CVE Database

132506+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-87506
8.3 HIGH

Privilege elevation in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code …

Sep 9, 2026
CVE-2026-87505
8.1 HIGH

Incorrect authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via …

Sep 9, 2026
CVE-2026-87504
9.6 CRITICAL

Use after free in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox …

Sep 9, 2026
CVE-2026-87503
6.5 MEDIUM

Inappropriate implementation in Downloads in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions …

Sep 9, 2026
CVE-2026-87502
4.2 MEDIUM

Confused deputy in Fullscreen in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to …

Sep 9, 2026
CVE-2026-87501
5.4 MEDIUM

UI misrepresentation in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security …

Sep 9, 2026
CVE-2026-87500
9.6 CRITICAL

Improper validation of array index in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox …

Sep 9, 2026
CVE-2026-87499
8.1 HIGH

Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via …

Sep 9, 2026
CVE-2026-87498
3.1 LOW

Missing authorization in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy …

Sep 9, 2026
CVE-2026-87497
4.3 MEDIUM

Uninitialized resource in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. …

Sep 9, 2026
CVE-2026-87496
5.4 MEDIUM

UI misrepresentation in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML …

Sep 9, 2026
CVE-2026-87495
4.3 MEDIUM

Information leak in Scroll in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via …

Sep 9, 2026
CVE-2026-87494
9.6 CRITICAL

Use after free in Browser in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code …

Sep 9, 2026
CVE-2026-87493
6.5 MEDIUM

Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted …

Sep 9, 2026
CVE-2026-87492
9.6 CRITICAL

Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted …

Sep 9, 2026
CVE-2026-87491
8.8 HIGH KEV

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a …

Sep 9, 2026
CVE-2026-87490
6.5 MEDIUM

Information leak in Transactions Platform in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium …

Sep 9, 2026
CVE-2026-87489
8.8 HIGH

Memory corruption in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted …

Sep 9, 2026
CVE-2026-87488
9.6 CRITICAL

Use after free in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox …

Sep 9, 2026
CVE-2026-87487
8.3 HIGH

Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to …

Sep 9, 2026
CVE-2026-87486
4.0 MEDIUM

Clickjacking in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to spoof address bar via a co-installed app. (Chromium …

Sep 9, 2026
CVE-2026-87485
3.1 LOW

Incorrect authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy …

Sep 9, 2026
CVE-2026-87484
5.4 MEDIUM

UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML …

Sep 9, 2026
CVE-2026-87483
6.5 MEDIUM

Incorrect authorization in Browser in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted …

Sep 9, 2026
CVE-2026-87482
5.9 MEDIUM

Cleartext transmission of sensitive data in HttpsUpgrades in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via …

Sep 9, 2026
CVE-2026-87481
8.3 HIGH

Incorrect authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially …

Sep 9, 2026
CVE-2026-87480
8.3 HIGH

Use after free in Printing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary …

Sep 9, 2026
CVE-2026-87479
8.3 HIGH

Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering …

Sep 9, 2026
CVE-2026-87478
6.5 MEDIUM

Observable discrepancy in Autofill in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security …

Sep 9, 2026
CVE-2026-87477
6.5 MEDIUM

Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security …

Sep 9, 2026
CVE-2026-87476
6.5 MEDIUM

Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security …

Sep 9, 2026
CVE-2026-87475
6.5 MEDIUM

Missing authorization in Omnibox in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions into a privileged …

Sep 9, 2026
CVE-2026-87474
9.6 CRITICAL

Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a …

Sep 9, 2026
CVE-2026-87473
6.5 MEDIUM

Incorrect authorization in FileHandling in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted …

Sep 9, 2026
CVE-2026-87472
4.2 MEDIUM

Improper input validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements …

Sep 9, 2026
CVE-2026-87471
8.1 HIGH

Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via …

Sep 9, 2026
CVE-2026-87470
9.6 CRITICAL

Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the …

Sep 9, 2026
CVE-2026-87469
4.3 MEDIUM

Improper input validation in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy into a privileged page via …

Sep 9, 2026
CVE-2026-87468
6.5 MEDIUM

Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security …

Sep 9, 2026
CVE-2026-87467
8.1 HIGH

Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to potentially execute arbitrary code outside the sandbox …

Sep 9, 2026
CVE-2026-87466
4.3 MEDIUM

Incorrect authorization in Workers in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium …

Sep 9, 2026
CVE-2026-87465
4.2 MEDIUM

Incorrect authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via …

Sep 9, 2026
CVE-2026-87464
9.6 CRITICAL

Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted …

Sep 9, 2026
CVE-2026-87463
4.8 MEDIUM

Incorrect authorization in Certificate in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to potentially spoof address bar via crafted network …

Sep 9, 2026
CVE-2026-87462
5.4 MEDIUM

UI misrepresentation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML …

Sep 9, 2026
CVE-2026-87461
4.3 MEDIUM

Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted Chrome extension. (Chromium security …

Sep 9, 2026
CVE-2026-87460
8.8 HIGH

Use after free in Platform in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Sep 9, 2026
CVE-2026-87459
6.5 MEDIUM

Observable discrepancy in Select in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security …

Sep 9, 2026
CVE-2026-87458
5.4 MEDIUM

UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML …

Sep 9, 2026
CVE-2026-87457
8.1 HIGH

Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via …

Sep 9, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.