SB20260917239 - Multiple vulnerabilities in Microsoft Edge
Published: September 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 198 vulnerabilities.
1) Use-after-free (CVE-ID: CVE-2026-85893)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to elevate privileges.
The vulnerability exists due to use-after-free in Microsoft Edge (Chromium-based) autofill functionality when activating autofill on an attacker-controlled webpage. A remote attacker can cause the user to visit an attacker-controlled webpage and perform two tap gestures that activate autofill to elevate privileges.
Successful exploitation elevates privileges from a low-integrity sandboxed execution environment to a medium-integrity level.
2) Heap-based buffer overflow (CVE-ID: CVE-2026-69486)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Edge (Chromium-based) when opening a malicious Office file. A remote attacker can send a malicious Office file and convince the victim to open it to execute arbitrary code.
3) Information disclosure (CVE-ID: CVE-2026-87658)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in Extensions in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
4) Use-after-free (CVE-ID: CVE-2026-87657)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within V8 in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
5) Improper Enforcement of Behavioral Workflow (CVE-ID: CVE-2026-87656)
CWE-ID: CWE-841 - Improper Enforcement of Behavioral Workflow
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause an unspecified impact.
The vulnerability exists due to improper state validation in Safebrowsing when handling Safe Browsing state. A remote attacker can trigger an invalid state to cause an unspecified impact.
6) Improper Restriction of Rendered UI Layers or Frames (CVE-ID: CVE-2026-87655)
CWE-ID: CWE-1021 - Improper Restriction of Rendered UI Layers or Frames
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unintended download-related actions.
The vulnerability exists due to clickjacking in the Downloads feature when rendering web content. A remote attacker can trick a victim into interacting with crafted web content to perform unintended download-related actions.
User interaction is required.
7) Buffer overflow (CVE-ID: CVE-2026-87654)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a boundary error in ANGLE in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger a buffer overflow and execute arbitrary code on the system.
8) Spoofing attack (CVE-ID: CVE-2026-87653)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to misrepresent browser user interface elements.
The vulnerability exists due to user interface misrepresentation in the FullScreen feature when displaying crafted web content in fullscreen mode. A remote attacker can trick a victim into viewing crafted web content to misrepresent browser user interface elements.
User interaction is required.
9) Incorrect authorization (CVE-ID: CVE-2026-87652)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to incorrect authorization in PushAPI when processing PushAPI requests. A remote attacker can send a crafted PushAPI request to perform unauthorized actions.
User interaction is required.
10) Improper Authorization (CVE-ID: CVE-2026-87651)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to incorrect authorization in Paint in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.
11) Out-of-bounds read (CVE-ID: CVE-2026-87650)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the WebGL component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.
12) Spoofing attack (CVE-ID: CVE-2026-87649)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to deceive users through download-related UI.
The vulnerability exists due to UI misrepresentation in Downloads when presenting download-related information. A remote attacker can exploit this flaw to deceive users through download-related UI.
13) Use-after-free (CVE-ID: CVE-2026-87648)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within ANGLE in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
14) Use of uninitialized resource (CVE-ID: CVE-2026-87647)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to usage of uninitialized resources in GPU in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger uninitialized usage of resources and compromise the affected system.
15) Use-after-free (CVE-ID: CVE-2026-87646)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Web Authentication component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
16) State Issues (CVE-ID: CVE-2026-87645)
CWE-ID: CWE-371 - State Issues
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to improper state validation in Safebrowsing in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.
17) Incorrect authorization (CVE-ID: CVE-2026-87644)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to incorrect authorization in Views when processing crafted web content. A remote attacker can trick a victim into interacting with crafted web content to perform unauthorized actions.
User interaction is required.
18) Use of uninitialized resource (CVE-ID: CVE-2026-87642)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger unspecified behavior.
The vulnerability exists due to use of an uninitialized resource in WebGL when handling WebGL resources. A remote attacker can trigger the uninitialized resource condition to trigger unspecified behavior.
19) Race condition (CVE-ID: CVE-2026-87641)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to a race condition in in Browser in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and crash the browser.
20) Use-after-free (CVE-ID: CVE-2026-87639)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the WebPackaging component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
21) Out-of-bounds write (CVE-ID: CVE-2026-87638)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted HTML content in Media. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.
22) Use-after-free (CVE-ID: CVE-2026-87637)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Extensions in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
23) Type Confusion (CVE-ID: CVE-2026-87636)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a type confusion error within the XML component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a type confusion error and gain access to sensitive information.
24) Spoofing attack (CVE-ID: CVE-2026-87635)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to misrepresent payment-related user interface elements.
The vulnerability exists due to UI misrepresentation in Payments when rendering payment-related user interface elements. A remote attacker can cause payment-related user interface elements to be misrepresented.
User interaction is required.
25) Use-after-free (CVE-ID: CVE-2026-87634)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to use-after-free error in WebPackaging in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.
26) Use-after-free (CVE-ID: CVE-2026-87633)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Views component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
27) Cross-site scripting (CVE-ID: CVE-2026-87632)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to execute arbitrary script in a victim's browser.
The vulnerability exists due to improper neutralization of input during web page generation in SanitizerAPI when processing crafted web content. A remote attacker can cause a victim to process crafted web content to execute arbitrary script in a victim's browser.
User interaction is required.
28) Missing Authorization (CVE-ID: CVE-2026-87631)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access restricted DOM resources.
