SB2026090967 - Multiple vulnerabilities in Google Chrome



SB2026090967 - Multiple vulnerabilities in Google Chrome

Published: September 9, 2026

Security Bulletin ID SB2026090967
CSH Severity
Critical
Patch available
YES
Number of vulnerabilities 230
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Critical 0% High 14% Medium 23% Low 62%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 230 vulnerabilities.


1) Use-after-free (CVE-ID: CVE-2026-87464)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the WebGL component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


2) Use-after-free (CVE-ID: CVE-2026-87488)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the WebGL component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


3) Out-of-bounds write (CVE-ID: CVE-2026-87438)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted HTML content in WebGL. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.


4) Buffer overflow (CVE-ID: CVE-2026-87527)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a boundary error in WebGL in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger a buffer overflow and execute arbitrary code on the system.


5) Use-after-free (CVE-ID: CVE-2026-87628)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Cast component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


6) Use-after-free (CVE-ID: CVE-2026-87512)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the ANGLE component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


7) Double free (CVE-ID: CVE-2026-87585)

CWE-ID: CWE-415 - Double Free

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger a double-free condition.

The vulnerability exists due to a double free in PDFium when processing a PDF document. A remote attacker can trick a victim into opening a PDF document to trigger a double-free condition.


8) Buffer overflow (CVE-ID: CVE-2026-87444)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a boundary error in Codecs in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger a buffer overflow and execute arbitrary code on the system.


9) Improper Authorization (CVE-ID: CVE-2026-87447)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to incorrect authorization in Network in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.


10) Out-of-bounds read (CVE-ID: CVE-2026-87440)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the Media component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.


11) Use-after-free (CVE-ID: CVE-2026-87633)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Views component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


12) Out-of-bounds read (CVE-ID: CVE-2026-87525)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the Chromoting component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.


13) Use-after-free (CVE-ID: CVE-2026-87578)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Receiver component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


14) Race condition (CVE-ID: CVE-2026-87517)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a race condition in Mobile in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and execute arbitrary code on the target system.


15) Use-after-free (CVE-ID: CVE-2026-87524)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Core component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


16) Missing Authorization (CVE-ID: CVE-2026-87569)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization.

The vulnerability exists due to missing authorization in Views when performing operations in Views. A remote attacker can trigger an operation in Views to bypass authorization.

User interaction is required.


17) Race condition (CVE-ID: CVE-2026-87554)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a race condition in Chromoting in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and execute arbitrary code on the target system.


18) Race condition (CVE-ID: CVE-2026-87467)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a race condition in Updater in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and execute arbitrary code on the target system.


19) Improper Authorization (CVE-ID: CVE-2026-87492)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to incorrect authorization in DevTools in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.


20) Use-after-free (CVE-ID: CVE-2026-87520)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Dawn component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


21) Use-after-free (CVE-ID: CVE-2026-87514)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Views component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


22) Out-of-bounds read (CVE-ID: CVE-2026-87650)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the WebGL component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.


23) Out-of-bounds read (CVE-ID: CVE-2026-87596)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the ANGLE component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.


24) Buffer overflow (CVE-ID: CVE-2026-87654)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a boundary error in ANGLE in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger a buffer overflow and execute arbitrary code on the system.


25) Out-of-bounds read (CVE-ID: CVE-2026-87604)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the ANGLE component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.


26) Out-of-bounds write (CVE-ID: CVE-2026-87621)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted HTML content in ANGLE. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.


27) Use of uninitialized resource (CVE-ID: CVE-2026-87647)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to usage of uninitialized resources in GPU in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger uninitialized usage of resources and compromise the affected system.


28) Use-after-free (CVE-ID: CVE-2026-87646)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Web Authentication component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


29) Improper Validation of Array Index (CVE-ID: CVE-2026-87500)

CWE-ID: CWE-129 - Improper Validation of Array Index

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause an unspecified security impact.

The vulnerability exists due to improper validation of an array index in ANGLE when processing a crafted array index. A remote attacker can provide a crafted array index to cause an unspecified security impact.

User interaction is required.


30) Improper Neutralization of Special Elements in Output Used by a Downstream Component (CVE-ID: CVE-2026-87572)

CWE-ID: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to inject content into DevTools.

The vulnerability exists due to improper input neutralization in DevTools when handling crafted content. A remote attacker can provide crafted content to inject content into DevTools.

User interaction is required.


31) Use-after-free (CVE-ID: CVE-2026-87460)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Platform component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


32) Use-after-free (CVE-ID: CVE-2026-87542)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Input component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


33) Use-after-free (CVE-ID: CVE-2026-87639)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the WebPackaging component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


34) Missing Authorization (CVE-ID: CVE-2026-87552)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to missing authorization in TrustedWebActivities when handling TrustedWebActivities. A remote attacker can invoke a TrustedWebActivity to perform unauthorized actions.

User interaction is required.


35) Improper Authorization (CVE-ID: CVE-2026-87651)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to incorrect authorization in Paint in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.


36) Use-after-free (CVE-ID: CVE-2026-87587)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the V8 component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


37) Type Confusion (CVE-ID: CVE-2026-87564)

CWE-ID: CWE-843 - Type confusion

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a type confusion error within the V8 component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger a type confusion error and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


38) Missing Authorization (CVE-ID: CVE-2026-87498)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access WebUI functionality without authorization.

The vulnerability exists due to missing authorization in WebUI when accessing WebUI functionality. A remote attacker can access WebUI functionality without authorization to access WebUI functionality without authorization.


39) Improper Authorization (CVE-ID: CVE-2026-87499)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to incorrect authorization in Network in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.


