SB2026090967 - Multiple vulnerabilities in Google Chrome
Published: September 9, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 230 vulnerabilities.
1) Use-after-free (CVE-ID: CVE-2026-87464)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the WebGL component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
2) Use-after-free (CVE-ID: CVE-2026-87488)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the WebGL component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
3) Out-of-bounds write (CVE-ID: CVE-2026-87438)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted HTML content in WebGL. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.
4) Buffer overflow (CVE-ID: CVE-2026-87527)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a boundary error in WebGL in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger a buffer overflow and execute arbitrary code on the system.
5) Use-after-free (CVE-ID: CVE-2026-87628)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Cast component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
6) Use-after-free (CVE-ID: CVE-2026-87512)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the ANGLE component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
7) Double free (CVE-ID: CVE-2026-87585)
CWE-ID: CWE-415 - Double Free
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger a double-free condition.
The vulnerability exists due to a double free in PDFium when processing a PDF document. A remote attacker can trick a victim into opening a PDF document to trigger a double-free condition.
8) Buffer overflow (CVE-ID: CVE-2026-87444)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a boundary error in Codecs in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger a buffer overflow and execute arbitrary code on the system.
9) Improper Authorization (CVE-ID: CVE-2026-87447)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to incorrect authorization in Network in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.
10) Out-of-bounds read (CVE-ID: CVE-2026-87440)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the Media component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.
11) Use-after-free (CVE-ID: CVE-2026-87633)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Views component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
12) Out-of-bounds read (CVE-ID: CVE-2026-87525)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the Chromoting component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.
13) Use-after-free (CVE-ID: CVE-2026-87578)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Receiver component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
14) Race condition (CVE-ID: CVE-2026-87517)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a race condition in Mobile in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and execute arbitrary code on the target system.
15) Use-after-free (CVE-ID: CVE-2026-87524)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Core component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
16) Missing Authorization (CVE-ID: CVE-2026-87569)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization.
The vulnerability exists due to missing authorization in Views when performing operations in Views. A remote attacker can trigger an operation in Views to bypass authorization.
User interaction is required.
17) Race condition (CVE-ID: CVE-2026-87554)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a race condition in Chromoting in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and execute arbitrary code on the target system.
18) Race condition (CVE-ID: CVE-2026-87467)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a race condition in Updater in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and execute arbitrary code on the target system.
19) Improper Authorization (CVE-ID: CVE-2026-87492)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to incorrect authorization in DevTools in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.
20) Use-after-free (CVE-ID: CVE-2026-87520)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Dawn component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
21) Use-after-free (CVE-ID: CVE-2026-87514)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Views component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
22) Out-of-bounds read (CVE-ID: CVE-2026-87650)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the WebGL component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.
23) Out-of-bounds read (CVE-ID: CVE-2026-87596)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the ANGLE component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.
24) Buffer overflow (CVE-ID: CVE-2026-87654)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a boundary error in ANGLE in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger a buffer overflow and execute arbitrary code on the system.
25) Out-of-bounds read (CVE-ID: CVE-2026-87604)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the ANGLE component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.
26) Out-of-bounds write (CVE-ID: CVE-2026-87621)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted HTML content in ANGLE. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.
27) Use of uninitialized resource (CVE-ID: CVE-2026-87647)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to usage of uninitialized resources in GPU in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger uninitialized usage of resources and compromise the affected system.
28) Use-after-free (CVE-ID: CVE-2026-87646)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Web Authentication component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
29) Improper Validation of Array Index (CVE-ID: CVE-2026-87500)
CWE-ID: CWE-129 - Improper Validation of Array Index
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause an unspecified security impact.
The vulnerability exists due to improper validation of an array index in ANGLE when processing a crafted array index. A remote attacker can provide a crafted array index to cause an unspecified security impact.
User interaction is required.
CWE-ID: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to inject content into DevTools.
The vulnerability exists due to improper input neutralization in DevTools when handling crafted content. A remote attacker can provide crafted content to inject content into DevTools.
User interaction is required.
31) Use-after-free (CVE-ID: CVE-2026-87460)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Platform component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
32) Use-after-free (CVE-ID: CVE-2026-87542)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Input component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
33) Use-after-free (CVE-ID: CVE-2026-87639)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the WebPackaging component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
34) Missing Authorization (CVE-ID: CVE-2026-87552)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to missing authorization in TrustedWebActivities when handling TrustedWebActivities. A remote attacker can invoke a TrustedWebActivity to perform unauthorized actions.
User interaction is required.
35) Improper Authorization (CVE-ID: CVE-2026-87651)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to incorrect authorization in Paint in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.
36) Use-after-free (CVE-ID: CVE-2026-87587)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the V8 component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
37) Type Confusion (CVE-ID: CVE-2026-87564)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a type confusion error within the V8 component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger a type confusion error and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
38) Missing Authorization (CVE-ID: CVE-2026-87498)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access WebUI functionality without authorization.
The vulnerability exists due to missing authorization in WebUI when accessing WebUI functionality. A remote attacker can access WebUI functionality without authorization to access WebUI functionality without authorization.
39) Improper Authorization (CVE-ID: CVE-2026-87499)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to incorrect authorization in Network in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.
40) Use-after-free (CVE-ID: CVE-2026-87607)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Device component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
41) Use-after-free (CVE-ID: CVE-2026-87558)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Payments component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
42) Use-after-free (CVE-ID: CVE-2026-87581)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Payments component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
43) Use-after-free (CVE-ID: CVE-2026-87480)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Printing component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
44) Type Confusion (CVE-ID: CVE-2026-87612)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a type confusion error within the V8 component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger a type confusion error and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
45) Use-after-free (CVE-ID: CVE-2026-87536)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the V8 component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
46) Use-after-free (CVE-ID: CVE-2026-87474)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Payments component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
47) Use-after-free (CVE-ID: CVE-2026-87504)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Core in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
48) Out-of-bounds read (CVE-ID: CVE-2026-87640)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the WebView component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.
49) Out-of-bounds write (CVE-ID: CVE-2026-87491) Exploited
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted HTML content in V8. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.
Note, the vulnerability is being actively exploited in the wild.
50) Observable discrepancy (CVE-ID: CVE-2026-87478)
CWE-ID: CWE-203 - Observable discrepancy
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an observable discrepancy in Autofill when processing autofill data. A remote attacker can interact with Autofill to disclose sensitive information.
User interaction is required.
51) Incomplete cleanup (CVE-ID: CVE-2026-87446)
CWE-ID: CWE-459 - Incomplete cleanup
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to incomplete cleanup in Extensions in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.
