SB20260917239 - Multiple vulnerabilities in Microsoft Edge



SB20260917239 - Multiple vulnerabilities in Microsoft Edge

Published: September 17, 2026

Security Bulletin ID SB20260917239
CSH Severity
High
Patch available
YES
Number of vulnerabilities 198
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 12% Medium 25% Low 63%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 198 vulnerabilities.


1) Use-after-free (CVE-ID: CVE-2026-85893)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to elevate privileges.

The vulnerability exists due to use-after-free in Microsoft Edge (Chromium-based) autofill functionality when activating autofill on an attacker-controlled webpage. A remote attacker can cause the user to visit an attacker-controlled webpage and perform two tap gestures that activate autofill to elevate privileges.

Successful exploitation elevates privileges from a low-integrity sandboxed execution environment to a medium-integrity level.


2) Heap-based buffer overflow (CVE-ID: CVE-2026-69486)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to a heap-based buffer overflow in Microsoft Edge (Chromium-based) when opening a malicious Office file. A remote attacker can send a malicious Office file and convince the victim to open it to execute arbitrary code.


3) Information disclosure (CVE-ID: CVE-2026-87658)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in Extensions in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


4) Use-after-free (CVE-ID: CVE-2026-87657)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within V8 in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


5) Improper Enforcement of Behavioral Workflow (CVE-ID: CVE-2026-87656)

CWE-ID: CWE-841 - Improper Enforcement of Behavioral Workflow

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause an unspecified impact.

The vulnerability exists due to improper state validation in Safebrowsing when handling Safe Browsing state. A remote attacker can trigger an invalid state to cause an unspecified impact.


6) Improper Restriction of Rendered UI Layers or Frames (CVE-ID: CVE-2026-87655)

CWE-ID: CWE-1021 - Improper Restriction of Rendered UI Layers or Frames

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unintended download-related actions.

The vulnerability exists due to clickjacking in the Downloads feature when rendering web content. A remote attacker can trick a victim into interacting with crafted web content to perform unintended download-related actions.

User interaction is required.


7) Buffer overflow (CVE-ID: CVE-2026-87654)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a boundary error in ANGLE in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger a buffer overflow and execute arbitrary code on the system.


8) Spoofing attack (CVE-ID: CVE-2026-87653)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent browser user interface elements.

The vulnerability exists due to user interface misrepresentation in the FullScreen feature when displaying crafted web content in fullscreen mode. A remote attacker can trick a victim into viewing crafted web content to misrepresent browser user interface elements.

User interaction is required.


9) Incorrect authorization (CVE-ID: CVE-2026-87652)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in PushAPI when processing PushAPI requests. A remote attacker can send a crafted PushAPI request to perform unauthorized actions.

User interaction is required.


10) Improper Authorization (CVE-ID: CVE-2026-87651)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to incorrect authorization in Paint in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.


11) Out-of-bounds read (CVE-ID: CVE-2026-87650)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the WebGL component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.


12) Spoofing attack (CVE-ID: CVE-2026-87649)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to deceive users through download-related UI.

The vulnerability exists due to UI misrepresentation in Downloads when presenting download-related information. A remote attacker can exploit this flaw to deceive users through download-related UI.


13) Use-after-free (CVE-ID: CVE-2026-87648)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within ANGLE in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


14) Use of uninitialized resource (CVE-ID: CVE-2026-87647)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to usage of uninitialized resources in GPU in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger uninitialized usage of resources and compromise the affected system.


15) Use-after-free (CVE-ID: CVE-2026-87646)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Web Authentication component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


16) State Issues (CVE-ID: CVE-2026-87645)

CWE-ID: CWE-371 - State Issues

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to improper state validation in Safebrowsing in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.


17) Incorrect authorization (CVE-ID: CVE-2026-87644)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in Views when processing crafted web content. A remote attacker can trick a victim into interacting with crafted web content to perform unauthorized actions.

User interaction is required.


18) Use of uninitialized resource (CVE-ID: CVE-2026-87642)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger unspecified behavior.

The vulnerability exists due to use of an uninitialized resource in WebGL when handling WebGL resources. A remote attacker can trigger the uninitialized resource condition to trigger unspecified behavior.


19) Race condition (CVE-ID: CVE-2026-87641)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a race condition in in Browser in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and crash the browser.


20) Use-after-free (CVE-ID: CVE-2026-87639)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the WebPackaging component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


21) Out-of-bounds write (CVE-ID: CVE-2026-87638)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted HTML content in Media. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.