The vulnerability exists due to missing authorization in the DOM when rendering crafted web content. A remote attacker can induce a victim to render crafted web content to access restricted DOM resources.
User interaction is required to render crafted web content.
29) Integer overflow (CVE-ID: CVE-2026-87630)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to a integer overflow in WebRTC in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.
30) Incorrect authorization (CVE-ID: CVE-2026-87629)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to incorrect authorization in sources when handling crafted content. A remote attacker can induce a victim to interact with crafted content to perform unauthorized actions.
31) Use-after-free (CVE-ID: CVE-2026-87628)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Cast component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
32) Interpretation Conflict (CVE-ID: CVE-2026-87627)
CWE-ID: CWE-436 - Interpretation Conflict
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass Safe Browsing protections.
The vulnerability exists due to an interpretation conflict in Safe Browsing when processing web content. A remote attacker can provide crafted web content to bypass Safe Browsing protections.
User interaction is required.
33) Incorrect authorization (CVE-ID: CVE-2026-87626)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access DeviceBoundSessionCredentials without authorization.
The vulnerability exists due to incorrect authorization in DeviceBoundSessionCredentials when performing authorization checks. A remote attacker can trigger the flawed authorization check to access DeviceBoundSessionCredentials without authorization.
User interaction is required.
34) Spoofing attack (CVE-ID: CVE-2026-87624)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to display misleading password-related information.
The vulnerability exists due to user interface misrepresentation in the Passwords feature when a victim interacts with crafted web content. A remote attacker can induce the victim to interact with misleading password-related information to display misleading password-related information.
35) Observable discrepancy (CVE-ID: CVE-2026-87623)
CWE-ID: CWE-203 - Observable discrepancy
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose information.
The vulnerability exists due to an observable discrepancy in the DOM when rendering crafted web content. A remote attacker can cause an observable discrepancy in the DOM to disclose information.
User interaction is required to render the crafted web content.
36) Missing Authorization (CVE-ID: CVE-2026-87622)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to missing authorization in FedCM when processing FedCM requests. A remote attacker can induce the victim to interact with web content to perform unauthorized actions.
User interaction is required.
37) Out-of-bounds write (CVE-ID: CVE-2026-87621)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted HTML content in ANGLE. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.
38) Observable discrepancy (CVE-ID: CVE-2026-87620)
CWE-ID: CWE-203 - Observable discrepancy
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an observable discrepancy in SVG when rendering crafted SVG content. A remote attacker can cause the browser to render crafted SVG content to disclose sensitive information.
39) Observable discrepancy (CVE-ID: CVE-2026-87619)
CWE-ID: CWE-203 - Observable discrepancy
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an observable discrepancy in Prefetch when prefetching content. A remote attacker can observe differences in Prefetch behavior to disclose sensitive information.
40) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-87618)
CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause incorrect reference resolution.
The vulnerability exists due to incorrect reference resolution in Storage when resolving references. A remote attacker can cause a reference to be resolved incorrectly to cause incorrect reference resolution.
41) Use-after-free (CVE-ID: CVE-2026-87617)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to use-after-free error in DevTools in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.
42) Improper initialization (CVE-ID: CVE-2026-87616)
CWE-ID: CWE-665 - Improper Initialization
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to improper initialization in Views in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.
43) Race condition (CVE-ID: CVE-2026-87615)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger a race condition in payment processing.
The vulnerability exists due to a race condition in Payments when using payment-related functionality. A remote attacker can interact with the Payments feature to trigger a race condition in payment processing.
User interaction is required.
44) Incorrect authorization (CVE-ID: CVE-2026-87614)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization controls.
The vulnerability exists due to incorrect authorization in ServiceWorker when handling ServiceWorker operations. A remote attacker can exploit the incorrect authorization to bypass authorization controls.
45) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-87613)
CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass security restrictions.
The vulnerability exists due to incorrect reference resolution in Extensions when processing extension references. A remote attacker can provide crafted extension references to bypass security restrictions.
User interaction is required.
46) Missing Authorization (CVE-ID: CVE-2026-87611)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access file system resources without authorization.
The vulnerability exists due to missing authorization in the FileSystem component when a victim interacts with web content. A remote attacker can cause a victim to interact with web content to access file system resources without authorization.
47) Incorrect authorization (CVE-ID: CVE-2026-87610)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to incorrect authorization in the Omnibox when processing Omnibox input. A remote attacker can cause a victim to interact with the Omnibox to perform unauthorized actions.
48) Use-after-free (CVE-ID: CVE-2026-87609)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Sharing in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
49) Improper Certificate Validation (CVE-ID: CVE-2026-87608)
CWE-ID: CWE-295 - Improper Certificate Validation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass certificate validation.
The vulnerability exists due to improper certificate validation in FedCM when validating certificates. A remote attacker can cause FedCM to improperly validate a certificate to bypass certificate validation.
User interaction is required.
50) Missing Authorization (CVE-ID: CVE-2026-87606)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization controls.
The vulnerability exists due to missing authorization in SiteIsolation when handling site isolation operations. A remote attacker can exploit the missing authorization controls to bypass authorization controls.
51) Missing Authorization (CVE-ID: CVE-2026-87605)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to missing authorization in the Contacts feature when processing contact-related requests. A remote attacker can interact with the Contacts feature to disclose sensitive information.