52) Use-after-free (CVE-ID: CVE-2026-87657)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within V8 in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
53) Missing Authorization (CVE-ID: CVE-2026-87434)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to missing authorization in CORS when handling cross-origin requests. A remote attacker can trick a victim into visiting a crafted website to disclose sensitive information.
User interaction is required.
54) Missing Authorization (CVE-ID: CVE-2026-87487)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access FileSystem resources without authorization.
The vulnerability exists due to missing authorization in FileSystem when accessing FileSystem resources. A remote attacker can access FileSystem resources without authorization to access FileSystem resources without authorization.
User interaction is required.
55) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-87453)
CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to a confused deputy weakness in BackgroundFetch when handling web content. A remote attacker can cause BackgroundFetch to act on their behalf to perform unauthorized actions.
56) Use-after-free (CVE-ID: CVE-2026-87588)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Chromecast in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
57) Type Confusion (CVE-ID: CVE-2026-87636)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a type confusion error within the XML component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a type confusion error and gain access to sensitive information.
58) Missing Authorization (CVE-ID: CVE-2026-87611)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access file system resources without authorization.
The vulnerability exists due to missing authorization in the FileSystem component when a victim interacts with web content. A remote attacker can cause a victim to interact with web content to access file system resources without authorization.
59) Missing Authorization (CVE-ID: CVE-2026-87606)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization controls.
The vulnerability exists due to missing authorization in SiteIsolation when handling site isolation operations. A remote attacker can exploit the missing authorization controls to bypass authorization controls.
60) Use of uninitialized resource (CVE-ID: CVE-2026-87456)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger an unspecified impact.
The vulnerability exists due to use of an uninitialized resource in the Media component when processing media content. A remote attacker can interact with the Media component to trigger an unspecified impact.
61) Input validation error (CVE-ID: CVE-2026-87553)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to insufficient validation of user-supplied input in SiteIsolation in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.
62) Information disclosure (CVE-ID: CVE-2026-87658)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in Extensions in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
63) Incorrect authorization (CVE-ID: CVE-2026-87465)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to incorrect authorization in Downloads when handling downloads. A remote attacker can exploit the authorization flaw to perform unauthorized actions.
64) Incorrect authorization (CVE-ID: CVE-2026-87515)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access resources without authorization.
The vulnerability exists due to incorrect authorization in FileAPI when handling FileAPI operations. A remote attacker can exploit the authorization flaw to access resources without authorization.
User interaction is required.
65) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-87547)
CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access unintended files.
The vulnerability exists due to incorrect reference resolution in FileSystem when resolving crafted filesystem references. A remote attacker can supply crafted references to access unintended files.
User interaction is required.
66) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-87442)
CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to a confused deputy issue in Prerender when handling crafted web content. A remote attacker can trick a victim into interacting with crafted web content to perform unauthorized actions.
67) Improper privilege management (CVE-ID: CVE-2026-87506)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper privilege management in WebUI when processing user-initiated WebUI interactions. A remote attacker can cause the victim to interact with WebUI content to escalate privileges.
User interaction is required.
68) Race condition (CVE-ID: CVE-2026-87433)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger a race condition.
The vulnerability exists due to a race condition in FileAPI when performing FileAPI operations. A remote attacker can perform FileAPI operations to trigger a race condition.
69) Missing Authorization (CVE-ID: CVE-2026-87557)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access local network resources without authorization.
The vulnerability exists due to missing authorization in LocalNetworkAccess when handling crafted web content. A remote attacker can induce the victim to interact with crafted web content to access local network resources without authorization.
User interaction is required.
70) Race condition (CVE-ID: CVE-2026-87457)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to a race condition in in Updater in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and crash the browser.
71) Improperly implemented security check for standard (CVE-ID: CVE-2026-87503)
CWE-ID: CWE-358 - Improperly Implemented Security Check for Standard
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to incorrect implementation in Downloads in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.
72) Incorrect authorization (CVE-ID: CVE-2026-87481)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access resources without authorization.
The vulnerability exists due to incorrect authorization in WebView when processing crafted web content. A remote attacker can cause WebView to process crafted web content to access resources without authorization.
User interaction is required.
73) Missing Authorization (CVE-ID: CVE-2026-87537)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to missing authorization in Extensions when processing extension requests. A remote attacker can send a crafted extension request to perform unauthorized actions.
User interaction is required.
74) Incorrect authorization (CVE-ID: CVE-2026-87471)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization restrictions.
The vulnerability exists due to incorrect authorization in ServiceWorker when processing crafted web content. A remote attacker can trick the victim into interacting with crafted web content to bypass authorization restrictions.
75) Incorrect authorization (CVE-ID: CVE-2026-87485)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access cross-origin resources.
The vulnerability exists due to incorrect authorization in CORS when processing cross-origin requests. A remote attacker can trick the victim into visiting crafted web content to access cross-origin resources.
76) Incorrect authorization (CVE-ID: CVE-2026-87652)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to incorrect authorization in PushAPI when processing PushAPI requests. A remote attacker can send a crafted PushAPI request to perform unauthorized actions.
User interaction is required.
77) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-87582)
CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to a confused deputy vulnerability in DataTransfer when handling crafted web content. A remote attacker can trick a victim into interacting with crafted web content to perform unauthorized actions.
78) Incorrect authorization (CVE-ID: CVE-2026-87466)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to incorrect authorization in Workers when processing crafted web content. A remote attacker can trick a victim into interacting with crafted web content to perform unauthorized actions.
79) Missing Authorization (CVE-ID: CVE-2026-87603)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization controls for the FileSystem.
The vulnerability exists due to missing authorization checks in the FileSystem when a victim interacts with affected FileSystem functionality. A remote attacker can cause a victim to interact with the affected FileSystem functionality to bypass authorization controls for the FileSystem.
User interaction is required.
80) Race condition (CVE-ID: CVE-2026-87615)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger a race condition in payment processing.
The vulnerability exists due to a race condition in Payments when using payment-related functionality. A remote attacker can interact with the Payments feature to trigger a race condition in payment processing.
User interaction is required.
81) Use of uninitialized resource (CVE-ID: CVE-2026-87642)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger unspecified behavior.
The vulnerability exists due to use of an uninitialized resource in WebGL when handling WebGL resources. A remote attacker can trigger the uninitialized resource condition to trigger unspecified behavior.
82) Incorrect authorization (CVE-ID: CVE-2026-87577)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access resources without proper authorization.
The vulnerability exists due to incorrect authorization in Isolated. Chrome Medium when handling crafted web content. A remote attacker can trick a victim into interacting with crafted web content to access resources without proper authorization.
User interaction is required.
83) Cross-site request forgery (CVE-ID: CVE-2026-87449)
CWE-ID: CWE-352 - Cross-Site Request Forgery (CSRF)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform cross-site request forgery.