40) Use-after-free (CVE-ID: CVE-2026-87607)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Device component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


41) Use-after-free (CVE-ID: CVE-2026-87558)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Payments component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


42) Use-after-free (CVE-ID: CVE-2026-87581)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Payments component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


43) Use-after-free (CVE-ID: CVE-2026-87480)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Printing component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


44) Type Confusion (CVE-ID: CVE-2026-87612)

CWE-ID: CWE-843 - Type confusion

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a type confusion error within the V8 component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger a type confusion error and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


45) Use-after-free (CVE-ID: CVE-2026-87536)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the V8 component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


46) Use-after-free (CVE-ID: CVE-2026-87474)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Payments component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


47) Use-after-free (CVE-ID: CVE-2026-87504)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within Core in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


48) Out-of-bounds read (CVE-ID: CVE-2026-87640)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the WebView component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.


49) Out-of-bounds write (CVE-ID: CVE-2026-87491) Exploited

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted HTML content in V8. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.

Note, the vulnerability is being actively exploited in the wild.


50) Observable discrepancy (CVE-ID: CVE-2026-87478)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an observable discrepancy in Autofill when processing autofill data. A remote attacker can interact with Autofill to disclose sensitive information.

User interaction is required.


51) Incomplete cleanup (CVE-ID: CVE-2026-87446)

CWE-ID: CWE-459 - Incomplete cleanup

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to incomplete cleanup in Extensions in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.


52) Use-after-free (CVE-ID: CVE-2026-87657)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within V8 in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


53) Missing Authorization (CVE-ID: CVE-2026-87434)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to missing authorization in CORS when handling cross-origin requests. A remote attacker can trick a victim into visiting a crafted website to disclose sensitive information.

User interaction is required.


54) Missing Authorization (CVE-ID: CVE-2026-87487)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access FileSystem resources without authorization.

The vulnerability exists due to missing authorization in FileSystem when accessing FileSystem resources. A remote attacker can access FileSystem resources without authorization to access FileSystem resources without authorization.

User interaction is required.


55) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-87453)

CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to a confused deputy weakness in BackgroundFetch when handling web content. A remote attacker can cause BackgroundFetch to act on their behalf to perform unauthorized actions.


56) Use-after-free (CVE-ID: CVE-2026-87588)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within Chromecast in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


57) Type Confusion (CVE-ID: CVE-2026-87636)

CWE-ID: CWE-843 - Type confusion

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a type confusion error within the XML component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a type confusion error and gain access to sensitive information.


58) Missing Authorization (CVE-ID: CVE-2026-87611)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access file system resources without authorization.

The vulnerability exists due to missing authorization in the FileSystem component when a victim interacts with web content. A remote attacker can cause a victim to interact with web content to access file system resources without authorization.


59) Missing Authorization (CVE-ID: CVE-2026-87606)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization controls.

The vulnerability exists due to missing authorization in SiteIsolation when handling site isolation operations. A remote attacker can exploit the missing authorization controls to bypass authorization controls.


60) Use of uninitialized resource (CVE-ID: CVE-2026-87456)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger an unspecified impact.

The vulnerability exists due to use of an uninitialized resource in the Media component when processing media content. A remote attacker can interact with the Media component to trigger an unspecified impact.


61) Input validation error (CVE-ID: CVE-2026-87553)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to insufficient validation of user-supplied input in SiteIsolation in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


62) Information disclosure (CVE-ID: CVE-2026-87658)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in Extensions in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


63) Incorrect authorization (CVE-ID: CVE-2026-87465)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in Downloads when handling downloads. A remote attacker can exploit the authorization flaw to perform unauthorized actions.


64) Incorrect authorization (CVE-ID: CVE-2026-87515)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access resources without authorization.

The vulnerability exists due to incorrect authorization in FileAPI when handling FileAPI operations. A remote attacker can exploit the authorization flaw to access resources without authorization.

User interaction is required.


65) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-87547)

CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access unintended files.

The vulnerability exists due to incorrect reference resolution in FileSystem when resolving crafted filesystem references. A remote attacker can supply crafted references to access unintended files.

User interaction is required.


66) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-87442)

CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to a confused deputy issue in Prerender when handling crafted web content. A remote attacker can trick a victim into interacting with crafted web content to perform unauthorized actions.


67) Improper privilege management (CVE-ID: CVE-2026-87506)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper privilege management in WebUI when processing user-initiated WebUI interactions. A remote attacker can cause the victim to interact with WebUI content to escalate privileges.

User interaction is required.


68) Race condition (CVE-ID: CVE-2026-87433)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger a race condition.

The vulnerability exists due to a race condition in FileAPI when performing FileAPI operations. A remote attacker can perform FileAPI operations to trigger a race condition.


69) Missing Authorization (CVE-ID: CVE-2026-87557)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access local network resources without authorization.

The vulnerability exists due to missing authorization in LocalNetworkAccess when handling crafted web content. A remote attacker can induce the victim to interact with crafted web content to access local network resources without authorization.

User interaction is required.


70) Race condition (CVE-ID: CVE-2026-87457)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a race condition in in Updater in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and crash the browser.


71) Improperly implemented security check for standard (CVE-ID: CVE-2026-87503)

CWE-ID: CWE-358 - Improperly Implemented Security Check for Standard

CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to incorrect implementation in Downloads in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.


72) Incorrect authorization (CVE-ID: CVE-2026-87481)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access resources without authorization.

The vulnerability exists due to incorrect authorization in WebView when processing crafted web content. A remote attacker can cause WebView to process crafted web content to access resources without authorization.

User interaction is required.


73) Missing Authorization (CVE-ID: CVE-2026-87537)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to missing authorization in Extensions when processing extension requests. A remote attacker can send a crafted extension request to perform unauthorized actions.

User interaction is required.


74) Incorrect authorization (CVE-ID: CVE-2026-87471)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization restrictions.