52) Out-of-bounds read (CVE-ID: CVE-2026-87604)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the ANGLE component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.
53) Missing Authorization (CVE-ID: CVE-2026-87603)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization controls for the FileSystem.
The vulnerability exists due to missing authorization checks in the FileSystem when a victim interacts with affected FileSystem functionality. A remote attacker can cause a victim to interact with the affected FileSystem functionality to bypass authorization controls for the FileSystem.
User interaction is required.
54) Out-of-bounds read (CVE-ID: CVE-2026-87602)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to a boundary condition within the ANGLE component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and crash the browser.
55) Input validation error (CVE-ID: CVE-2026-87600)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause an unspecified impact.
The vulnerability exists due to improper input validation in Safebrowsing when processing input. A remote attacker can provide specially crafted input to cause an unspecified impact.
User interaction is required.
56) Input validation error (CVE-ID: CVE-2026-87599)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to insufficient validation of user-supplied input in Interstitials in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.
57) Incorrect authorization (CVE-ID: CVE-2026-87598)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access ServiceWorker functionality without authorization.
The vulnerability exists due to incorrect authorization in ServiceWorker when processing crafted web content. A remote attacker can induce a victim to interact with crafted web content to access ServiceWorker functionality without authorization.
58) Out-of-bounds read (CVE-ID: CVE-2026-87596)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the ANGLE component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.
59) Incorrect authorization (CVE-ID: CVE-2026-87594)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to incorrect authorization in DataTransfer when handling DataTransfer operations. A remote attacker can invoke DataTransfer operations to perform unauthorized actions.
60) Information disclosure (CVE-ID: CVE-2026-87593)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper information disclosure in the Editing component when rendering web content. A remote attacker can cause web content to be rendered to disclose sensitive information.
User interaction is required.
61) Out-of-bounds read (CVE-ID: CVE-2026-87592)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to a boundary condition within the Tint component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and crash the browser.
62) Incorrect authorization (CVE-ID: CVE-2026-87591)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to incorrect authorization in Extensions when handling extension-related operations. A remote attacker can invoke extension functionality without proper authorization to perform unauthorized actions.
63) Input validation error (CVE-ID: CVE-2026-87590)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause an unspecified security impact.
The vulnerability exists due to improper input validation in Passwords when processing input. A remote attacker can provide specially crafted input to cause an unspecified security impact.
64) Incorrect authorization (CVE-ID: CVE-2026-87589)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to incorrect authorization in SiteIsolation when handling web content. A remote attacker can cause a victim to interact with web content to perform unauthorized actions.
65) Use-after-free (CVE-ID: CVE-2026-87588)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Chromecast in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
66) Out-of-bounds read (CVE-ID: CVE-2026-87586)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the ANGLE component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.
67) Double free (CVE-ID: CVE-2026-87585)
CWE-ID: CWE-415 - Double Free
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger a double-free condition.
The vulnerability exists due to a double free in PDFium when processing a PDF document. A remote attacker can trick a victim into opening a PDF document to trigger a double-free condition.
68) Incorrect authorization (CVE-ID: CVE-2026-87584)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to improper authorization in WebUI when handling WebUI requests. A remote attacker can induce a user to interact with WebUI functionality to perform unauthorized actions.
User interaction is required.
69) Spoofing attack (CVE-ID: CVE-2026-87583)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to misrepresent password-related user interface elements.
The vulnerability exists due to user interface misrepresentation in Passwords when rendering password-related user interface elements. A remote attacker can cause password-related user interface elements to be misrepresented to mislead users.
User interaction is required.
70) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-87582)
CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to a confused deputy vulnerability in DataTransfer when handling crafted web content. A remote attacker can trick a victim into interacting with crafted web content to perform unauthorized actions.
71) Use-after-free (CVE-ID: CVE-2026-87581)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Payments component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
72) Incorrect authorization (CVE-ID: CVE-2026-87580)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to improper authorization in WebAppInstalls when handling web application installation requests. A remote attacker can exploit the incorrect authorization to perform unauthorized actions.
User interaction is required.
73) Buffer overflow (CVE-ID: CVE-2026-87579)
CWE-ID: CWE-120 - Buffer overflow
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a buffer overflow in WebRTC when processing crafted WebRTC content. A remote attacker can trick the victim into processing crafted WebRTC content to cause a denial of service.
74) Use-after-free (CVE-ID: CVE-2026-87578)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Receiver component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
75) Incorrect authorization (CVE-ID: CVE-2026-87577)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access resources without proper authorization.
The vulnerability exists due to incorrect authorization in Isolated. Chrome Medium when handling crafted web content. A remote attacker can trick a victim into interacting with crafted web content to access resources without proper authorization.
User interaction is required.
76) Incorrect authorization (CVE-ID: CVE-2026-87575)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to incorrect authorization in Loader when performing authorization checks. A remote attacker can exploit the authorization flaw to perform unauthorized actions.
77) Information disclosure (CVE-ID: CVE-2026-87574)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in ServiceWorker in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
78) Input validation error (CVE-ID: CVE-2026-87573)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to insufficient validation of user-supplied input in Network in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.
CWE-ID: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to inject content into DevTools.
The vulnerability exists due to improper input neutralization in DevTools when handling crafted content. A remote attacker can provide crafted content to inject content into DevTools.
User interaction is required.