The vulnerability exists due to cross-site request forgery in DeviceBoundSessionCredentials when handling cross-site requests. A remote attacker can send a crafted cross-site request to perform cross-site request forgery.
84) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-87613)
CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass security restrictions.
The vulnerability exists due to incorrect reference resolution in Extensions when processing extension references. A remote attacker can provide crafted extension references to bypass security restrictions.
User interaction is required.
85) State Issues (CVE-ID: CVE-2026-87645)
CWE-ID: CWE-371 - State Issues
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to improper state validation in Safebrowsing in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.
86) Missing Authorization (CVE-ID: CVE-2026-87443)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access unauthorized resources.
The vulnerability exists due to missing authorization in Actor when processing crafted web content. A remote attacker can trick a victim into interacting with crafted web content to access unauthorized resources.
87) Integer overflow (CVE-ID: CVE-2026-87630)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to a integer overflow in WebRTC in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.
88) Input validation error (CVE-ID: CVE-2026-87590)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause an unspecified security impact.
The vulnerability exists due to improper input validation in Passwords when processing input. A remote attacker can provide specially crafted input to cause an unspecified security impact.
89) Incorrect authorization (CVE-ID: CVE-2026-87580)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to improper authorization in WebAppInstalls when handling web application installation requests. A remote attacker can exploit the incorrect authorization to perform unauthorized actions.
User interaction is required.
90) Cleartext transmission of sensitive information (CVE-ID: CVE-2026-87482)
CWE-ID: CWE-319 - Cleartext Transmission of Sensitive Information
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to cleartext transmission of sensitive data in HttpsUpgrades when handling sensitive data. A remote attacker can cause HttpsUpgrades to transmit sensitive data in cleartext to disclose sensitive information.
91) Use of uninitialized resource (CVE-ID: CVE-2026-87497)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use of an uninitialized resource in Codecs when processing media content. A remote attacker can cause the browser to process media content to cause a denial of service.
User interaction is required.
92) Buffer overflow (CVE-ID: CVE-2026-87579)
CWE-ID: CWE-120 - Buffer overflow
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a buffer overflow in WebRTC when processing crafted WebRTC content. A remote attacker can trick the victim into processing crafted WebRTC content to cause a denial of service.
93) Use of uninitialized resource (CVE-ID: CVE-2026-87576)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use of an uninitialized resource in the GPU component when processing content. A remote attacker can trigger the vulnerable GPU resource to cause a denial of service.
94) Incorrect authorization (CVE-ID: CVE-2026-87476)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization controls.
The vulnerability exists due to incorrect authorization in Loader when performing authorization checks. A remote attacker can exploit the authorization flaw to bypass authorization controls.
95) Missing Authorization (CVE-ID: CVE-2026-87475)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to missing authorization in Omnibox when processing omnibox input. A remote attacker can cause input to be processed without required authorization checks to perform unauthorized actions.
User interaction is required.
96) Incomplete cleanup (CVE-ID: CVE-2026-87436)
CWE-ID: CWE-459 - Incomplete cleanup
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to incomplete cleanup in Browser in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.
97) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2026-87479)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient policy enforcement in Extensions in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and gain access to sensitive information.
98) Missing Authorization (CVE-ID: CVE-2026-87513)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization.
The vulnerability exists due to missing authorization in ControlledFrame when processing ControlledFrame operations. A remote attacker can perform ControlledFrame operations to bypass authorization.
User interaction is required.
99) Incorrect authorization (CVE-ID: CVE-2026-87432)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization restrictions.
The vulnerability exists due to incorrect authorization in Navigation when handling navigation requests. A remote attacker can initiate a navigation request to bypass authorization restrictions.
100) Missing Authorization (CVE-ID: CVE-2026-87560)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to missing authorization in the Browser component when using the browser. A remote attacker can exploit the missing authorization to perform unauthorized actions.
User interaction is required.
101) Information disclosure (CVE-ID: CVE-2026-87521)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in WebMCP in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
102) Observable discrepancy (CVE-ID: CVE-2026-87539)
CWE-ID: CWE-203 - Observable discrepancy
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an observable discrepancy in the Network component when processing network-related content. A remote attacker can induce user interaction with network-related content to disclose sensitive information.
103) Use-after-free (CVE-ID: CVE-2026-87648)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within ANGLE in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
104) Missing Authorization (CVE-ID: CVE-2026-87534)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to missing authorization in WebView when processing web content. A remote attacker can cause a victim to interact with crafted web content to perform unauthorized actions.
User interaction is required.
105) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-87562)
CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause incorrect reference resolution.
The vulnerability exists due to incorrect reference resolution in the Accessibility component when a victim interacts with web content. A remote attacker can induce a victim to interact with web content to cause incorrect reference resolution.
106) Missing Authorization (CVE-ID: CVE-2026-87556)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization controls.
The vulnerability exists due to missing authorization in the Browser component when processing authorization checks. A remote attacker can exploit the missing authorization to bypass authorization controls.
107) Incorrect authorization (CVE-ID: CVE-2026-87508)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization controls.
The vulnerability exists due to incorrect authorization in Loader when loading content. A remote attacker can cause the browser to load crafted content to bypass authorization controls.
User interaction is required.
108) Integer overflow (CVE-ID: CVE-2026-87643)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to a integer overflow in GPU in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.
109) Input validation error (CVE-ID: CVE-2026-87573)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to insufficient validation of user-supplied input in Network in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.
110) Improper Enforcement of Behavioral Workflow (CVE-ID: CVE-2026-87548)
CWE-ID: CWE-841 - Improper Enforcement of Behavioral Workflow
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass intended installer state validation.
The vulnerability exists due to improper state validation in the installer when processing installer state. A remote attacker can cause the installer to accept an invalid state to bypass intended installer state validation.
User interaction is required.
111) Spoofing attack (CVE-ID: CVE-2026-87501)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause UI misrepresentation.
The vulnerability exists due to UI misrepresentation in the Passwords feature when handling user interaction. A remote attacker can exploit the issue to cause UI misrepresentation.
112) Incorrect authorization (CVE-ID: CVE-2026-87452)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to incorrect authorization in the GPU component when processing crafted web content. A remote attacker can cause a victim to interact with crafted web content to perform unauthorized actions.
113) Observable discrepancy (CVE-ID: CVE-2026-87516)
CWE-ID: CWE-203 - Observable discrepancy
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an observable discrepancy in Navigation when handling navigation requests. A remote attacker can trick the victim into navigating to crafted content to disclose sensitive information.
114) Input validation error (CVE-ID: CVE-2026-87599)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to insufficient validation of user-supplied input in Interstitials in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.
115) Spoofing attack (CVE-ID: CVE-2026-87507)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to misrepresent download-related information.