22) Use-after-free (CVE-ID: CVE-2026-87637)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within Extensions in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


23) Type Confusion (CVE-ID: CVE-2026-87636)

CWE-ID: CWE-843 - Type confusion

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a type confusion error within the XML component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a type confusion error and gain access to sensitive information.


24) Spoofing attack (CVE-ID: CVE-2026-87635)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent payment-related user interface elements.

The vulnerability exists due to UI misrepresentation in Payments when rendering payment-related user interface elements. A remote attacker can cause payment-related user interface elements to be misrepresented.

User interaction is required.


25) Use-after-free (CVE-ID: CVE-2026-87634)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to use-after-free error in WebPackaging in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


26) Use-after-free (CVE-ID: CVE-2026-87633)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Views component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


27) Cross-site scripting (CVE-ID: CVE-2026-87632)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote attacker to execute arbitrary script in a victim's browser.

The vulnerability exists due to improper neutralization of input during web page generation in SanitizerAPI when processing crafted web content. A remote attacker can cause a victim to process crafted web content to execute arbitrary script in a victim's browser.

User interaction is required.


28) Missing Authorization (CVE-ID: CVE-2026-87631)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access restricted DOM resources.

The vulnerability exists due to missing authorization in the DOM when rendering crafted web content. A remote attacker can induce a victim to render crafted web content to access restricted DOM resources.

User interaction is required to render crafted web content.


29) Integer overflow (CVE-ID: CVE-2026-87630)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a integer overflow in WebRTC in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.


30) Incorrect authorization (CVE-ID: CVE-2026-87629)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in sources when handling crafted content. A remote attacker can induce a victim to interact with crafted content to perform unauthorized actions.


31) Use-after-free (CVE-ID: CVE-2026-87628)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Cast component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


32) Interpretation Conflict (CVE-ID: CVE-2026-87627)

CWE-ID: CWE-436 - Interpretation Conflict

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass Safe Browsing protections.

The vulnerability exists due to an interpretation conflict in Safe Browsing when processing web content. A remote attacker can provide crafted web content to bypass Safe Browsing protections.

User interaction is required.


33) Incorrect authorization (CVE-ID: CVE-2026-87626)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access DeviceBoundSessionCredentials without authorization.

The vulnerability exists due to incorrect authorization in DeviceBoundSessionCredentials when performing authorization checks. A remote attacker can trigger the flawed authorization check to access DeviceBoundSessionCredentials without authorization.

User interaction is required.


34) Spoofing attack (CVE-ID: CVE-2026-87624)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to display misleading password-related information.

The vulnerability exists due to user interface misrepresentation in the Passwords feature when a victim interacts with crafted web content. A remote attacker can induce the victim to interact with misleading password-related information to display misleading password-related information.


35) Observable discrepancy (CVE-ID: CVE-2026-87623)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose information.

The vulnerability exists due to an observable discrepancy in the DOM when rendering crafted web content. A remote attacker can cause an observable discrepancy in the DOM to disclose information.

User interaction is required to render the crafted web content.


36) Missing Authorization (CVE-ID: CVE-2026-87622)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to missing authorization in FedCM when processing FedCM requests. A remote attacker can induce the victim to interact with web content to perform unauthorized actions.

User interaction is required.


37) Out-of-bounds write (CVE-ID: CVE-2026-87621)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted HTML content in ANGLE. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.


38) Observable discrepancy (CVE-ID: CVE-2026-87620)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an observable discrepancy in SVG when rendering crafted SVG content. A remote attacker can cause the browser to render crafted SVG content to disclose sensitive information.


39) Observable discrepancy (CVE-ID: CVE-2026-87619)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an observable discrepancy in Prefetch when prefetching content. A remote attacker can observe differences in Prefetch behavior to disclose sensitive information.


40) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-87618)

CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause incorrect reference resolution.

The vulnerability exists due to incorrect reference resolution in Storage when resolving references. A remote attacker can cause a reference to be resolved incorrectly to cause incorrect reference resolution.


41) Use-after-free (CVE-ID: CVE-2026-87617)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to use-after-free error in DevTools in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


42) Improper initialization (CVE-ID: CVE-2026-87616)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to improper initialization in Views in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


43) Race condition (CVE-ID: CVE-2026-87615)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger a race condition in payment processing.

The vulnerability exists due to a race condition in Payments when using payment-related functionality. A remote attacker can interact with the Payments feature to trigger a race condition in payment processing.

User interaction is required.