The vulnerability exists due to incorrect authorization in ServiceWorker when processing crafted web content. A remote attacker can trick the victim into interacting with crafted web content to bypass authorization restrictions.


75) Incorrect authorization (CVE-ID: CVE-2026-87485)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access cross-origin resources.

The vulnerability exists due to incorrect authorization in CORS when processing cross-origin requests. A remote attacker can trick the victim into visiting crafted web content to access cross-origin resources.


76) Incorrect authorization (CVE-ID: CVE-2026-87652)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in PushAPI when processing PushAPI requests. A remote attacker can send a crafted PushAPI request to perform unauthorized actions.

User interaction is required.


77) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-87582)

CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to a confused deputy vulnerability in DataTransfer when handling crafted web content. A remote attacker can trick a victim into interacting with crafted web content to perform unauthorized actions.


78) Incorrect authorization (CVE-ID: CVE-2026-87466)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in Workers when processing crafted web content. A remote attacker can trick a victim into interacting with crafted web content to perform unauthorized actions.


79) Missing Authorization (CVE-ID: CVE-2026-87603)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization controls for the FileSystem.

The vulnerability exists due to missing authorization checks in the FileSystem when a victim interacts with affected FileSystem functionality. A remote attacker can cause a victim to interact with the affected FileSystem functionality to bypass authorization controls for the FileSystem.

User interaction is required.


80) Race condition (CVE-ID: CVE-2026-87615)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger a race condition in payment processing.

The vulnerability exists due to a race condition in Payments when using payment-related functionality. A remote attacker can interact with the Payments feature to trigger a race condition in payment processing.

User interaction is required.


81) Use of uninitialized resource (CVE-ID: CVE-2026-87642)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger unspecified behavior.

The vulnerability exists due to use of an uninitialized resource in WebGL when handling WebGL resources. A remote attacker can trigger the uninitialized resource condition to trigger unspecified behavior.


82) Incorrect authorization (CVE-ID: CVE-2026-87577)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access resources without proper authorization.

The vulnerability exists due to incorrect authorization in Isolated. Chrome Medium when handling crafted web content. A remote attacker can trick a victim into interacting with crafted web content to access resources without proper authorization.

User interaction is required.


83) Cross-site request forgery (CVE-ID: CVE-2026-87449)

CWE-ID: CWE-352 - Cross-Site Request Forgery (CSRF)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform cross-site request forgery.

The vulnerability exists due to cross-site request forgery in DeviceBoundSessionCredentials when handling cross-site requests. A remote attacker can send a crafted cross-site request to perform cross-site request forgery.


84) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-87613)

CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass security restrictions.

The vulnerability exists due to incorrect reference resolution in Extensions when processing extension references. A remote attacker can provide crafted extension references to bypass security restrictions.

User interaction is required.


85) State Issues (CVE-ID: CVE-2026-87645)

CWE-ID: CWE-371 - State Issues

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to improper state validation in Safebrowsing in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.


86) Missing Authorization (CVE-ID: CVE-2026-87443)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access unauthorized resources.

The vulnerability exists due to missing authorization in Actor when processing crafted web content. A remote attacker can trick a victim into interacting with crafted web content to access unauthorized resources.


87) Integer overflow (CVE-ID: CVE-2026-87630)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a integer overflow in WebRTC in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.


88) Input validation error (CVE-ID: CVE-2026-87590)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause an unspecified security impact.

The vulnerability exists due to improper input validation in Passwords when processing input. A remote attacker can provide specially crafted input to cause an unspecified security impact.


89) Incorrect authorization (CVE-ID: CVE-2026-87580)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to improper authorization in WebAppInstalls when handling web application installation requests. A remote attacker can exploit the incorrect authorization to perform unauthorized actions.

User interaction is required.


90) Cleartext transmission of sensitive information (CVE-ID: CVE-2026-87482)

CWE-ID: CWE-319 - Cleartext Transmission of Sensitive Information

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to cleartext transmission of sensitive data in HttpsUpgrades when handling sensitive data. A remote attacker can cause HttpsUpgrades to transmit sensitive data in cleartext to disclose sensitive information.


91) Use of uninitialized resource (CVE-ID: CVE-2026-87497)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to use of an uninitialized resource in Codecs when processing media content. A remote attacker can cause the browser to process media content to cause a denial of service.

User interaction is required.


92) Buffer overflow (CVE-ID: CVE-2026-87579)

CWE-ID: CWE-120 - Buffer overflow

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a buffer overflow in WebRTC when processing crafted WebRTC content. A remote attacker can trick the victim into processing crafted WebRTC content to cause a denial of service.


93) Use of uninitialized resource (CVE-ID: CVE-2026-87576)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to use of an uninitialized resource in the GPU component when processing content. A remote attacker can trigger the vulnerable GPU resource to cause a denial of service.


94) Incorrect authorization (CVE-ID: CVE-2026-87476)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization controls.

The vulnerability exists due to incorrect authorization in Loader when performing authorization checks. A remote attacker can exploit the authorization flaw to bypass authorization controls.


95) Missing Authorization (CVE-ID: CVE-2026-87475)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to missing authorization in Omnibox when processing omnibox input. A remote attacker can cause input to be processed without required authorization checks to perform unauthorized actions.

User interaction is required.


96) Incomplete cleanup (CVE-ID: CVE-2026-87436)

CWE-ID: CWE-459 - Incomplete cleanup

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to incomplete cleanup in Browser in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.


97) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2026-87479)

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient policy enforcement in Extensions in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and gain access to sensitive information.


98) Missing Authorization (CVE-ID: CVE-2026-87513)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization.

The vulnerability exists due to missing authorization in ControlledFrame when processing ControlledFrame operations. A remote attacker can perform ControlledFrame operations to bypass authorization.