80) Improper Certificate Validation (CVE-ID: CVE-2026-87571)
CWE-ID: CWE-295 - Improper Certificate Validation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause Chrome to accept improperly validated certificates.
The vulnerability exists due to improper certificate validation in Loader when processing certificates. A remote attacker can provide an improperly validated certificate to cause Chrome to accept improperly validated certificates.
User interaction is required.
81) Incorrect authorization (CVE-ID: CVE-2026-87570)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access resources without proper authorization.
The vulnerability exists due to incorrect authorization in SiteIsolation when processing web content. A remote attacker can cause SiteIsolation to incorrectly authorize access to resources.
82) Missing Authorization (CVE-ID: CVE-2026-87569)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization.
The vulnerability exists due to missing authorization in Views when performing operations in Views. A remote attacker can trigger an operation in Views to bypass authorization.
User interaction is required.
83) Input validation error (CVE-ID: CVE-2026-87568)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger an unspecified security impact.
The vulnerability exists due to improper input validation in Chromium when processing input. A remote attacker can provide specially crafted input to trigger an unspecified security impact.
84) Spoofing attack (CVE-ID: CVE-2026-87567)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to misrepresent URL information.
The vulnerability exists due to UI misrepresentation in UrlFormatting when formatting URLs. A remote attacker can cause URL information to be misrepresented to misrepresent URL information.
User interaction is required.
85) Observable discrepancy (CVE-ID: CVE-2026-87566)
CWE-ID: CWE-203 - Observable discrepancy
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an observable discrepancy in Layout when rendering crafted web content. A remote attacker can trick the victim into visiting a crafted website to disclose sensitive information.
User interaction is required.
86) Information disclosure (CVE-ID: CVE-2026-87565)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an unspecified flaw in the Passwords component when a victim interacts with content. A remote attacker can induce a victim to interact with content to disclose sensitive information.
87) Origin validation error (CVE-ID: CVE-2026-87563)
CWE-ID: CWE-346 - Origin Validation Error
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass origin-based security restrictions.
The vulnerability exists due to improper origin validation in Paint when processing web content. A remote attacker can trick a victim into visiting a crafted website to bypass origin-based security restrictions.
88) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-87562)
CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause incorrect reference resolution.
The vulnerability exists due to incorrect reference resolution in the Accessibility component when a victim interacts with web content. A remote attacker can induce a victim to interact with web content to cause incorrect reference resolution.
89) Incorrect authorization (CVE-ID: CVE-2026-87561)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to incorrect authorization in Web Authentication when processing Web Authentication requests. A remote attacker can submit a crafted Web Authentication request to perform unauthorized actions.
90) Missing Authorization (CVE-ID: CVE-2026-87560)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to missing authorization in the Browser component when using the browser. A remote attacker can exploit the missing authorization to perform unauthorized actions.
User interaction is required.
91) Spoofing attack (CVE-ID: CVE-2026-87559)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to misrepresent the user interface.
The vulnerability exists due to UI misrepresentation in the UI when rendering web content. A remote attacker can trick the victim into interacting with misrepresented UI elements to misrepresent the user interface.
92) Use-after-free (CVE-ID: CVE-2026-87558)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Payments component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
93) Missing Authorization (CVE-ID: CVE-2026-87557)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access local network resources without authorization.
The vulnerability exists due to missing authorization in LocalNetworkAccess when handling crafted web content. A remote attacker can induce the victim to interact with crafted web content to access local network resources without authorization.
User interaction is required.
94) Missing Authorization (CVE-ID: CVE-2026-87556)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization controls.
The vulnerability exists due to missing authorization in the Browser component when processing authorization checks. A remote attacker can exploit the missing authorization to bypass authorization controls.
95) Race condition (CVE-ID: CVE-2026-87554)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a race condition in Chromoting in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and execute arbitrary code on the target system.
96) Input validation error (CVE-ID: CVE-2026-87553)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to insufficient validation of user-supplied input in SiteIsolation in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.
97) Improper Certificate Validation (CVE-ID: CVE-2026-87551)
CWE-ID: CWE-295 - Improper Certificate Validation
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass certificate validation.
The vulnerability exists due to improper certificate validation in CORS when handling CORS requests. A remote attacker can send a crafted CORS request to bypass certificate validation.
98) Improper Encoding or Escaping of Output (CVE-ID: CVE-2026-87550)
CWE-ID: CWE-116 - Improper Encoding or Escaping of Output
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to inject CSS.
The vulnerability exists due to improper encoding or escaping of output in CSS when rendering crafted CSS content. A remote attacker can provide crafted CSS content to inject CSS.
99) Incomplete cleanup (CVE-ID: CVE-2026-87549)
CWE-ID: CWE-459 - Incomplete cleanup
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to incomplete cleanup in Downloads in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.
100) Improper Enforcement of Behavioral Workflow (CVE-ID: CVE-2026-87548)
CWE-ID: CWE-841 - Improper Enforcement of Behavioral Workflow
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass intended installer state validation.
The vulnerability exists due to improper state validation in the installer when processing installer state. A remote attacker can cause the installer to accept an invalid state to bypass intended installer state validation.
User interaction is required.
101) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-87547)
CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access unintended files.
The vulnerability exists due to incorrect reference resolution in FileSystem when resolving crafted filesystem references. A remote attacker can supply crafted references to access unintended files.
User interaction is required.