The vulnerability exists due to improper presentation of critical information in Downloads when displaying download-related information. A remote attacker can cause download-related information to be misrepresented to misrepresent download-related information.
User interaction is required.
116) Spoofing attack (CVE-ID: CVE-2026-87559)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to misrepresent the user interface.
The vulnerability exists due to UI misrepresentation in the UI when rendering web content. A remote attacker can trick the victim into interacting with misrepresented UI elements to misrepresent the user interface.
117) Input validation error (CVE-ID: CVE-2026-87472)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to insufficient validation of user-supplied input in FedCM in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.
118) Improper Restriction of Rendered UI Layers or Frames (CVE-ID: CVE-2026-87486)
CWE-ID: CWE-1021 - Improper Restriction of Rendered UI Layers or Frames
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform clickjacking attacks.
The vulnerability exists due to clickjacking in TrustedWebActivities when rendering web content. A remote attacker can trick a victim into interacting with a crafted interface to perform clickjacking attacks.
User interaction is required.
119) Improper Restriction of Rendered UI Layers or Frames (CVE-ID: CVE-2026-87655)
CWE-ID: CWE-1021 - Improper Restriction of Rendered UI Layers or Frames
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unintended download-related actions.
The vulnerability exists due to clickjacking in the Downloads feature when rendering web content. A remote attacker can trick a victim into interacting with crafted web content to perform unintended download-related actions.
User interaction is required.
120) Spoofing attack (CVE-ID: CVE-2026-87462)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to misrepresent FedCM user interface elements.
The vulnerability exists due to UI misrepresentation in FedCM when rendering FedCM user interface elements. A remote attacker can induce a victim to interact with misleading FedCM user interface elements to misrepresent FedCM user interface elements.
User interaction is required.
121) Spoofing attack (CVE-ID: CVE-2026-87649)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to deceive users through download-related UI.
The vulnerability exists due to UI misrepresentation in Downloads when presenting download-related information. A remote attacker can exploit this flaw to deceive users through download-related UI.
122) Spoofing attack (CVE-ID: CVE-2026-87445)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to misrepresent the user interface.
The vulnerability exists due to user interface misrepresentation in the Session component when interacting with the Session component. A remote attacker can trigger the UI misrepresentation to misrepresent the user interface.
123) Spoofing attack (CVE-ID: CVE-2026-87567)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to misrepresent URL information.
The vulnerability exists due to UI misrepresentation in UrlFormatting when formatting URLs. A remote attacker can cause URL information to be misrepresented to misrepresent URL information.
User interaction is required.
124) Spoofing attack (CVE-ID: CVE-2026-87496)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to mislead users.
The vulnerability exists due to UI misrepresentation in the Browser component when displaying browser UI. A remote attacker can cause browser UI to be misrepresented to mislead users.
125) Missing Authorization (CVE-ID: CVE-2026-87441)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized download-related actions.
The vulnerability exists due to missing authorization in Downloads when handling download-related actions. A remote attacker can invoke download-related functionality without required authorization to perform unauthorized download-related actions.
126) Incomplete cleanup (CVE-ID: CVE-2026-87549)
CWE-ID: CWE-459 - Incomplete cleanup
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to incomplete cleanup in Downloads in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.
127) Spoofing attack (CVE-ID: CVE-2026-87458)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to misrepresent user interface elements.
The vulnerability exists due to UI misrepresentation in Geometry when rendering content. A remote attacker can exploit the UI misrepresentation to misrepresent user interface elements.
User interaction is required.
128) Information disclosure (CVE-ID: CVE-2026-87574)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in ServiceWorker in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
129) Information disclosure (CVE-ID: CVE-2026-87495)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in Scroll in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
130) Information disclosure (CVE-ID: CVE-2026-87541)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in Navigation in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
131) Information disclosure (CVE-ID: CVE-2026-87451)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in Downloads in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
132) Incorrect authorization (CVE-ID: CVE-2026-87570)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access resources without proper authorization.
The vulnerability exists due to incorrect authorization in SiteIsolation when processing web content. A remote attacker can cause SiteIsolation to incorrectly authorize access to resources.
133) Use of uninitialized resource (CVE-ID: CVE-2026-87555)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger an unspecified impact.
The vulnerability exists due to use of an uninitialized resource in the GPU component when processing web content. A remote attacker can trick a victim into accessing web content to trigger an unspecified impact.
User interaction is required.
134) Input validation error (CVE-ID: CVE-2026-87600)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause an unspecified impact.
The vulnerability exists due to improper input validation in Safebrowsing when processing input. A remote attacker can provide specially crafted input to cause an unspecified impact.
User interaction is required.
135) Improper Enforcement of Behavioral Workflow (CVE-ID: CVE-2026-87532)
CWE-ID: CWE-841 - Improper Enforcement of Behavioral Workflow
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to affect Safebrowsing functionality.
The vulnerability exists due to improper state validation in Safebrowsing when processing user-initiated browsing activity. A remote attacker can induce a victim to interact with crafted web content to affect Safebrowsing functionality.
136) Information disclosure (CVE-ID: CVE-2026-87439)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in ServiceWorker in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
137) Incorrect authorization (CVE-ID: CVE-2026-87450)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to incorrect authorization in Permissions when handling permission requests. A remote attacker can exploit the authorization flaw to perform unauthorized actions.
138) Incorrect authorization (CVE-ID: CVE-2026-87505)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to incorrect authorization in FileSystem when processing user-initiated filesystem operations. A remote attacker can induce a victim to interact with web content that invokes filesystem operations to bypass authorization checks.
139) Missing Authorization (CVE-ID: CVE-2026-87622)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to missing authorization in FedCM when processing FedCM requests. A remote attacker can induce the victim to interact with web content to perform unauthorized actions.
User interaction is required.
140) Incorrect authorization (CVE-ID: CVE-2026-87540)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to incorrect authorization in the Isolated component when processing crafted web content. A remote attacker can trick the victim into interacting with crafted web content to perform unauthorized actions.
User interaction is required.
141) Incorrect authorization (CVE-ID: CVE-2026-87594)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to incorrect authorization in DataTransfer when handling DataTransfer operations. A remote attacker can invoke DataTransfer operations to perform unauthorized actions.
142) Observable discrepancy (CVE-ID: CVE-2026-87518)
CWE-ID: CWE-203 - Observable discrepancy
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to obtain information about Safe Browsing behavior.
The vulnerability exists due to an observable discrepancy in Safe Browsing when handling Safe Browsing checks. A remote attacker can trigger the discrepancy to obtain information about Safe Browsing behavior.
User interaction is required.
143) Incorrect authorization (CVE-ID: CVE-2026-87589)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to incorrect authorization in SiteIsolation when handling web content. A remote attacker can cause a victim to interact with web content to perform unauthorized actions.