User interaction is required.


99) Incorrect authorization (CVE-ID: CVE-2026-87432)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization restrictions.

The vulnerability exists due to incorrect authorization in Navigation when handling navigation requests. A remote attacker can initiate a navigation request to bypass authorization restrictions.


100) Missing Authorization (CVE-ID: CVE-2026-87560)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to missing authorization in the Browser component when using the browser. A remote attacker can exploit the missing authorization to perform unauthorized actions.

User interaction is required.


101) Information disclosure (CVE-ID: CVE-2026-87521)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in WebMCP in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


102) Observable discrepancy (CVE-ID: CVE-2026-87539)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an observable discrepancy in the Network component when processing network-related content. A remote attacker can induce user interaction with network-related content to disclose sensitive information.


103) Use-after-free (CVE-ID: CVE-2026-87648)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within ANGLE in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


104) Missing Authorization (CVE-ID: CVE-2026-87534)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to missing authorization in WebView when processing web content. A remote attacker can cause a victim to interact with crafted web content to perform unauthorized actions.

User interaction is required.


105) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-87562)

CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause incorrect reference resolution.

The vulnerability exists due to incorrect reference resolution in the Accessibility component when a victim interacts with web content. A remote attacker can induce a victim to interact with web content to cause incorrect reference resolution.


106) Missing Authorization (CVE-ID: CVE-2026-87556)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization controls.

The vulnerability exists due to missing authorization in the Browser component when processing authorization checks. A remote attacker can exploit the missing authorization to bypass authorization controls.


107) Incorrect authorization (CVE-ID: CVE-2026-87508)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization controls.

The vulnerability exists due to incorrect authorization in Loader when loading content. A remote attacker can cause the browser to load crafted content to bypass authorization controls.

User interaction is required.


108) Integer overflow (CVE-ID: CVE-2026-87643)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a integer overflow in GPU in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.


109) Input validation error (CVE-ID: CVE-2026-87573)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to insufficient validation of user-supplied input in Network in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


110) Improper Enforcement of Behavioral Workflow (CVE-ID: CVE-2026-87548)

CWE-ID: CWE-841 - Improper Enforcement of Behavioral Workflow

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass intended installer state validation.

The vulnerability exists due to improper state validation in the installer when processing installer state. A remote attacker can cause the installer to accept an invalid state to bypass intended installer state validation.

User interaction is required.


111) Spoofing attack (CVE-ID: CVE-2026-87501)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause UI misrepresentation.

The vulnerability exists due to UI misrepresentation in the Passwords feature when handling user interaction. A remote attacker can exploit the issue to cause UI misrepresentation.


112) Incorrect authorization (CVE-ID: CVE-2026-87452)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in the GPU component when processing crafted web content. A remote attacker can cause a victim to interact with crafted web content to perform unauthorized actions.


113) Observable discrepancy (CVE-ID: CVE-2026-87516)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an observable discrepancy in Navigation when handling navigation requests. A remote attacker can trick the victim into navigating to crafted content to disclose sensitive information.


114) Input validation error (CVE-ID: CVE-2026-87599)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to insufficient validation of user-supplied input in Interstitials in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


115) Spoofing attack (CVE-ID: CVE-2026-87507)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent download-related information.

The vulnerability exists due to improper presentation of critical information in Downloads when displaying download-related information. A remote attacker can cause download-related information to be misrepresented to misrepresent download-related information.

User interaction is required.


116) Spoofing attack (CVE-ID: CVE-2026-87559)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent the user interface.

The vulnerability exists due to UI misrepresentation in the UI when rendering web content. A remote attacker can trick the victim into interacting with misrepresented UI elements to misrepresent the user interface.


117) Input validation error (CVE-ID: CVE-2026-87472)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to insufficient validation of user-supplied input in FedCM in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


118) Improper Restriction of Rendered UI Layers or Frames (CVE-ID: CVE-2026-87486)

CWE-ID: CWE-1021 - Improper Restriction of Rendered UI Layers or Frames

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform clickjacking attacks.

The vulnerability exists due to clickjacking in TrustedWebActivities when rendering web content. A remote attacker can trick a victim into interacting with a crafted interface to perform clickjacking attacks.

User interaction is required.


119) Improper Restriction of Rendered UI Layers or Frames (CVE-ID: CVE-2026-87655)

CWE-ID: CWE-1021 - Improper Restriction of Rendered UI Layers or Frames

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unintended download-related actions.

The vulnerability exists due to clickjacking in the Downloads feature when rendering web content. A remote attacker can trick a victim into interacting with crafted web content to perform unintended download-related actions.

User interaction is required.


120) Spoofing attack (CVE-ID: CVE-2026-87462)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent FedCM user interface elements.

The vulnerability exists due to UI misrepresentation in FedCM when rendering FedCM user interface elements. A remote attacker can induce a victim to interact with misleading FedCM user interface elements to misrepresent FedCM user interface elements.

User interaction is required.


121) Spoofing attack (CVE-ID: CVE-2026-87649)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to deceive users through download-related UI.

The vulnerability exists due to UI misrepresentation in Downloads when presenting download-related information. A remote attacker can exploit this flaw to deceive users through download-related UI.


122) Spoofing attack (CVE-ID: CVE-2026-87445)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent the user interface.

The vulnerability exists due to user interface misrepresentation in the Session component when interacting with the Session component. A remote attacker can trigger the UI misrepresentation to misrepresent the user interface.


123) Spoofing attack (CVE-ID: CVE-2026-87567)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent URL information.

The vulnerability exists due to UI misrepresentation in UrlFormatting when formatting URLs. A remote attacker can cause URL information to be misrepresented to misrepresent URL information.

User interaction is required.