102) Type conversion (CVE-ID: CVE-2026-87546)
CWE-ID: CWE-704 - Type conversion
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a low-severity security impact.
The vulnerability exists due to incorrect type conversion or cast in Safe Browsing when performing type conversions or casts. A remote attacker can trigger the vulnerable code path to cause a low-severity security impact.
103) Incorrect authorization (CVE-ID: CVE-2026-87544)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization restrictions.
The vulnerability exists due to incorrect authorization in Extensions when handling extension-related requests. A remote attacker can send a crafted extension-related request to bypass authorization restrictions.
User interaction is required.
104) Missing Authorization (CVE-ID: CVE-2026-87543)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to missing authorization in Core when a victim interacts with web content. A remote attacker can cause a victim to interact with web content to perform unauthorized actions.
105) Use-after-free (CVE-ID: CVE-2026-87542)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Input component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
106) Information disclosure (CVE-ID: CVE-2026-87541)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in Navigation in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
107) Incorrect authorization (CVE-ID: CVE-2026-87540)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to incorrect authorization in the Isolated component when processing crafted web content. A remote attacker can trick the victim into interacting with crafted web content to perform unauthorized actions.
User interaction is required.
108) Observable discrepancy (CVE-ID: CVE-2026-87539)
CWE-ID: CWE-203 - Observable discrepancy
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an observable discrepancy in the Network component when processing network-related content. A remote attacker can induce user interaction with network-related content to disclose sensitive information.
109) Improper Restriction of Rendered UI Layers or Frames (CVE-ID: CVE-2026-87538)
CWE-ID: CWE-1021 - Improper Restriction of Rendered UI Layers or Frames
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause users to perform unintended actions.
The vulnerability exists due to clickjacking in Input when rendering crafted web content. A remote attacker can trick a victim into interacting with crafted web content to cause users to perform unintended actions.
110) Missing Authorization (CVE-ID: CVE-2026-87537)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to missing authorization in Extensions when processing extension requests. A remote attacker can send a crafted extension request to perform unauthorized actions.
User interaction is required.
111) Information Loss or Omission (CVE-ID: CVE-2026-87535)
CWE-ID: CWE-221 - Information Loss or Omission
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause information loss.
The vulnerability exists due to information loss or omission in Safe Browsing when processing crafted web content. A remote attacker can trick the victim into visiting a crafted website to cause information loss.
112) Use-after-free (CVE-ID: CVE-2026-87533)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within DevTools in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
113) Improper Enforcement of Behavioral Workflow (CVE-ID: CVE-2026-87532)
CWE-ID: CWE-841 - Improper Enforcement of Behavioral Workflow
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to affect Safebrowsing functionality.
The vulnerability exists due to improper state validation in Safebrowsing when processing user-initiated browsing activity. A remote attacker can induce a victim to interact with crafted web content to affect Safebrowsing functionality.
114) Information disclosure (CVE-ID: CVE-2026-87531)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in CORS in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
115) Insecure DLL loading (CVE-ID: CVE-2026-87530)
CWE-ID: CWE-427 - Uncontrolled Search Path Element
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to an uncontrolled search path element in CredentialProvider when resolving files through an uncontrolled search path. A remote attacker can cause a malicious file to be loaded to execute arbitrary code.
User interaction is required.
116) Numeric Truncation Error (CVE-ID: CVE-2026-87529)
CWE-ID: CWE-197 - Numeric Truncation Error
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger an incorrect numeric conversion during media processing.
The vulnerability exists due to numeric truncation in the Media component when processing media content. A remote attacker can induce the victim to process crafted media content to trigger an incorrect numeric conversion during media processing.
117) Type Confusion (CVE-ID: CVE-2026-87528)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a type confusion error within the Rust component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a type confusion error and gain access to sensitive information.
118) Buffer overflow (CVE-ID: CVE-2026-87527)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a boundary error in WebGL in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger a buffer overflow and execute arbitrary code on the system.
119) Use-after-free (CVE-ID: CVE-2026-87526)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Passwords in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
120) Out-of-bounds read (CVE-ID: CVE-2026-87525)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the Chromoting component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.
121) Use-after-free (CVE-ID: CVE-2026-87524)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Core component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
122) Race condition (CVE-ID: CVE-2026-87523)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to a race condition in in DataTransfer in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and crash the browser.
123) Information disclosure (CVE-ID: CVE-2026-87521)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in WebMCP in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
124) Incorrect authorization (CVE-ID: CVE-2026-87519)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access protected Safe Browsing functionality.
The vulnerability exists due to incorrect authorization in Safe Browsing when using the Safe Browsing feature. A remote attacker can exploit the authorization flaw to access protected Safe Browsing functionality.
User interaction is required.
125) Observable discrepancy (CVE-ID: CVE-2026-87516)
CWE-ID: CWE-203 - Observable discrepancy
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an observable discrepancy in Navigation when handling navigation requests. A remote attacker can trick the victim into navigating to crafted content to disclose sensitive information.
126) Incorrect authorization (CVE-ID: CVE-2026-87515)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access resources without authorization.
The vulnerability exists due to incorrect authorization in FileAPI when handling FileAPI operations. A remote attacker can exploit the authorization flaw to access resources without authorization.
User interaction is required.
127) Use-after-free (CVE-ID: CVE-2026-87514)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Views component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
128) Missing Authorization (CVE-ID: CVE-2026-87513)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization.