44) Incorrect authorization (CVE-ID: CVE-2026-87614)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization controls.

The vulnerability exists due to incorrect authorization in ServiceWorker when handling ServiceWorker operations. A remote attacker can exploit the incorrect authorization to bypass authorization controls.


45) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-87613)

CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass security restrictions.

The vulnerability exists due to incorrect reference resolution in Extensions when processing extension references. A remote attacker can provide crafted extension references to bypass security restrictions.

User interaction is required.


46) Missing Authorization (CVE-ID: CVE-2026-87611)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access file system resources without authorization.

The vulnerability exists due to missing authorization in the FileSystem component when a victim interacts with web content. A remote attacker can cause a victim to interact with web content to access file system resources without authorization.


47) Incorrect authorization (CVE-ID: CVE-2026-87610)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in the Omnibox when processing Omnibox input. A remote attacker can cause a victim to interact with the Omnibox to perform unauthorized actions.


48) Use-after-free (CVE-ID: CVE-2026-87609)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within Sharing in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


49) Improper Certificate Validation (CVE-ID: CVE-2026-87608)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass certificate validation.

The vulnerability exists due to improper certificate validation in FedCM when validating certificates. A remote attacker can cause FedCM to improperly validate a certificate to bypass certificate validation.

User interaction is required.


50) Missing Authorization (CVE-ID: CVE-2026-87606)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization controls.

The vulnerability exists due to missing authorization in SiteIsolation when handling site isolation operations. A remote attacker can exploit the missing authorization controls to bypass authorization controls.


51) Missing Authorization (CVE-ID: CVE-2026-87605)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to missing authorization in the Contacts feature when processing contact-related requests. A remote attacker can interact with the Contacts feature to disclose sensitive information.


52) Out-of-bounds read (CVE-ID: CVE-2026-87604)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the ANGLE component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.


53) Missing Authorization (CVE-ID: CVE-2026-87603)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization controls for the FileSystem.

The vulnerability exists due to missing authorization checks in the FileSystem when a victim interacts with affected FileSystem functionality. A remote attacker can cause a victim to interact with the affected FileSystem functionality to bypass authorization controls for the FileSystem.

User interaction is required.


54) Out-of-bounds read (CVE-ID: CVE-2026-87602)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a boundary condition within the ANGLE component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and crash the browser.


55) Input validation error (CVE-ID: CVE-2026-87600)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause an unspecified impact.

The vulnerability exists due to improper input validation in Safebrowsing when processing input. A remote attacker can provide specially crafted input to cause an unspecified impact.

User interaction is required.


56) Input validation error (CVE-ID: CVE-2026-87599)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to insufficient validation of user-supplied input in Interstitials in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


57) Incorrect authorization (CVE-ID: CVE-2026-87598)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access ServiceWorker functionality without authorization.

The vulnerability exists due to incorrect authorization in ServiceWorker when processing crafted web content. A remote attacker can induce a victim to interact with crafted web content to access ServiceWorker functionality without authorization.


58) Out-of-bounds read (CVE-ID: CVE-2026-87596)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the ANGLE component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.


59) Incorrect authorization (CVE-ID: CVE-2026-87594)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in DataTransfer when handling DataTransfer operations. A remote attacker can invoke DataTransfer operations to perform unauthorized actions.


60) Information disclosure (CVE-ID: CVE-2026-87593)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper information disclosure in the Editing component when rendering web content. A remote attacker can cause web content to be rendered to disclose sensitive information.

User interaction is required.


61) Out-of-bounds read (CVE-ID: CVE-2026-87592)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a boundary condition within the Tint component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and crash the browser.


62) Incorrect authorization (CVE-ID: CVE-2026-87591)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in Extensions when handling extension-related operations. A remote attacker can invoke extension functionality without proper authorization to perform unauthorized actions.


63) Input validation error (CVE-ID: CVE-2026-87590)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause an unspecified security impact.

The vulnerability exists due to improper input validation in Passwords when processing input. A remote attacker can provide specially crafted input to cause an unspecified security impact.


64) Incorrect authorization (CVE-ID: CVE-2026-87589)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in SiteIsolation when handling web content. A remote attacker can cause a victim to interact with web content to perform unauthorized actions.


65) Use-after-free (CVE-ID: CVE-2026-87588)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within Chromecast in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


66) Out-of-bounds read (CVE-ID: CVE-2026-87586)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the ANGLE component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.


67) Double free (CVE-ID: CVE-2026-87585)

CWE-ID: CWE-415 - Double Free

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger a double-free condition.