124) Spoofing attack (CVE-ID: CVE-2026-87496)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to mislead users.

The vulnerability exists due to UI misrepresentation in the Browser component when displaying browser UI. A remote attacker can cause browser UI to be misrepresented to mislead users.


125) Missing Authorization (CVE-ID: CVE-2026-87441)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized download-related actions.

The vulnerability exists due to missing authorization in Downloads when handling download-related actions. A remote attacker can invoke download-related functionality without required authorization to perform unauthorized download-related actions.


126) Incomplete cleanup (CVE-ID: CVE-2026-87549)

CWE-ID: CWE-459 - Incomplete cleanup

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to incomplete cleanup in Downloads in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.


127) Spoofing attack (CVE-ID: CVE-2026-87458)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent user interface elements.

The vulnerability exists due to UI misrepresentation in Geometry when rendering content. A remote attacker can exploit the UI misrepresentation to misrepresent user interface elements.

User interaction is required.


128) Information disclosure (CVE-ID: CVE-2026-87574)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in ServiceWorker in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


129) Information disclosure (CVE-ID: CVE-2026-87495)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in Scroll in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


130) Information disclosure (CVE-ID: CVE-2026-87541)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in Navigation in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


131) Information disclosure (CVE-ID: CVE-2026-87451)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in Downloads in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


132) Incorrect authorization (CVE-ID: CVE-2026-87570)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access resources without proper authorization.

The vulnerability exists due to incorrect authorization in SiteIsolation when processing web content. A remote attacker can cause SiteIsolation to incorrectly authorize access to resources.


133) Use of uninitialized resource (CVE-ID: CVE-2026-87555)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger an unspecified impact.

The vulnerability exists due to use of an uninitialized resource in the GPU component when processing web content. A remote attacker can trick a victim into accessing web content to trigger an unspecified impact.

User interaction is required.


134) Input validation error (CVE-ID: CVE-2026-87600)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause an unspecified impact.

The vulnerability exists due to improper input validation in Safebrowsing when processing input. A remote attacker can provide specially crafted input to cause an unspecified impact.

User interaction is required.


135) Improper Enforcement of Behavioral Workflow (CVE-ID: CVE-2026-87532)

CWE-ID: CWE-841 - Improper Enforcement of Behavioral Workflow

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to affect Safebrowsing functionality.

The vulnerability exists due to improper state validation in Safebrowsing when processing user-initiated browsing activity. A remote attacker can induce a victim to interact with crafted web content to affect Safebrowsing functionality.


136) Information disclosure (CVE-ID: CVE-2026-87439)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in ServiceWorker in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


137) Incorrect authorization (CVE-ID: CVE-2026-87450)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in Permissions when handling permission requests. A remote attacker can exploit the authorization flaw to perform unauthorized actions.


138) Incorrect authorization (CVE-ID: CVE-2026-87505)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization checks.

The vulnerability exists due to incorrect authorization in FileSystem when processing user-initiated filesystem operations. A remote attacker can induce a victim to interact with web content that invokes filesystem operations to bypass authorization checks.


139) Missing Authorization (CVE-ID: CVE-2026-87622)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to missing authorization in FedCM when processing FedCM requests. A remote attacker can induce the victim to interact with web content to perform unauthorized actions.

User interaction is required.


140) Incorrect authorization (CVE-ID: CVE-2026-87540)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in the Isolated component when processing crafted web content. A remote attacker can trick the victim into interacting with crafted web content to perform unauthorized actions.

User interaction is required.


141) Incorrect authorization (CVE-ID: CVE-2026-87594)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in DataTransfer when handling DataTransfer operations. A remote attacker can invoke DataTransfer operations to perform unauthorized actions.


142) Observable discrepancy (CVE-ID: CVE-2026-87518)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to obtain information about Safe Browsing behavior.

The vulnerability exists due to an observable discrepancy in Safe Browsing when handling Safe Browsing checks. A remote attacker can trigger the discrepancy to obtain information about Safe Browsing behavior.

User interaction is required.


143) Incorrect authorization (CVE-ID: CVE-2026-87589)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in SiteIsolation when handling web content. A remote attacker can cause a victim to interact with web content to perform unauthorized actions.


144) Spoofing attack (CVE-ID: CVE-2026-87484)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to spoof user interface elements.

The vulnerability exists due to UI misrepresentation in Geometry when rendering crafted web content. A remote attacker can cause crafted web content to be rendered to spoof user interface elements.

User interaction is required to view the crafted web content.


145) Insecure DLL loading (CVE-ID: CVE-2026-87530)

CWE-ID: CWE-427 - Uncontrolled Search Path Element

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to an uncontrolled search path element in CredentialProvider when resolving files through an uncontrolled search path. A remote attacker can cause a malicious file to be loaded to execute arbitrary code.

User interaction is required.


146) Improper Encoding or Escaping of Output (CVE-ID: CVE-2026-87550)

CWE-ID: CWE-116 - Improper Encoding or Escaping of Output

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to inject CSS.

The vulnerability exists due to improper encoding or escaping of output in CSS when rendering crafted CSS content. A remote attacker can provide crafted CSS content to inject CSS.


147) Use-after-free (CVE-ID: CVE-2026-87494)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within Browser in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


148) Incorrect authorization (CVE-ID: CVE-2026-87483)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization controls.

The vulnerability exists due to incorrect authorization in Browser when processing content. A remote attacker can exploit the authorization flaw to bypass authorization controls.


149) Information disclosure (CVE-ID: CVE-2026-87454)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in Enterprise in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


150) Improper initialization (CVE-ID: CVE-2026-87616)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to improper initialization in Views in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


151) Information Loss or Omission (CVE-ID: CVE-2026-87535)

CWE-ID: CWE-221 - Information Loss or Omission

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause information loss.