The vulnerability exists due to missing authorization in ControlledFrame when processing ControlledFrame operations. A remote attacker can perform ControlledFrame operations to bypass authorization.
User interaction is required.
129) Use-after-free (CVE-ID: CVE-2026-87512)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the ANGLE component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
130) Missing Authorization (CVE-ID: CVE-2026-87511)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access DevTools functionality without authorization.
The vulnerability exists due to missing authorization in DevTools when accessing DevTools functionality. A remote attacker can access DevTools functionality without authorization to access DevTools functionality without authorization.
131) Input validation error (CVE-ID: CVE-2026-87510)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to insufficient validation of user-supplied input in FileAPI in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.
132) Incorrect authorization (CVE-ID: CVE-2026-87509)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization restrictions.
The vulnerability exists due to incorrect authorization in the Updater when handling update operations. A remote attacker can exploit the authorization flaw to bypass authorization restrictions.
133) Incorrect authorization (CVE-ID: CVE-2026-87508)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization controls.
The vulnerability exists due to incorrect authorization in Loader when loading content. A remote attacker can cause the browser to load crafted content to bypass authorization controls.
User interaction is required.
134) Spoofing attack (CVE-ID: CVE-2026-87507)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to misrepresent download-related information.
The vulnerability exists due to improper presentation of critical information in Downloads when displaying download-related information. A remote attacker can cause download-related information to be misrepresented to misrepresent download-related information.
User interaction is required.
135) Improper privilege management (CVE-ID: CVE-2026-87506)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper privilege management in WebUI when processing user-initiated WebUI interactions. A remote attacker can cause the victim to interact with WebUI content to escalate privileges.
User interaction is required.
136) Incorrect authorization (CVE-ID: CVE-2026-87505)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to incorrect authorization in FileSystem when processing user-initiated filesystem operations. A remote attacker can induce a victim to interact with web content that invokes filesystem operations to bypass authorization checks.
137) Use-after-free (CVE-ID: CVE-2026-87504)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Core in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
138) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-87502)
CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause the browser to perform unauthorized actions.
The vulnerability exists due to a confused deputy condition in the Fullscreen feature when handling fullscreen requests. A remote attacker can trick a victim into interacting with fullscreen content to cause the browser to perform unauthorized actions.
139) Spoofing attack (CVE-ID: CVE-2026-87501)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause UI misrepresentation.
The vulnerability exists due to UI misrepresentation in the Passwords feature when handling user interaction. A remote attacker can exploit the issue to cause UI misrepresentation.
140) Improper Validation of Array Index (CVE-ID: CVE-2026-87500)
CWE-ID: CWE-129 - Improper Validation of Array Index
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause an unspecified security impact.
The vulnerability exists due to improper validation of an array index in ANGLE when processing a crafted array index. A remote attacker can provide a crafted array index to cause an unspecified security impact.
User interaction is required.
141) Improper Authorization (CVE-ID: CVE-2026-87499)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to incorrect authorization in Network in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.
142) Missing Authorization (CVE-ID: CVE-2026-87498)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access WebUI functionality without authorization.
The vulnerability exists due to missing authorization in WebUI when accessing WebUI functionality. A remote attacker can access WebUI functionality without authorization to access WebUI functionality without authorization.
143) Use of uninitialized resource (CVE-ID: CVE-2026-87497)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use of an uninitialized resource in Codecs when processing media content. A remote attacker can cause the browser to process media content to cause a denial of service.
User interaction is required.
144) Spoofing attack (CVE-ID: CVE-2026-87496)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to mislead users.
The vulnerability exists due to UI misrepresentation in the Browser component when displaying browser UI. A remote attacker can cause browser UI to be misrepresented to mislead users.
145) Information disclosure (CVE-ID: CVE-2026-87495)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in Scroll in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
146) Use-after-free (CVE-ID: CVE-2026-87494)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Browser in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
147) Missing Authorization (CVE-ID: CVE-2026-87493)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized filesystem operations.
The vulnerability exists due to missing authorization in FileSystem when processing crafted web content. A remote attacker can provide crafted web content to perform unauthorized filesystem operations.
User interaction is required.
148) Improper Authorization (CVE-ID: CVE-2026-87492)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to incorrect authorization in DevTools in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.
149) Information disclosure (CVE-ID: CVE-2026-87490)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an unspecified flaw in the Transactions Platform when a victim interacts with content. A remote attacker can cause a victim to interact with content to disclose sensitive information.
150) Buffer overflow (CVE-ID: CVE-2026-87489)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger memory corruption.
The vulnerability exists due to memory corruption in V8 when processing web content. A remote attacker can induce a victim to interact with web content to trigger memory corruption.
User interaction is required.
151) Missing Authorization (CVE-ID: CVE-2026-87487)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access FileSystem resources without authorization.
The vulnerability exists due to missing authorization in FileSystem when accessing FileSystem resources. A remote attacker can access FileSystem resources without authorization to access FileSystem resources without authorization.
User interaction is required.
152) Incorrect authorization (CVE-ID: CVE-2026-87485)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access cross-origin resources.
The vulnerability exists due to incorrect authorization in CORS when processing cross-origin requests. A remote attacker can trick the victim into visiting crafted web content to access cross-origin resources.
153) Spoofing attack (CVE-ID: CVE-2026-87484)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to spoof user interface elements.