144) Spoofing attack (CVE-ID: CVE-2026-87484)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to spoof user interface elements.
The vulnerability exists due to UI misrepresentation in Geometry when rendering crafted web content. A remote attacker can cause crafted web content to be rendered to spoof user interface elements.
User interaction is required to view the crafted web content.
145) Insecure DLL loading (CVE-ID: CVE-2026-87530)
CWE-ID: CWE-427 - Uncontrolled Search Path Element
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to an uncontrolled search path element in CredentialProvider when resolving files through an uncontrolled search path. A remote attacker can cause a malicious file to be loaded to execute arbitrary code.
User interaction is required.
146) Improper Encoding or Escaping of Output (CVE-ID: CVE-2026-87550)
CWE-ID: CWE-116 - Improper Encoding or Escaping of Output
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to inject CSS.
The vulnerability exists due to improper encoding or escaping of output in CSS when rendering crafted CSS content. A remote attacker can provide crafted CSS content to inject CSS.
147) Use-after-free (CVE-ID: CVE-2026-87494)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Browser in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
148) Incorrect authorization (CVE-ID: CVE-2026-87483)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization controls.
The vulnerability exists due to incorrect authorization in Browser when processing content. A remote attacker can exploit the authorization flaw to bypass authorization controls.
149) Information disclosure (CVE-ID: CVE-2026-87454)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in Enterprise in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
150) Improper initialization (CVE-ID: CVE-2026-87616)
CWE-ID: CWE-665 - Improper Initialization
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to improper initialization in Views in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.
151) Information Loss or Omission (CVE-ID: CVE-2026-87535)
CWE-ID: CWE-221 - Information Loss or Omission
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause information loss.
The vulnerability exists due to information loss or omission in Safe Browsing when processing crafted web content. A remote attacker can trick the victim into visiting a crafted website to cause information loss.
152) Incorrect authorization (CVE-ID: CVE-2026-87644)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to incorrect authorization in Views when processing crafted web content. A remote attacker can trick a victim into interacting with crafted web content to perform unauthorized actions.
User interaction is required.
153) Use-after-free (CVE-ID: CVE-2026-87533)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within DevTools in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
154) Spoofing attack (CVE-ID: CVE-2026-87635)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to misrepresent payment-related user interface elements.
The vulnerability exists due to UI misrepresentation in Payments when rendering payment-related user interface elements. A remote attacker can cause payment-related user interface elements to be misrepresented.
User interaction is required.
155) Race condition (CVE-ID: CVE-2026-87641)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to a race condition in in Browser in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and crash the browser.
156) Missing Authorization (CVE-ID: CVE-2026-87431)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to missing authorization in Extensions when processing user interaction. A remote attacker can induce a victim to interact with content to perform unauthorized actions.
157) Missing Authorization (CVE-ID: CVE-2026-87493)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized filesystem operations.
The vulnerability exists due to missing authorization in FileSystem when processing crafted web content. A remote attacker can provide crafted web content to perform unauthorized filesystem operations.
User interaction is required.
158) Use-after-free (CVE-ID: CVE-2026-87625)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within V8 in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
159) Incorrect authorization (CVE-ID: CVE-2026-87468)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization restrictions.
The vulnerability exists due to incorrect authorization in the Isolated component when processing crafted web content. A remote attacker can trick a victim into interacting with crafted web content to bypass authorization restrictions.
160) Origin validation error (CVE-ID: CVE-2026-87563)
CWE-ID: CWE-346 - Origin Validation Error
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass origin-based security restrictions.
The vulnerability exists due to improper origin validation in Paint when processing web content. A remote attacker can trick a victim into visiting a crafted website to bypass origin-based security restrictions.
161) Input validation error (CVE-ID: CVE-2026-87510)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to insufficient validation of user-supplied input in FileAPI in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.
162) Information disclosure (CVE-ID: CVE-2026-87435)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in ControlledFrame in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
163) Information disclosure (CVE-ID: CVE-2026-87531)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in CORS in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
164) Use-after-free (CVE-ID: CVE-2026-87637)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Extensions in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
165) Numeric Truncation Error (CVE-ID: CVE-2026-87529)
CWE-ID: CWE-197 - Numeric Truncation Error
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger an incorrect numeric conversion during media processing.
The vulnerability exists due to numeric truncation in the Media component when processing media content. A remote attacker can induce the victim to process crafted media content to trigger an incorrect numeric conversion during media processing.
166) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-87470)
CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger an unspecified impact.
The vulnerability exists due to improper quantity validation in Tint when processing input. A remote attacker can provide input containing an improperly validated quantity to trigger an unspecified impact.
167) Out-of-bounds read (CVE-ID: CVE-2026-87586)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the ANGLE component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.
168) Incorrect authorization (CVE-ID: CVE-2026-87584)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to improper authorization in WebUI when handling WebUI requests. A remote attacker can induce a user to interact with WebUI functionality to perform unauthorized actions.
User interaction is required.
169) Cross-site scripting (CVE-ID: CVE-2026-87632)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to execute arbitrary script in a victim's browser.
The vulnerability exists due to improper neutralization of input during web page generation in SanitizerAPI when processing crafted web content. A remote attacker can cause a victim to process crafted web content to execute arbitrary script in a victim's browser.
User interaction is required.
170) Type Confusion (CVE-ID: CVE-2026-87528)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a type confusion error within the Rust component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a type confusion error and gain access to sensitive information.
171) Observable discrepancy (CVE-ID: CVE-2026-87623)
CWE-ID: CWE-203 - Observable discrepancy
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose information.
The vulnerability exists due to an observable discrepancy in the DOM when rendering crafted web content. A remote attacker can cause an observable discrepancy in the DOM to disclose information.
User interaction is required to render the crafted web content.
172) Observable discrepancy (CVE-ID: CVE-2026-87566)
CWE-ID: CWE-203 - Observable discrepancy
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an observable discrepancy in Layout when rendering crafted web content. A remote attacker can trick the victim into visiting a crafted website to disclose sensitive information.
User interaction is required.
173) Out-of-bounds write (CVE-ID: CVE-2026-87638)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted HTML content in Media. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.
174) Use-after-free (CVE-ID: CVE-2026-87455)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Aura in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
175) Incorrect authorization (CVE-ID: CVE-2026-87591)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to incorrect authorization in Extensions when handling extension-related operations. A remote attacker can invoke extension functionality without proper authorization to perform unauthorized actions.
176) Use-after-free (CVE-ID: CVE-2026-87526)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Passwords in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
177) Use-after-free (CVE-ID: CVE-2026-87609)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Sharing in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
178) Incorrect authorization (CVE-ID: CVE-2026-87610)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to incorrect authorization in the Omnibox when processing Omnibox input. A remote attacker can cause a victim to interact with the Omnibox to perform unauthorized actions.