The vulnerability exists due to a double free in PDFium when processing a PDF document. A remote attacker can trick a victim into opening a PDF document to trigger a double-free condition.


68) Incorrect authorization (CVE-ID: CVE-2026-87584)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to improper authorization in WebUI when handling WebUI requests. A remote attacker can induce a user to interact with WebUI functionality to perform unauthorized actions.

User interaction is required.


69) Spoofing attack (CVE-ID: CVE-2026-87583)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent password-related user interface elements.

The vulnerability exists due to user interface misrepresentation in Passwords when rendering password-related user interface elements. A remote attacker can cause password-related user interface elements to be misrepresented to mislead users.

User interaction is required.


70) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-87582)

CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to a confused deputy vulnerability in DataTransfer when handling crafted web content. A remote attacker can trick a victim into interacting with crafted web content to perform unauthorized actions.


71) Use-after-free (CVE-ID: CVE-2026-87581)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Payments component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


72) Incorrect authorization (CVE-ID: CVE-2026-87580)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to improper authorization in WebAppInstalls when handling web application installation requests. A remote attacker can exploit the incorrect authorization to perform unauthorized actions.

User interaction is required.


73) Buffer overflow (CVE-ID: CVE-2026-87579)

CWE-ID: CWE-120 - Buffer overflow

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a buffer overflow in WebRTC when processing crafted WebRTC content. A remote attacker can trick the victim into processing crafted WebRTC content to cause a denial of service.


74) Use-after-free (CVE-ID: CVE-2026-87578)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Receiver component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


75) Incorrect authorization (CVE-ID: CVE-2026-87577)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access resources without proper authorization.

The vulnerability exists due to incorrect authorization in Isolated. Chrome Medium when handling crafted web content. A remote attacker can trick a victim into interacting with crafted web content to access resources without proper authorization.

User interaction is required.


76) Incorrect authorization (CVE-ID: CVE-2026-87575)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in Loader when performing authorization checks. A remote attacker can exploit the authorization flaw to perform unauthorized actions.


77) Information disclosure (CVE-ID: CVE-2026-87574)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in ServiceWorker in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


78) Input validation error (CVE-ID: CVE-2026-87573)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to insufficient validation of user-supplied input in Network in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


79) Improper Neutralization of Special Elements in Output Used by a Downstream Component (CVE-ID: CVE-2026-87572)

CWE-ID: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to inject content into DevTools.

The vulnerability exists due to improper input neutralization in DevTools when handling crafted content. A remote attacker can provide crafted content to inject content into DevTools.

User interaction is required.


80) Improper Certificate Validation (CVE-ID: CVE-2026-87571)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause Chrome to accept improperly validated certificates.

The vulnerability exists due to improper certificate validation in Loader when processing certificates. A remote attacker can provide an improperly validated certificate to cause Chrome to accept improperly validated certificates.

User interaction is required.


81) Incorrect authorization (CVE-ID: CVE-2026-87570)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access resources without proper authorization.

The vulnerability exists due to incorrect authorization in SiteIsolation when processing web content. A remote attacker can cause SiteIsolation to incorrectly authorize access to resources.


82) Missing Authorization (CVE-ID: CVE-2026-87569)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization.

The vulnerability exists due to missing authorization in Views when performing operations in Views. A remote attacker can trigger an operation in Views to bypass authorization.

User interaction is required.


83) Input validation error (CVE-ID: CVE-2026-87568)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger an unspecified security impact.

The vulnerability exists due to improper input validation in Chromium when processing input. A remote attacker can provide specially crafted input to trigger an unspecified security impact.


84) Spoofing attack (CVE-ID: CVE-2026-87567)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent URL information.

The vulnerability exists due to UI misrepresentation in UrlFormatting when formatting URLs. A remote attacker can cause URL information to be misrepresented to misrepresent URL information.

User interaction is required.


85) Observable discrepancy (CVE-ID: CVE-2026-87566)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an observable discrepancy in Layout when rendering crafted web content. A remote attacker can trick the victim into visiting a crafted website to disclose sensitive information.

User interaction is required.


86) Information disclosure (CVE-ID: CVE-2026-87565)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an unspecified flaw in the Passwords component when a victim interacts with content. A remote attacker can induce a victim to interact with content to disclose sensitive information.


87) Origin validation error (CVE-ID: CVE-2026-87563)

CWE-ID: CWE-346 - Origin Validation Error

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass origin-based security restrictions.