The vulnerability exists due to UI misrepresentation in Geometry when rendering crafted web content. A remote attacker can cause crafted web content to be rendered to spoof user interface elements.
User interaction is required to view the crafted web content.
154) Use-after-free (CVE-ID: CVE-2026-87480)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Printing component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
155) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2026-87479)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient policy enforcement in Extensions in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and gain access to sensitive information.
156) Observable discrepancy (CVE-ID: CVE-2026-87478)
CWE-ID: CWE-203 - Observable discrepancy
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an observable discrepancy in Autofill when processing autofill data. A remote attacker can interact with Autofill to disclose sensitive information.
User interaction is required.
157) Information disclosure (CVE-ID: CVE-2026-87477)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an unspecified information disclosure flaw in Chrome Core when a user interacts with content processed by Chrome. A remote attacker can cause a user to interact with content processed by Chrome to disclose sensitive information.
158) Incorrect authorization (CVE-ID: CVE-2026-87476)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization controls.
The vulnerability exists due to incorrect authorization in Loader when performing authorization checks. A remote attacker can exploit the authorization flaw to bypass authorization controls.
159) Missing Authorization (CVE-ID: CVE-2026-87475)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to missing authorization in Omnibox when processing omnibox input. A remote attacker can cause input to be processed without required authorization checks to perform unauthorized actions.
User interaction is required.
160) Use-after-free (CVE-ID: CVE-2026-87474)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Payments component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
161) Incorrect authorization (CVE-ID: CVE-2026-87473)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access resources without authorization.
The vulnerability exists due to improper authorization in FileHandling when processing content after user interaction. A remote attacker can induce a victim to interact with content to access resources without authorization.
162) Input validation error (CVE-ID: CVE-2026-87472)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to insufficient validation of user-supplied input in FedCM in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.
163) Incorrect authorization (CVE-ID: CVE-2026-87471)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization restrictions.
The vulnerability exists due to incorrect authorization in ServiceWorker when processing crafted web content. A remote attacker can trick the victim into interacting with crafted web content to bypass authorization restrictions.
164) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-87470)
CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger an unspecified impact.
The vulnerability exists due to improper quantity validation in Tint when processing input. A remote attacker can provide input containing an improperly validated quantity to trigger an unspecified impact.
165) Input validation error (CVE-ID: CVE-2026-87469)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a low-severity security impact.
The vulnerability exists due to improper input validation in Extensions when processing input. A remote attacker can provide specially crafted input to cause a low-severity security impact.
166) Incorrect authorization (CVE-ID: CVE-2026-87468)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization restrictions.
The vulnerability exists due to incorrect authorization in the Isolated component when processing crafted web content. A remote attacker can trick a victim into interacting with crafted web content to bypass authorization restrictions.
167) Race condition (CVE-ID: CVE-2026-87467)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a race condition in Updater in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and execute arbitrary code on the target system.
168) Incorrect authorization (CVE-ID: CVE-2026-87466)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to incorrect authorization in Workers when processing crafted web content. A remote attacker can trick a victim into interacting with crafted web content to perform unauthorized actions.
169) Incorrect authorization (CVE-ID: CVE-2026-87465)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to incorrect authorization in Downloads when handling downloads. A remote attacker can exploit the authorization flaw to perform unauthorized actions.
170) Incorrect authorization (CVE-ID: CVE-2026-87463)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization controls.
The vulnerability exists due to incorrect authorization in Certificate when handling certificate-related operations. A remote attacker can exploit the issue to bypass authorization controls.
User interaction is required.
171) Spoofing attack (CVE-ID: CVE-2026-87462)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to misrepresent FedCM user interface elements.
The vulnerability exists due to UI misrepresentation in FedCM when rendering FedCM user interface elements. A remote attacker can induce a victim to interact with misleading FedCM user interface elements to misrepresent FedCM user interface elements.
User interaction is required.
172) Information disclosure (CVE-ID: CVE-2026-87461)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an unspecified information disclosure flaw in Core when processing content after user interaction. A remote attacker can cause a victim to interact with crafted content to disclose sensitive information.
173) Use-after-free (CVE-ID: CVE-2026-87460)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Platform component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
174) Observable discrepancy (CVE-ID: CVE-2026-87459)
CWE-ID: CWE-203 - Observable discrepancy
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to obtain information.
The vulnerability exists due to an observable discrepancy in Select when interacting with Select. A remote attacker can trigger the observable discrepancy to obtain information.
175) Spoofing attack (CVE-ID: CVE-2026-87458)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to misrepresent user interface elements.
The vulnerability exists due to UI misrepresentation in Geometry when rendering content. A remote attacker can exploit the UI misrepresentation to misrepresent user interface elements.
User interaction is required.
176) Race condition (CVE-ID: CVE-2026-87457)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to a race condition in in Updater in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and crash the browser.
177) Use of uninitialized resource (CVE-ID: CVE-2026-87456)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger an unspecified impact.
The vulnerability exists due to use of an uninitialized resource in the Media component when processing media content. A remote attacker can interact with the Media component to trigger an unspecified impact.
178) Use-after-free (CVE-ID: CVE-2026-87455)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Aura in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
179) Information disclosure (CVE-ID: CVE-2026-87454)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in Enterprise in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
180) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-87453)
CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to a confused deputy weakness in BackgroundFetch when handling web content. A remote attacker can cause BackgroundFetch to act on their behalf to perform unauthorized actions.