The vulnerability exists due to information loss or omission in Safe Browsing when processing crafted web content. A remote attacker can trick the victim into visiting a crafted website to cause information loss.


152) Incorrect authorization (CVE-ID: CVE-2026-87644)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in Views when processing crafted web content. A remote attacker can trick a victim into interacting with crafted web content to perform unauthorized actions.

User interaction is required.


153) Use-after-free (CVE-ID: CVE-2026-87533)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within DevTools in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


154) Spoofing attack (CVE-ID: CVE-2026-87635)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent payment-related user interface elements.

The vulnerability exists due to UI misrepresentation in Payments when rendering payment-related user interface elements. A remote attacker can cause payment-related user interface elements to be misrepresented.

User interaction is required.


155) Race condition (CVE-ID: CVE-2026-87641)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a race condition in in Browser in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and crash the browser.


156) Missing Authorization (CVE-ID: CVE-2026-87431)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to missing authorization in Extensions when processing user interaction. A remote attacker can induce a victim to interact with content to perform unauthorized actions.


157) Missing Authorization (CVE-ID: CVE-2026-87493)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized filesystem operations.

The vulnerability exists due to missing authorization in FileSystem when processing crafted web content. A remote attacker can provide crafted web content to perform unauthorized filesystem operations.

User interaction is required.


158) Use-after-free (CVE-ID: CVE-2026-87625)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within V8 in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


159) Incorrect authorization (CVE-ID: CVE-2026-87468)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization restrictions.

The vulnerability exists due to incorrect authorization in the Isolated component when processing crafted web content. A remote attacker can trick a victim into interacting with crafted web content to bypass authorization restrictions.


160) Origin validation error (CVE-ID: CVE-2026-87563)

CWE-ID: CWE-346 - Origin Validation Error

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass origin-based security restrictions.

The vulnerability exists due to improper origin validation in Paint when processing web content. A remote attacker can trick a victim into visiting a crafted website to bypass origin-based security restrictions.


161) Input validation error (CVE-ID: CVE-2026-87510)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to insufficient validation of user-supplied input in FileAPI in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


162) Information disclosure (CVE-ID: CVE-2026-87435)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in ControlledFrame in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


163) Information disclosure (CVE-ID: CVE-2026-87531)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in CORS in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


164) Use-after-free (CVE-ID: CVE-2026-87637)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within Extensions in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


165) Numeric Truncation Error (CVE-ID: CVE-2026-87529)

CWE-ID: CWE-197 - Numeric Truncation Error

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger an incorrect numeric conversion during media processing.

The vulnerability exists due to numeric truncation in the Media component when processing media content. A remote attacker can induce the victim to process crafted media content to trigger an incorrect numeric conversion during media processing.


166) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-87470)

CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger an unspecified impact.

The vulnerability exists due to improper quantity validation in Tint when processing input. A remote attacker can provide input containing an improperly validated quantity to trigger an unspecified impact.


167) Out-of-bounds read (CVE-ID: CVE-2026-87586)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the ANGLE component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.


168) Incorrect authorization (CVE-ID: CVE-2026-87584)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to improper authorization in WebUI when handling WebUI requests. A remote attacker can induce a user to interact with WebUI functionality to perform unauthorized actions.

User interaction is required.


169) Cross-site scripting (CVE-ID: CVE-2026-87632)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote attacker to execute arbitrary script in a victim's browser.

The vulnerability exists due to improper neutralization of input during web page generation in SanitizerAPI when processing crafted web content. A remote attacker can cause a victim to process crafted web content to execute arbitrary script in a victim's browser.

User interaction is required.


170) Type Confusion (CVE-ID: CVE-2026-87528)

CWE-ID: CWE-843 - Type confusion

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a type confusion error within the Rust component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a type confusion error and gain access to sensitive information.


171) Observable discrepancy (CVE-ID: CVE-2026-87623)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose information.

The vulnerability exists due to an observable discrepancy in the DOM when rendering crafted web content. A remote attacker can cause an observable discrepancy in the DOM to disclose information.

User interaction is required to render the crafted web content.


172) Observable discrepancy (CVE-ID: CVE-2026-87566)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an observable discrepancy in Layout when rendering crafted web content. A remote attacker can trick the victim into visiting a crafted website to disclose sensitive information.

User interaction is required.


173) Out-of-bounds write (CVE-ID: CVE-2026-87638)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted HTML content in Media. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.


174) Use-after-free (CVE-ID: CVE-2026-87455)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within Aura in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


175) Incorrect authorization (CVE-ID: CVE-2026-87591)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in Extensions when handling extension-related operations. A remote attacker can invoke extension functionality without proper authorization to perform unauthorized actions.


176) Use-after-free (CVE-ID: CVE-2026-87526)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within Passwords in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


177) Use-after-free (CVE-ID: CVE-2026-87609)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within Sharing in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


178) Incorrect authorization (CVE-ID: CVE-2026-87610)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in the Omnibox when processing Omnibox input. A remote attacker can cause a victim to interact with the Omnibox to perform unauthorized actions.


179) Incorrect authorization (CVE-ID: CVE-2026-87626)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access DeviceBoundSessionCredentials without authorization.

The vulnerability exists due to incorrect authorization in DeviceBoundSessionCredentials when performing authorization checks. A remote attacker can trigger the flawed authorization check to access DeviceBoundSessionCredentials without authorization.

User interaction is required.


180) Incorrect authorization (CVE-ID: CVE-2026-87629)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in sources when handling crafted content. A remote attacker can induce a victim to interact with crafted content to perform unauthorized actions.


181) Spoofing attack (CVE-ID: CVE-2026-87653)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent browser user interface elements.