The vulnerability exists due to improper origin validation in Paint when processing web content. A remote attacker can trick a victim into visiting a crafted website to bypass origin-based security restrictions.


88) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-87562)

CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause incorrect reference resolution.

The vulnerability exists due to incorrect reference resolution in the Accessibility component when a victim interacts with web content. A remote attacker can induce a victim to interact with web content to cause incorrect reference resolution.


89) Incorrect authorization (CVE-ID: CVE-2026-87561)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in Web Authentication when processing Web Authentication requests. A remote attacker can submit a crafted Web Authentication request to perform unauthorized actions.


90) Missing Authorization (CVE-ID: CVE-2026-87560)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to missing authorization in the Browser component when using the browser. A remote attacker can exploit the missing authorization to perform unauthorized actions.

User interaction is required.


91) Spoofing attack (CVE-ID: CVE-2026-87559)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent the user interface.

The vulnerability exists due to UI misrepresentation in the UI when rendering web content. A remote attacker can trick the victim into interacting with misrepresented UI elements to misrepresent the user interface.


92) Use-after-free (CVE-ID: CVE-2026-87558)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Payments component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


93) Missing Authorization (CVE-ID: CVE-2026-87557)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access local network resources without authorization.

The vulnerability exists due to missing authorization in LocalNetworkAccess when handling crafted web content. A remote attacker can induce the victim to interact with crafted web content to access local network resources without authorization.

User interaction is required.


94) Missing Authorization (CVE-ID: CVE-2026-87556)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization controls.

The vulnerability exists due to missing authorization in the Browser component when processing authorization checks. A remote attacker can exploit the missing authorization to bypass authorization controls.


95) Race condition (CVE-ID: CVE-2026-87554)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a race condition in Chromoting in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and execute arbitrary code on the target system.


96) Input validation error (CVE-ID: CVE-2026-87553)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to insufficient validation of user-supplied input in SiteIsolation in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


97) Improper Certificate Validation (CVE-ID: CVE-2026-87551)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass certificate validation.

The vulnerability exists due to improper certificate validation in CORS when handling CORS requests. A remote attacker can send a crafted CORS request to bypass certificate validation.


98) Improper Encoding or Escaping of Output (CVE-ID: CVE-2026-87550)

CWE-ID: CWE-116 - Improper Encoding or Escaping of Output

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to inject CSS.

The vulnerability exists due to improper encoding or escaping of output in CSS when rendering crafted CSS content. A remote attacker can provide crafted CSS content to inject CSS.


99) Incomplete cleanup (CVE-ID: CVE-2026-87549)

CWE-ID: CWE-459 - Incomplete cleanup

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to incomplete cleanup in Downloads in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.


100) Improper Enforcement of Behavioral Workflow (CVE-ID: CVE-2026-87548)

CWE-ID: CWE-841 - Improper Enforcement of Behavioral Workflow

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass intended installer state validation.

The vulnerability exists due to improper state validation in the installer when processing installer state. A remote attacker can cause the installer to accept an invalid state to bypass intended installer state validation.

User interaction is required.


101) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-87547)

CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access unintended files.

The vulnerability exists due to incorrect reference resolution in FileSystem when resolving crafted filesystem references. A remote attacker can supply crafted references to access unintended files.

User interaction is required.


102) Type conversion (CVE-ID: CVE-2026-87546)

CWE-ID: CWE-704 - Type conversion

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a low-severity security impact.

The vulnerability exists due to incorrect type conversion or cast in Safe Browsing when performing type conversions or casts. A remote attacker can trigger the vulnerable code path to cause a low-severity security impact.


103) Incorrect authorization (CVE-ID: CVE-2026-87544)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization restrictions.

The vulnerability exists due to incorrect authorization in Extensions when handling extension-related requests. A remote attacker can send a crafted extension-related request to bypass authorization restrictions.

User interaction is required.


104) Missing Authorization (CVE-ID: CVE-2026-87543)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to missing authorization in Core when a victim interacts with web content. A remote attacker can cause a victim to interact with web content to perform unauthorized actions.


105) Use-after-free (CVE-ID: CVE-2026-87542)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Input component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


106) Information disclosure (CVE-ID: CVE-2026-87541)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in Navigation in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


107) Incorrect authorization (CVE-ID: CVE-2026-87540)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in the Isolated component when processing crafted web content. A remote attacker can trick the victim into interacting with crafted web content to perform unauthorized actions.

User interaction is required.