181) Incorrect authorization (CVE-ID: CVE-2026-87452)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to incorrect authorization in the GPU component when processing crafted web content. A remote attacker can cause a victim to interact with crafted web content to perform unauthorized actions.
182) Information disclosure (CVE-ID: CVE-2026-87451)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in Downloads in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
183) Incorrect authorization (CVE-ID: CVE-2026-87450)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to incorrect authorization in Permissions when handling permission requests. A remote attacker can exploit the authorization flaw to perform unauthorized actions.
184) Cross-site request forgery (CVE-ID: CVE-2026-87449)
CWE-ID: CWE-352 - Cross-Site Request Forgery (CSRF)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform cross-site request forgery.
The vulnerability exists due to cross-site request forgery in DeviceBoundSessionCredentials when handling cross-site requests. A remote attacker can send a crafted cross-site request to perform cross-site request forgery.
185) Use-after-free (CVE-ID: CVE-2026-87448)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to use-after-free error in DevTools in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.
186) Improper Authorization (CVE-ID: CVE-2026-87447)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to incorrect authorization in Network in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.
187) Incomplete cleanup (CVE-ID: CVE-2026-87446)
CWE-ID: CWE-459 - Incomplete cleanup
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to incomplete cleanup in Extensions in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.
188) Spoofing attack (CVE-ID: CVE-2026-87445)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to misrepresent the user interface.
The vulnerability exists due to user interface misrepresentation in the Session component when interacting with the Session component. A remote attacker can trigger the UI misrepresentation to misrepresent the user interface.
189) Buffer overflow (CVE-ID: CVE-2026-87444)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a boundary error in Codecs in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger a buffer overflow and execute arbitrary code on the system.
190) Missing Authorization (CVE-ID: CVE-2026-87443)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access unauthorized resources.
The vulnerability exists due to missing authorization in Actor when processing crafted web content. A remote attacker can trick a victim into interacting with crafted web content to access unauthorized resources.
191) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-87442)
CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to a confused deputy issue in Prerender when handling crafted web content. A remote attacker can trick a victim into interacting with crafted web content to perform unauthorized actions.
192) Missing Authorization (CVE-ID: CVE-2026-87441)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized download-related actions.
The vulnerability exists due to missing authorization in Downloads when handling download-related actions. A remote attacker can invoke download-related functionality without required authorization to perform unauthorized download-related actions.
193) Out-of-bounds read (CVE-ID: CVE-2026-87440)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the Media component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.
194) Information disclosure (CVE-ID: CVE-2026-87439)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in ServiceWorker in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
195) Information disclosure (CVE-ID: CVE-2026-87437)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an unspecified flaw in Frames when handling frames. A remote attacker can induce a victim to interact with web content to disclose sensitive information.
196) Incomplete cleanup (CVE-ID: CVE-2026-87436)
CWE-ID: CWE-459 - Incomplete cleanup
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to incomplete cleanup in Browser in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.
197) Information disclosure (CVE-ID: CVE-2026-87435)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in ControlledFrame in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
198) Missing Authorization (CVE-ID: CVE-2026-87434)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to missing authorization in CORS when handling cross-origin requests. A remote attacker can trick a victim into visiting a crafted website to disclose sensitive information.
User interaction is required.
Remediation
Install update from vendor's website.
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-85893
- https://docs.microsoft.com/en-us/DeployEdge/microsoft-edge-relnotes-security
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69486
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87658
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87657
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87656
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87655
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87654
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87653
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87652
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87651
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87650
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87649
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87648
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87647
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87646
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87645
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87644
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87642
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87641
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87639
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87638
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87637
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87636
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87635
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87634
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87633
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87632
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87631
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87630
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87629
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87628
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87627
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87626
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87624
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87623
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87622
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87621
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87620
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87619
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87618
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87617
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87616
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87615
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87614
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87613
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87611
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87610
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87609
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87608
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87606
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87605
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87604
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87603
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87602
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87600
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87599
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87598
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87596
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87594
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87593
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87592
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87591
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87590
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87589
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87588
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87586
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87585
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87584
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87583
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87582
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87581
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87580
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87579
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87578
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87577
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87575
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87574
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87573
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87572
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87571
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87570
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87569
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87568
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87567
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87566
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87565
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87563
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87562
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87561
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87560
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87559
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87558
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87557
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87556
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87554
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87553
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87551
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87550
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87549
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87548
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87547
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87546
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87544
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87543
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87542
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87541
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87540
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87539
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87538
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87537
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87535
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87533
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87532
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87531
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87530
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87529
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87528
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87527
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87526
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87525
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87524
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87523
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87521
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87519
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87516
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87515
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87514
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87513
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87512
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87511
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87510
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87509
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87508
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87507
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87506
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87505
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87504
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87502
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87501
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87500
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87499
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87498
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87497
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87496
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87495
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87494
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87493
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87492
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87490
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87489
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87487
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87485
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87484
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87480
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87479
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87478
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87477
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87476
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87475
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87474
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87473
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87472
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87471
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87470
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87469
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87468
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87467
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87466
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87465
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87463
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87462
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87461
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87460
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87459
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87458
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87457
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87456
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87455
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87454
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87453
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87452
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87451
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87450
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87449
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87448
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87447
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87446
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87445
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87444
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87443
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87442
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87441
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87440
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87439
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87437
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87436
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87435
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87434