
T1005
Uninitialized resource in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87455
CRITICAL
CVSS: 9.6
EPSS: 0.5%
CWE-416
T1203
Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87454
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-200
T1005
T1083
Information leak in Enterprise in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87453
MEDIUM
CVSS: 5.3
EPSS: 0.3%
CWE-441
Confused deputy in BackgroundFetch in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87452
LOW
CVSS: 3.1
EPSS: 0.2%
CWE-863
T1078
Incorrect authorization in GPU in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87451
LOW
CVSS: 3.1
EPSS: 0.2%
CWE-200
T1005
T1083
Information leak in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87450
HIGH
CVSS: 7.5
EPSS: 0.3%
CWE-863
T1078
Incorrect authorization in Permissions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87449
MEDIUM
CVSS: 4.3
EPSS: 0.2%
CWE-352
T1189
Cross-site request forgery in DeviceBoundSessionCredentials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87448
CRITICAL
CVSS: 9.6
EPSS: 0.5%
CWE-416
T1203
Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87447
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-863
T1078
Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: High)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87446
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-459
Incomplete cleanup in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87445
MEDIUM
CVSS: 5.4
EPSS: 0.2%
CWE-451
UI misrepresentation in Session in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87444
HIGH
CVSS: 8.8
EPSS: 0.4%
CWE-119
T1203
Memory corruption in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87443
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-862
T1078
Missing authorization in Actor in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87442
LOW
CVSS: 3.1
EPSS: 0.2%
CWE-441
Confused deputy in Prerender in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87441
MEDIUM
CVSS: 6.5
EPSS: 0.2%
CWE-862
T1078
Missing authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87440
HIGH
CVSS: 8.8
EPSS: 0.4%
CWE-125
T1005
Out of bounds read in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87439
MEDIUM
CVSS: 5.3
EPSS: 0.3%
CWE-200
T1005
T1083
Information leak in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87437
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-200
T1005
T1083
Information leak in Frames in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87436
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-459
Incomplete cleanup in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87435
MEDIUM
CVSS: 5.3
EPSS: 0.3%
CWE-200
T1005
T1083
Information leak in ControlledFrame in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87434
LOW
CVSS: 3.1
EPSS: 0.2%
CWE-862
T1078
Missing authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87433
HIGH
CVSS: 8.8
EPSS: 0.3%
CWE-367
Race condition in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87432
MEDIUM
CVSS: 4.2
EPSS: 0.2%
CWE-863
T1078
Incorrect authorization in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87431
HIGH
CVSS: 7.5
EPSS: 0.3%
CWE-862
T1078
Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87430
HIGH
CVSS: 8.8
EPSS: 0.6%
CWE-122
T1203
Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87429
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-862
T1078
Missing authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-85706
CRITICAL
CVSS: 10.0
EPSS: 93.0%
VulnCheck KEV
PoC Available
CWE-22
T1083
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.
Published: 2026-09-12
Mentioned in 4 article(s):
CVE-2026-85921
HIGH
CVSS: 8.2
EPSS: 0.3%
CWE-415
T1203
Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
Published: 2026-09-14
Mentioned in 1 article(s):
CVE-2026-51990
CRITICAL
CVSS: 9.8
EPSS: 0.9%
VulnCheck KEV
PoC Available
CWE-94
T1059
An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary code via the biz_helper.exe component
Published: 2026-09-16
Mentioned in 1 article(s):