108) Observable discrepancy (CVE-ID: CVE-2026-87539)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an observable discrepancy in the Network component when processing network-related content. A remote attacker can induce user interaction with network-related content to disclose sensitive information.


109) Improper Restriction of Rendered UI Layers or Frames (CVE-ID: CVE-2026-87538)

CWE-ID: CWE-1021 - Improper Restriction of Rendered UI Layers or Frames

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause users to perform unintended actions.

The vulnerability exists due to clickjacking in Input when rendering crafted web content. A remote attacker can trick a victim into interacting with crafted web content to cause users to perform unintended actions.


110) Missing Authorization (CVE-ID: CVE-2026-87537)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to missing authorization in Extensions when processing extension requests. A remote attacker can send a crafted extension request to perform unauthorized actions.

User interaction is required.


111) Information Loss or Omission (CVE-ID: CVE-2026-87535)

CWE-ID: CWE-221 - Information Loss or Omission

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause information loss.

The vulnerability exists due to information loss or omission in Safe Browsing when processing crafted web content. A remote attacker can trick the victim into visiting a crafted website to cause information loss.


112) Use-after-free (CVE-ID: CVE-2026-87533)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within DevTools in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


113) Improper Enforcement of Behavioral Workflow (CVE-ID: CVE-2026-87532)

CWE-ID: CWE-841 - Improper Enforcement of Behavioral Workflow

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to affect Safebrowsing functionality.

The vulnerability exists due to improper state validation in Safebrowsing when processing user-initiated browsing activity. A remote attacker can induce a victim to interact with crafted web content to affect Safebrowsing functionality.


114) Information disclosure (CVE-ID: CVE-2026-87531)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in CORS in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


115) Insecure DLL loading (CVE-ID: CVE-2026-87530)

CWE-ID: CWE-427 - Uncontrolled Search Path Element

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to an uncontrolled search path element in CredentialProvider when resolving files through an uncontrolled search path. A remote attacker can cause a malicious file to be loaded to execute arbitrary code.

User interaction is required.


116) Numeric Truncation Error (CVE-ID: CVE-2026-87529)

CWE-ID: CWE-197 - Numeric Truncation Error

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger an incorrect numeric conversion during media processing.

The vulnerability exists due to numeric truncation in the Media component when processing media content. A remote attacker can induce the victim to process crafted media content to trigger an incorrect numeric conversion during media processing.


117) Type Confusion (CVE-ID: CVE-2026-87528)

CWE-ID: CWE-843 - Type confusion

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a type confusion error within the Rust component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a type confusion error and gain access to sensitive information.


118) Buffer overflow (CVE-ID: CVE-2026-87527)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a boundary error in WebGL in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger a buffer overflow and execute arbitrary code on the system.


119) Use-after-free (CVE-ID: CVE-2026-87526)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within Passwords in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


120) Out-of-bounds read (CVE-ID: CVE-2026-87525)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the Chromoting component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.


121) Use-after-free (CVE-ID: CVE-2026-87524)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Core component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


122) Race condition (CVE-ID: CVE-2026-87523)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a race condition in in DataTransfer in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and crash the browser.


123) Information disclosure (CVE-ID: CVE-2026-87521)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in WebMCP in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


124) Incorrect authorization (CVE-ID: CVE-2026-87519)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access protected Safe Browsing functionality.

The vulnerability exists due to incorrect authorization in Safe Browsing when using the Safe Browsing feature. A remote attacker can exploit the authorization flaw to access protected Safe Browsing functionality.

User interaction is required.


125) Observable discrepancy (CVE-ID: CVE-2026-87516)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an observable discrepancy in Navigation when handling navigation requests. A remote attacker can trick the victim into navigating to crafted content to disclose sensitive information.


126) Incorrect authorization (CVE-ID: CVE-2026-87515)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access resources without authorization.

The vulnerability exists due to incorrect authorization in FileAPI when handling FileAPI operations. A remote attacker can exploit the authorization flaw to access resources without authorization.

User interaction is required.


127) Use-after-free (CVE-ID: CVE-2026-87514)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Views component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


128) Missing Authorization (CVE-ID: CVE-2026-87513)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization.

The vulnerability exists due to missing authorization in ControlledFrame when processing ControlledFrame operations. A remote attacker can perform ControlledFrame operations to bypass authorization.

User interaction is required.


129) Use-after-free (CVE-ID: CVE-2026-87512)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the ANGLE component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


130) Missing Authorization (CVE-ID: CVE-2026-87511)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access DevTools functionality without authorization.