179) Incorrect authorization (CVE-ID: CVE-2026-87626)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access DeviceBoundSessionCredentials without authorization.
The vulnerability exists due to incorrect authorization in DeviceBoundSessionCredentials when performing authorization checks. A remote attacker can trigger the flawed authorization check to access DeviceBoundSessionCredentials without authorization.
User interaction is required.
180) Incorrect authorization (CVE-ID: CVE-2026-87629)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to incorrect authorization in sources when handling crafted content. A remote attacker can induce a victim to interact with crafted content to perform unauthorized actions.
181) Spoofing attack (CVE-ID: CVE-2026-87653)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to misrepresent browser user interface elements.
The vulnerability exists due to user interface misrepresentation in the FullScreen feature when displaying crafted web content in fullscreen mode. A remote attacker can trick a victim into viewing crafted web content to misrepresent browser user interface elements.
User interaction is required.
182) Use-after-free (CVE-ID: CVE-2026-87634)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to use-after-free error in WebPackaging in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.
183) Missing Authorization (CVE-ID: CVE-2026-87429)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to missing authorization in ServiceWorker when handling service worker operations. A remote attacker can induce a victim to interact with browser content to perform unauthorized actions.
184) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-87618)
CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause incorrect reference resolution.
The vulnerability exists due to incorrect reference resolution in Storage when resolving references. A remote attacker can cause a reference to be resolved incorrectly to cause incorrect reference resolution.
185) Incorrect authorization (CVE-ID: CVE-2026-87614)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization controls.
The vulnerability exists due to incorrect authorization in ServiceWorker when handling ServiceWorker operations. A remote attacker can exploit the incorrect authorization to bypass authorization controls.
186) Observable discrepancy (CVE-ID: CVE-2026-87619)
CWE-ID: CWE-203 - Observable discrepancy
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an observable discrepancy in Prefetch when prefetching content. A remote attacker can observe differences in Prefetch behavior to disclose sensitive information.
187) Incorrect authorization (CVE-ID: CVE-2026-87561)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to incorrect authorization in Web Authentication when processing Web Authentication requests. A remote attacker can submit a crafted Web Authentication request to perform unauthorized actions.
188) Incorrect authorization (CVE-ID: CVE-2026-87598)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access ServiceWorker functionality without authorization.
The vulnerability exists due to incorrect authorization in ServiceWorker when processing crafted web content. A remote attacker can induce a victim to interact with crafted web content to access ServiceWorker functionality without authorization.
189) Incorrect authorization (CVE-ID: CVE-2026-87519)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access protected Safe Browsing functionality.
The vulnerability exists due to incorrect authorization in Safe Browsing when using the Safe Browsing feature. A remote attacker can exploit the authorization flaw to access protected Safe Browsing functionality.
User interaction is required.
190) Missing Authorization (CVE-ID: CVE-2026-87543)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to missing authorization in Core when a victim interacts with web content. A remote attacker can cause a victim to interact with web content to perform unauthorized actions.
191) Missing Authorization (CVE-ID: CVE-2026-87522)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to missing authorization in WebView when handling web content. A remote attacker can access functionality without authorization to perform unauthorized actions.
192) Input validation error (CVE-ID: CVE-2026-87568)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger an unspecified security impact.
The vulnerability exists due to improper input validation in Chromium when processing input. A remote attacker can provide specially crafted input to trigger an unspecified security impact.
193) Improper Enforcement of Behavioral Workflow (CVE-ID: CVE-2026-87656)
CWE-ID: CWE-841 - Improper Enforcement of Behavioral Workflow
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause an unspecified impact.
The vulnerability exists due to improper state validation in Safebrowsing when handling Safe Browsing state. A remote attacker can trigger an invalid state to cause an unspecified impact.
194) Missing Authorization (CVE-ID: CVE-2026-87511)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access DevTools functionality without authorization.
The vulnerability exists due to missing authorization in DevTools when accessing DevTools functionality. A remote attacker can access DevTools functionality without authorization to access DevTools functionality without authorization.
195) Interpretation Conflict (CVE-ID: CVE-2026-87627)
CWE-ID: CWE-436 - Interpretation Conflict
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass Safe Browsing protections.
The vulnerability exists due to an interpretation conflict in Safe Browsing when processing web content. A remote attacker can provide crafted web content to bypass Safe Browsing protections.
User interaction is required.
196) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2026-87595)
CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause the browser to send requests to arbitrary destinations.
The vulnerability exists due to server-side request forgery in Mobile when processing crafted content. A remote attacker can trick the victim into processing crafted content to cause the browser to send requests to arbitrary destinations.
197) Out-of-bounds read (CVE-ID: CVE-2026-87592)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to a boundary condition within the Tint component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and crash the browser.
198) Observable discrepancy (CVE-ID: CVE-2026-87620)
CWE-ID: CWE-203 - Observable discrepancy
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an observable discrepancy in SVG when rendering crafted SVG content. A remote attacker can cause the browser to render crafted SVG content to disclose sensitive information.
199) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-87502)
CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause the browser to perform unauthorized actions.
The vulnerability exists due to a confused deputy condition in the Fullscreen feature when handling fullscreen requests. A remote attacker can trick a victim into interacting with fullscreen content to cause the browser to perform unauthorized actions.
200) Use-after-free (CVE-ID: CVE-2026-87448)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to use-after-free error in DevTools in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.
201) Observable discrepancy (CVE-ID: CVE-2026-87459)
CWE-ID: CWE-203 - Observable discrepancy
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to obtain information.
The vulnerability exists due to an observable discrepancy in Select when interacting with Select. A remote attacker can trigger the observable discrepancy to obtain information.
202) Incorrect authorization (CVE-ID: CVE-2026-87463)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization controls.
The vulnerability exists due to incorrect authorization in Certificate when handling certificate-related operations. A remote attacker can exploit the issue to bypass authorization controls.
User interaction is required.
203) Type conversion (CVE-ID: CVE-2026-87546)
CWE-ID: CWE-704 - Type conversion
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a low-severity security impact.
The vulnerability exists due to incorrect type conversion or cast in Safe Browsing when performing type conversions or casts. A remote attacker can trigger the vulnerable code path to cause a low-severity security impact.
204) Improper Restriction of Rendered UI Layers or Frames (CVE-ID: CVE-2026-87538)
CWE-ID: CWE-1021 - Improper Restriction of Rendered UI Layers or Frames
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause users to perform unintended actions.
The vulnerability exists due to clickjacking in Input when rendering crafted web content. A remote attacker can trick a victim into interacting with crafted web content to cause users to perform unintended actions.