The vulnerability exists due to user interface misrepresentation in the FullScreen feature when displaying crafted web content in fullscreen mode. A remote attacker can trick a victim into viewing crafted web content to misrepresent browser user interface elements.

User interaction is required.


182) Use-after-free (CVE-ID: CVE-2026-87634)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to use-after-free error in WebPackaging in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


183) Missing Authorization (CVE-ID: CVE-2026-87429)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to missing authorization in ServiceWorker when handling service worker operations. A remote attacker can induce a victim to interact with browser content to perform unauthorized actions.


184) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-87618)

CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause incorrect reference resolution.

The vulnerability exists due to incorrect reference resolution in Storage when resolving references. A remote attacker can cause a reference to be resolved incorrectly to cause incorrect reference resolution.


185) Incorrect authorization (CVE-ID: CVE-2026-87614)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization controls.

The vulnerability exists due to incorrect authorization in ServiceWorker when handling ServiceWorker operations. A remote attacker can exploit the incorrect authorization to bypass authorization controls.


186) Observable discrepancy (CVE-ID: CVE-2026-87619)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an observable discrepancy in Prefetch when prefetching content. A remote attacker can observe differences in Prefetch behavior to disclose sensitive information.


187) Incorrect authorization (CVE-ID: CVE-2026-87561)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in Web Authentication when processing Web Authentication requests. A remote attacker can submit a crafted Web Authentication request to perform unauthorized actions.


188) Incorrect authorization (CVE-ID: CVE-2026-87598)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access ServiceWorker functionality without authorization.

The vulnerability exists due to incorrect authorization in ServiceWorker when processing crafted web content. A remote attacker can induce a victim to interact with crafted web content to access ServiceWorker functionality without authorization.


189) Incorrect authorization (CVE-ID: CVE-2026-87519)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access protected Safe Browsing functionality.

The vulnerability exists due to incorrect authorization in Safe Browsing when using the Safe Browsing feature. A remote attacker can exploit the authorization flaw to access protected Safe Browsing functionality.

User interaction is required.


190) Missing Authorization (CVE-ID: CVE-2026-87543)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to missing authorization in Core when a victim interacts with web content. A remote attacker can cause a victim to interact with web content to perform unauthorized actions.


191) Missing Authorization (CVE-ID: CVE-2026-87522)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to missing authorization in WebView when handling web content. A remote attacker can access functionality without authorization to perform unauthorized actions.


192) Input validation error (CVE-ID: CVE-2026-87568)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger an unspecified security impact.

The vulnerability exists due to improper input validation in Chromium when processing input. A remote attacker can provide specially crafted input to trigger an unspecified security impact.


193) Improper Enforcement of Behavioral Workflow (CVE-ID: CVE-2026-87656)

CWE-ID: CWE-841 - Improper Enforcement of Behavioral Workflow

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause an unspecified impact.

The vulnerability exists due to improper state validation in Safebrowsing when handling Safe Browsing state. A remote attacker can trigger an invalid state to cause an unspecified impact.


194) Missing Authorization (CVE-ID: CVE-2026-87511)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access DevTools functionality without authorization.

The vulnerability exists due to missing authorization in DevTools when accessing DevTools functionality. A remote attacker can access DevTools functionality without authorization to access DevTools functionality without authorization.


195) Interpretation Conflict (CVE-ID: CVE-2026-87627)

CWE-ID: CWE-436 - Interpretation Conflict

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass Safe Browsing protections.

The vulnerability exists due to an interpretation conflict in Safe Browsing when processing web content. A remote attacker can provide crafted web content to bypass Safe Browsing protections.

User interaction is required.


196) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2026-87595)

CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause the browser to send requests to arbitrary destinations.

The vulnerability exists due to server-side request forgery in Mobile when processing crafted content. A remote attacker can trick the victim into processing crafted content to cause the browser to send requests to arbitrary destinations.


197) Out-of-bounds read (CVE-ID: CVE-2026-87592)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a boundary condition within the Tint component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and crash the browser.


198) Observable discrepancy (CVE-ID: CVE-2026-87620)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an observable discrepancy in SVG when rendering crafted SVG content. A remote attacker can cause the browser to render crafted SVG content to disclose sensitive information.


199) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-87502)

CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause the browser to perform unauthorized actions.

The vulnerability exists due to a confused deputy condition in the Fullscreen feature when handling fullscreen requests. A remote attacker can trick a victim into interacting with fullscreen content to cause the browser to perform unauthorized actions.


200) Use-after-free (CVE-ID: CVE-2026-87448)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to use-after-free error in DevTools in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


201) Observable discrepancy (CVE-ID: CVE-2026-87459)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to obtain information.

The vulnerability exists due to an observable discrepancy in Select when interacting with Select. A remote attacker can trigger the observable discrepancy to obtain information.


202) Incorrect authorization (CVE-ID: CVE-2026-87463)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization controls.

The vulnerability exists due to incorrect authorization in Certificate when handling certificate-related operations. A remote attacker can exploit the issue to bypass authorization controls.

User interaction is required.


203) Type conversion (CVE-ID: CVE-2026-87546)

CWE-ID: CWE-704 - Type conversion

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a low-severity security impact.

The vulnerability exists due to incorrect type conversion or cast in Safe Browsing when performing type conversions or casts. A remote attacker can trigger the vulnerable code path to cause a low-severity security impact.


204) Improper Restriction of Rendered UI Layers or Frames (CVE-ID: CVE-2026-87538)

CWE-ID: CWE-1021 - Improper Restriction of Rendered UI Layers or Frames

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause users to perform unintended actions.

The vulnerability exists due to clickjacking in Input when rendering crafted web content. A remote attacker can trick a victim into interacting with crafted web content to cause users to perform unintended actions.