The vulnerability exists due to missing authorization in DevTools when accessing DevTools functionality. A remote attacker can access DevTools functionality without authorization to access DevTools functionality without authorization.


131) Input validation error (CVE-ID: CVE-2026-87510)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to insufficient validation of user-supplied input in FileAPI in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


132) Incorrect authorization (CVE-ID: CVE-2026-87509)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization restrictions.

The vulnerability exists due to incorrect authorization in the Updater when handling update operations. A remote attacker can exploit the authorization flaw to bypass authorization restrictions.


133) Incorrect authorization (CVE-ID: CVE-2026-87508)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization controls.

The vulnerability exists due to incorrect authorization in Loader when loading content. A remote attacker can cause the browser to load crafted content to bypass authorization controls.

User interaction is required.


134) Spoofing attack (CVE-ID: CVE-2026-87507)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent download-related information.

The vulnerability exists due to improper presentation of critical information in Downloads when displaying download-related information. A remote attacker can cause download-related information to be misrepresented to misrepresent download-related information.

User interaction is required.


135) Improper privilege management (CVE-ID: CVE-2026-87506)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper privilege management in WebUI when processing user-initiated WebUI interactions. A remote attacker can cause the victim to interact with WebUI content to escalate privileges.

User interaction is required.


136) Incorrect authorization (CVE-ID: CVE-2026-87505)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization checks.

The vulnerability exists due to incorrect authorization in FileSystem when processing user-initiated filesystem operations. A remote attacker can induce a victim to interact with web content that invokes filesystem operations to bypass authorization checks.


137) Use-after-free (CVE-ID: CVE-2026-87504)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within Core in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


138) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-87502)

CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause the browser to perform unauthorized actions.

The vulnerability exists due to a confused deputy condition in the Fullscreen feature when handling fullscreen requests. A remote attacker can trick a victim into interacting with fullscreen content to cause the browser to perform unauthorized actions.


139) Spoofing attack (CVE-ID: CVE-2026-87501)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause UI misrepresentation.

The vulnerability exists due to UI misrepresentation in the Passwords feature when handling user interaction. A remote attacker can exploit the issue to cause UI misrepresentation.


140) Improper Validation of Array Index (CVE-ID: CVE-2026-87500)

CWE-ID: CWE-129 - Improper Validation of Array Index

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause an unspecified security impact.

The vulnerability exists due to improper validation of an array index in ANGLE when processing a crafted array index. A remote attacker can provide a crafted array index to cause an unspecified security impact.

User interaction is required.


141) Improper Authorization (CVE-ID: CVE-2026-87499)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to incorrect authorization in Network in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.


142) Missing Authorization (CVE-ID: CVE-2026-87498)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access WebUI functionality without authorization.

The vulnerability exists due to missing authorization in WebUI when accessing WebUI functionality. A remote attacker can access WebUI functionality without authorization to access WebUI functionality without authorization.


143) Use of uninitialized resource (CVE-ID: CVE-2026-87497)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to use of an uninitialized resource in Codecs when processing media content. A remote attacker can cause the browser to process media content to cause a denial of service.

User interaction is required.


144) Spoofing attack (CVE-ID: CVE-2026-87496)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to mislead users.

The vulnerability exists due to UI misrepresentation in the Browser component when displaying browser UI. A remote attacker can cause browser UI to be misrepresented to mislead users.


145) Information disclosure (CVE-ID: CVE-2026-87495)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in Scroll in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


146) Use-after-free (CVE-ID: CVE-2026-87494)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within Browser in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


147) Missing Authorization (CVE-ID: CVE-2026-87493)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized filesystem operations.

The vulnerability exists due to missing authorization in FileSystem when processing crafted web content. A remote attacker can provide crafted web content to perform unauthorized filesystem operations.

User interaction is required.


148) Improper Authorization (CVE-ID: CVE-2026-87492)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to incorrect authorization in DevTools in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.


149) Information disclosure (CVE-ID: CVE-2026-87490)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an unspecified flaw in the Transactions Platform when a victim interacts with content. A remote attacker can cause a victim to interact with content to disclose sensitive information.


150) Buffer overflow (CVE-ID: CVE-2026-87489)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger memory corruption.

The vulnerability exists due to memory corruption in V8 when processing web content. A remote attacker can induce a victim to interact with web content to trigger memory corruption.

User interaction is required.


151) Missing Authorization (CVE-ID: CVE-2026-87487)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access FileSystem resources without authorization.