205) Information disclosure (CVE-ID: CVE-2026-87545)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an unspecified flaw in Mobile Chrome when handling crafted content. A remote attacker can trick a victim into interacting with crafted content to disclose sensitive information.
206) Use-after-free (CVE-ID: CVE-2026-87617)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to use-after-free error in DevTools in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.
207) Race condition (CVE-ID: CVE-2026-87523)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to a race condition in in DataTransfer in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and crash the browser.
208) Information disclosure (CVE-ID: CVE-2026-87565)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an unspecified flaw in the Passwords component when a victim interacts with content. A remote attacker can induce a victim to interact with content to disclose sensitive information.
209) Spoofing attack (CVE-ID: CVE-2026-87597)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to misrepresent user interface content.
The vulnerability exists due to UI misrepresentation in CustomTabs when displaying CustomTabs content. A remote attacker can present misleading user interface content to misrepresent user interface content.
User interaction is required.
210) Spoofing attack (CVE-ID: CVE-2026-87624)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to display misleading password-related information.
The vulnerability exists due to user interface misrepresentation in the Passwords feature when a victim interacts with crafted web content. A remote attacker can induce the victim to interact with misleading password-related information to display misleading password-related information.
211) Missing Authorization (CVE-ID: CVE-2026-87605)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to missing authorization in the Contacts feature when processing contact-related requests. A remote attacker can interact with the Contacts feature to disclose sensitive information.
212) Information disclosure (CVE-ID: CVE-2026-87490)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an unspecified flaw in the Transactions Platform when a victim interacts with content. A remote attacker can cause a victim to interact with content to disclose sensitive information.
213) Spoofing attack (CVE-ID: CVE-2026-87583)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to misrepresent password-related user interface elements.
The vulnerability exists due to user interface misrepresentation in Passwords when rendering password-related user interface elements. A remote attacker can cause password-related user interface elements to be misrepresented to mislead users.
User interaction is required.
214) Incorrect authorization (CVE-ID: CVE-2026-87509)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization restrictions.
The vulnerability exists due to incorrect authorization in the Updater when handling update operations. A remote attacker can exploit the authorization flaw to bypass authorization restrictions.
215) Incorrect authorization (CVE-ID: CVE-2026-87473)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access resources without authorization.
The vulnerability exists due to improper authorization in FileHandling when processing content after user interaction. A remote attacker can induce a victim to interact with content to access resources without authorization.
216) Information disclosure (CVE-ID: CVE-2026-87461)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an unspecified information disclosure flaw in Core when processing content after user interaction. A remote attacker can cause a victim to interact with crafted content to disclose sensitive information.
217) Missing Authorization (CVE-ID: CVE-2026-87631)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access restricted DOM resources.
The vulnerability exists due to missing authorization in the DOM when rendering crafted web content. A remote attacker can induce a victim to render crafted web content to access restricted DOM resources.
User interaction is required to render crafted web content.
218) Input validation error (CVE-ID: CVE-2026-87469)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a low-severity security impact.
The vulnerability exists due to improper input validation in Extensions when processing input. A remote attacker can provide specially crafted input to cause a low-severity security impact.
219) Buffer overflow (CVE-ID: CVE-2026-87489)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger memory corruption.
The vulnerability exists due to memory corruption in V8 when processing web content. A remote attacker can induce a victim to interact with web content to trigger memory corruption.
User interaction is required.
220) Incorrect authorization (CVE-ID: CVE-2026-87575)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to incorrect authorization in Loader when performing authorization checks. A remote attacker can exploit the authorization flaw to perform unauthorized actions.
221) Improper Certificate Validation (CVE-ID: CVE-2026-87571)
CWE-ID: CWE-295 - Improper Certificate Validation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause Chrome to accept improperly validated certificates.
The vulnerability exists due to improper certificate validation in Loader when processing certificates. A remote attacker can provide an improperly validated certificate to cause Chrome to accept improperly validated certificates.
User interaction is required.
222) Information disclosure (CVE-ID: CVE-2026-87477)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an unspecified information disclosure flaw in Chrome Core when a user interacts with content processed by Chrome. A remote attacker can cause a user to interact with content processed by Chrome to disclose sensitive information.
223) Improper Certificate Validation (CVE-ID: CVE-2026-87551)
CWE-ID: CWE-295 - Improper Certificate Validation
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass certificate validation.
The vulnerability exists due to improper certificate validation in CORS when handling CORS requests. A remote attacker can send a crafted CORS request to bypass certificate validation.
224) Improper Certificate Validation (CVE-ID: CVE-2026-87608)
CWE-ID: CWE-295 - Improper Certificate Validation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass certificate validation.
The vulnerability exists due to improper certificate validation in FedCM when validating certificates. A remote attacker can cause FedCM to improperly validate a certificate to bypass certificate validation.
User interaction is required.
225) Information disclosure (CVE-ID: CVE-2026-87437)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an unspecified flaw in Frames when handling frames. A remote attacker can induce a victim to interact with web content to disclose sensitive information.
226) Out-of-bounds read (CVE-ID: CVE-2026-87602)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to a boundary condition within the ANGLE component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and crash the browser.
227) Race condition (CVE-ID: CVE-2026-87601)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to a race condition in in V8 in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and crash the browser.
228) Incorrect authorization (CVE-ID: CVE-2026-87544)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization restrictions.
The vulnerability exists due to incorrect authorization in Extensions when handling extension-related requests. A remote attacker can send a crafted extension-related request to bypass authorization restrictions.
User interaction is required.
229) Buffer overflow (CVE-ID: CVE-2026-87430)
CWE-ID: CWE-120 - Buffer overflow
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a buffer overflow in WebRTC when processing web content. A remote attacker can cause WebRTC to process crafted web content to cause a denial of service.
User interaction is required.
230) Information disclosure (CVE-ID: CVE-2026-87593)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper information disclosure in the Editing component when rendering web content. A remote attacker can cause web content to be rendered to disclose sensitive information.
User interaction is required.
Remediation
Install update from vendor's website.