205) Information disclosure (CVE-ID: CVE-2026-87545)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an unspecified flaw in Mobile Chrome when handling crafted content. A remote attacker can trick a victim into interacting with crafted content to disclose sensitive information.


206) Use-after-free (CVE-ID: CVE-2026-87617)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to use-after-free error in DevTools in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


207) Race condition (CVE-ID: CVE-2026-87523)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a race condition in in DataTransfer in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and crash the browser.


208) Information disclosure (CVE-ID: CVE-2026-87565)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an unspecified flaw in the Passwords component when a victim interacts with content. A remote attacker can induce a victim to interact with content to disclose sensitive information.


209) Spoofing attack (CVE-ID: CVE-2026-87597)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent user interface content.

The vulnerability exists due to UI misrepresentation in CustomTabs when displaying CustomTabs content. A remote attacker can present misleading user interface content to misrepresent user interface content.

User interaction is required.


210) Spoofing attack (CVE-ID: CVE-2026-87624)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to display misleading password-related information.

The vulnerability exists due to user interface misrepresentation in the Passwords feature when a victim interacts with crafted web content. A remote attacker can induce the victim to interact with misleading password-related information to display misleading password-related information.


211) Missing Authorization (CVE-ID: CVE-2026-87605)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to missing authorization in the Contacts feature when processing contact-related requests. A remote attacker can interact with the Contacts feature to disclose sensitive information.


212) Information disclosure (CVE-ID: CVE-2026-87490)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an unspecified flaw in the Transactions Platform when a victim interacts with content. A remote attacker can cause a victim to interact with content to disclose sensitive information.


213) Spoofing attack (CVE-ID: CVE-2026-87583)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent password-related user interface elements.

The vulnerability exists due to user interface misrepresentation in Passwords when rendering password-related user interface elements. A remote attacker can cause password-related user interface elements to be misrepresented to mislead users.

User interaction is required.


214) Incorrect authorization (CVE-ID: CVE-2026-87509)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization restrictions.

The vulnerability exists due to incorrect authorization in the Updater when handling update operations. A remote attacker can exploit the authorization flaw to bypass authorization restrictions.


215) Incorrect authorization (CVE-ID: CVE-2026-87473)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access resources without authorization.

The vulnerability exists due to improper authorization in FileHandling when processing content after user interaction. A remote attacker can induce a victim to interact with content to access resources without authorization.


216) Information disclosure (CVE-ID: CVE-2026-87461)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an unspecified information disclosure flaw in Core when processing content after user interaction. A remote attacker can cause a victim to interact with crafted content to disclose sensitive information.


217) Missing Authorization (CVE-ID: CVE-2026-87631)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access restricted DOM resources.

The vulnerability exists due to missing authorization in the DOM when rendering crafted web content. A remote attacker can induce a victim to render crafted web content to access restricted DOM resources.

User interaction is required to render crafted web content.


218) Input validation error (CVE-ID: CVE-2026-87469)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a low-severity security impact.

The vulnerability exists due to improper input validation in Extensions when processing input. A remote attacker can provide specially crafted input to cause a low-severity security impact.


219) Buffer overflow (CVE-ID: CVE-2026-87489)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger memory corruption.

The vulnerability exists due to memory corruption in V8 when processing web content. A remote attacker can induce a victim to interact with web content to trigger memory corruption.

User interaction is required.


220) Incorrect authorization (CVE-ID: CVE-2026-87575)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in Loader when performing authorization checks. A remote attacker can exploit the authorization flaw to perform unauthorized actions.


221) Improper Certificate Validation (CVE-ID: CVE-2026-87571)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause Chrome to accept improperly validated certificates.

The vulnerability exists due to improper certificate validation in Loader when processing certificates. A remote attacker can provide an improperly validated certificate to cause Chrome to accept improperly validated certificates.

User interaction is required.


222) Information disclosure (CVE-ID: CVE-2026-87477)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an unspecified information disclosure flaw in Chrome Core when a user interacts with content processed by Chrome. A remote attacker can cause a user to interact with content processed by Chrome to disclose sensitive information.


223) Improper Certificate Validation (CVE-ID: CVE-2026-87551)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass certificate validation.

The vulnerability exists due to improper certificate validation in CORS when handling CORS requests. A remote attacker can send a crafted CORS request to bypass certificate validation.


224) Improper Certificate Validation (CVE-ID: CVE-2026-87608)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass certificate validation.

The vulnerability exists due to improper certificate validation in FedCM when validating certificates. A remote attacker can cause FedCM to improperly validate a certificate to bypass certificate validation.

User interaction is required.


225) Information disclosure (CVE-ID: CVE-2026-87437)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an unspecified flaw in Frames when handling frames. A remote attacker can induce a victim to interact with web content to disclose sensitive information.


226) Out-of-bounds read (CVE-ID: CVE-2026-87602)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a boundary condition within the ANGLE component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and crash the browser.


227) Race condition (CVE-ID: CVE-2026-87601)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a race condition in in V8 in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and crash the browser.


228) Incorrect authorization (CVE-ID: CVE-2026-87544)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization restrictions.

The vulnerability exists due to incorrect authorization in Extensions when handling extension-related requests. A remote attacker can send a crafted extension-related request to bypass authorization restrictions.

User interaction is required.


229) Buffer overflow (CVE-ID: CVE-2026-87430)

CWE-ID: CWE-120 - Buffer overflow

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a buffer overflow in WebRTC when processing web content. A remote attacker can cause WebRTC to process crafted web content to cause a denial of service.

User interaction is required.


230) Information disclosure (CVE-ID: CVE-2026-87593)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper information disclosure in the Editing component when rendering web content. A remote attacker can cause web content to be rendered to disclose sensitive information.

User interaction is required.


Remediation

Install update from vendor's website.

References