References
- https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html
- https://crbug.com/544163112
- https://crbug.com/546252753
- https://crbug.com/548127218
- https://crbug.com/548130125
- https://crbug.com/553770012
- https://crbug.com/541715128
- https://crbug.com/540817065
- https://crbug.com/489489002
- https://crbug.com/503464711
- https://crbug.com/513458719
- https://crbug.com/516996291
- https://crbug.com/517336350
- https://crbug.com/517371367
- https://crbug.com/517581661
- https://crbug.com/522546457
- https://crbug.com/523277481
- https://crbug.com/524423633
- https://crbug.com/524453236
- https://crbug.com/529123409
- https://crbug.com/529878021
- https://crbug.com/532916987
- https://crbug.com/534912743
- https://crbug.com/536434693
- https://crbug.com/536444790
- https://crbug.com/536648007
- https://crbug.com/536664909
- https://crbug.com/536673946
- https://crbug.com/539754136
- https://crbug.com/540019091
- https://crbug.com/540021969
- https://crbug.com/540058837
- https://crbug.com/542756749
- https://crbug.com/544415098
- https://crbug.com/547426657
- https://crbug.com/550141694
- https://crbug.com/550360762
- https://crbug.com/552342545
- https://crbug.com/552413517
- https://crbug.com/553118043
- https://crbug.com/553122131
- https://crbug.com/553128689
- https://crbug.com/553129531
- https://crbug.com/553928324
- https://crbug.com/554236352
- https://crbug.com/554421904
- https://crbug.com/554558968
- https://crbug.com/499206649
- https://crbug.com/498482618
- https://crbug.com/543557673
- https://crbug.com/40060525
- https://crbug.com/483435192
- https://crbug.com/542146471
- https://crbug.com/493322521
- https://crbug.com/495429423
- https://crbug.com/495444970
- https://crbug.com/495515356
- https://crbug.com/495541478
- https://crbug.com/495876543
- https://crbug.com/495933780
- https://crbug.com/496231550
- https://crbug.com/496595299
- https://crbug.com/496615345
- https://crbug.com/496616790
- https://crbug.com/497093426
- https://crbug.com/497111188
- https://crbug.com/497443419
- https://crbug.com/497551905
- https://crbug.com/497574154
- https://crbug.com/497635917
- https://crbug.com/497837188
- https://crbug.com/497986036
- https://crbug.com/498730641
- https://crbug.com/498732709
- https://crbug.com/498869663
- https://crbug.com/499230506
- https://crbug.com/499425100
- https://crbug.com/500094528
- https://crbug.com/500467033
- https://crbug.com/501627201
- https://crbug.com/501643868
- https://crbug.com/501644790
- https://crbug.com/501700023
- https://crbug.com/501850947
- https://crbug.com/501889544
- https://crbug.com/502611474
- https://crbug.com/502768228
- https://crbug.com/502783118
- https://crbug.com/502814490
- https://crbug.com/502986244
- https://crbug.com/503736006
- https://crbug.com/504670493
- https://crbug.com/504690157
- https://crbug.com/506385755
- https://crbug.com/506390077
- https://crbug.com/507225626
- https://crbug.com/511754574
- https://crbug.com/511772271
- https://crbug.com/511773417
- https://crbug.com/511820041
- https://crbug.com/511824746
- https://crbug.com/512986143
- https://crbug.com/513003268
- https://crbug.com/513048243
- https://crbug.com/513134173
- https://crbug.com/513135531
- https://crbug.com/513192482
- https://crbug.com/513346220
- https://crbug.com/513416699
- https://crbug.com/513438970
- https://crbug.com/513495219
- https://crbug.com/513509804
- https://crbug.com/513524705
- https://crbug.com/513608513
- https://crbug.com/513702096
- https://crbug.com/514009699
- https://crbug.com/514011926
- https://crbug.com/514016678
- https://crbug.com/514017067
- https://crbug.com/514023309
- https://crbug.com/514041087
- https://crbug.com/514055890
- https://crbug.com/514056835
- https://crbug.com/514069596
- https://crbug.com/514074827
- https://crbug.com/514556469
- https://crbug.com/516534546
- https://crbug.com/517072005
- https://crbug.com/517092658
- https://crbug.com/517122234
- https://crbug.com/517156678
- https://crbug.com/517178299
- https://crbug.com/517215407
- https://crbug.com/517337579
- https://crbug.com/517339356
- https://crbug.com/517369256
- https://crbug.com/517415433
- https://crbug.com/517432155
- https://crbug.com/517597701
- https://crbug.com/517602176
- https://crbug.com/517721914
- https://crbug.com/517732336
- https://crbug.com/517917560
- https://crbug.com/518002426
- https://crbug.com/518039263
- https://crbug.com/518081914
- https://crbug.com/518082852
- https://crbug.com/520161438
- https://crbug.com/520201931
- https://crbug.com/520389619
- https://crbug.com/520469117
- https://crbug.com/520572550
- https://crbug.com/521616899
- https://crbug.com/521620916
- https://crbug.com/522304737
- https://crbug.com/523091391
- https://crbug.com/523313374
- https://crbug.com/523741272
- https://crbug.com/532921336
- https://crbug.com/532931962
- https://crbug.com/532952073
- https://crbug.com/532957878
- https://crbug.com/533070113
- https://crbug.com/533597592
- https://crbug.com/534863145
- https://crbug.com/536423794
- https://crbug.com/536446354
- https://crbug.com/536598187
- https://crbug.com/537466493
- https://crbug.com/538197156
- https://crbug.com/539569491
- https://crbug.com/540015493
- https://crbug.com/540021850
- https://crbug.com/540024134
- https://crbug.com/542565481
- https://crbug.com/543938457
- https://crbug.com/544484669
- https://crbug.com/547322272
- https://crbug.com/547592631
- https://crbug.com/553155590
- https://crbug.com/490773579
- https://crbug.com/40058710
- https://crbug.com/349994197
- https://crbug.com/497025031
- https://crbug.com/497203958
- https://crbug.com/497359396
- https://crbug.com/497433347
- https://crbug.com/499217288
- https://crbug.com/499218516
- https://crbug.com/501763003
- https://crbug.com/502452118
- https://crbug.com/507219126
- https://crbug.com/513143955
- https://crbug.com/513245072
- https://crbug.com/513395384
- https://crbug.com/513473551
- https://crbug.com/513726466
- https://crbug.com/513947572
- https://crbug.com/514489101
- https://crbug.com/515426792
- https://crbug.com/516965176
- https://crbug.com/517219513
- https://crbug.com/517776674
- https://crbug.com/517926950
- https://crbug.com/522399466
- https://crbug.com/523243507
- https://crbug.com/523442920
- https://crbug.com/532933816
- https://crbug.com/532968511
- https://crbug.com/533018632
- https://crbug.com/533044125
- https://crbug.com/533084499
- https://crbug.com/533112829
- https://crbug.com/533116484
- https://crbug.com/535718578
- https://crbug.com/537101736
- https://crbug.com/537470182
- https://crbug.com/537476242
- https://crbug.com/538715523
- https://crbug.com/539453394
- https://crbug.com/540013886
- https://crbug.com/540046516
- https://crbug.com/540059211
- https://crbug.com/540070236
- https://crbug.com/540072282
- https://crbug.com/540082621
- https://crbug.com/541546782
- https://crbug.com/541604100
- https://crbug.com/542355360
- https://crbug.com/542449805
- https://crbug.com/553252820