The vulnerability exists due to missing authorization in FileSystem when accessing FileSystem resources. A remote attacker can access FileSystem resources without authorization to access FileSystem resources without authorization.

User interaction is required.


152) Incorrect authorization (CVE-ID: CVE-2026-87485)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access cross-origin resources.

The vulnerability exists due to incorrect authorization in CORS when processing cross-origin requests. A remote attacker can trick the victim into visiting crafted web content to access cross-origin resources.


153) Spoofing attack (CVE-ID: CVE-2026-87484)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to spoof user interface elements.

The vulnerability exists due to UI misrepresentation in Geometry when rendering crafted web content. A remote attacker can cause crafted web content to be rendered to spoof user interface elements.

User interaction is required to view the crafted web content.


154) Use-after-free (CVE-ID: CVE-2026-87480)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Printing component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


155) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2026-87479)

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient policy enforcement in Extensions in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and gain access to sensitive information.


156) Observable discrepancy (CVE-ID: CVE-2026-87478)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an observable discrepancy in Autofill when processing autofill data. A remote attacker can interact with Autofill to disclose sensitive information.

User interaction is required.


157) Information disclosure (CVE-ID: CVE-2026-87477)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an unspecified information disclosure flaw in Chrome Core when a user interacts with content processed by Chrome. A remote attacker can cause a user to interact with content processed by Chrome to disclose sensitive information.


158) Incorrect authorization (CVE-ID: CVE-2026-87476)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization controls.

The vulnerability exists due to incorrect authorization in Loader when performing authorization checks. A remote attacker can exploit the authorization flaw to bypass authorization controls.


159) Missing Authorization (CVE-ID: CVE-2026-87475)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to missing authorization in Omnibox when processing omnibox input. A remote attacker can cause input to be processed without required authorization checks to perform unauthorized actions.

User interaction is required.


160) Use-after-free (CVE-ID: CVE-2026-87474)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Payments component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


161) Incorrect authorization (CVE-ID: CVE-2026-87473)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access resources without authorization.

The vulnerability exists due to improper authorization in FileHandling when processing content after user interaction. A remote attacker can induce a victim to interact with content to access resources without authorization.


162) Input validation error (CVE-ID: CVE-2026-87472)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to insufficient validation of user-supplied input in FedCM in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


163) Incorrect authorization (CVE-ID: CVE-2026-87471)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization restrictions.

The vulnerability exists due to incorrect authorization in ServiceWorker when processing crafted web content. A remote attacker can trick the victim into interacting with crafted web content to bypass authorization restrictions.


164) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-87470)

CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger an unspecified impact.

The vulnerability exists due to improper quantity validation in Tint when processing input. A remote attacker can provide input containing an improperly validated quantity to trigger an unspecified impact.


165) Input validation error (CVE-ID: CVE-2026-87469)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a low-severity security impact.

The vulnerability exists due to improper input validation in Extensions when processing input. A remote attacker can provide specially crafted input to cause a low-severity security impact.


166) Incorrect authorization (CVE-ID: CVE-2026-87468)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization restrictions.

The vulnerability exists due to incorrect authorization in the Isolated component when processing crafted web content. A remote attacker can trick a victim into interacting with crafted web content to bypass authorization restrictions.


167) Race condition (CVE-ID: CVE-2026-87467)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a race condition in Updater in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and execute arbitrary code on the target system.


168) Incorrect authorization (CVE-ID: CVE-2026-87466)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in Workers when processing crafted web content. A remote attacker can trick a victim into interacting with crafted web content to perform unauthorized actions.


169) Incorrect authorization (CVE-ID: CVE-2026-87465)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in Downloads when handling downloads. A remote attacker can exploit the authorization flaw to perform unauthorized actions.


170) Incorrect authorization (CVE-ID: CVE-2026-87463)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization controls.

The vulnerability exists due to incorrect authorization in Certificate when handling certificate-related operations. A remote attacker can exploit the issue to bypass authorization controls.

User interaction is required.


171) Spoofing attack (CVE-ID: CVE-2026-87462)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent FedCM user interface elements.

The vulnerability exists due to UI misrepresentation in FedCM when rendering FedCM user interface elements. A remote attacker can induce a victim to interact with misleading FedCM user interface elements to misrepresent FedCM user interface elements.

User interaction is required.


172) Information disclosure (CVE-ID: CVE-2026-87461)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an unspecified information disclosure flaw in Core when processing content after user interaction. A remote attacker can cause a victim to interact with crafted content to disclose sensitive information.


173) Use-after-free (CVE-ID: CVE-2026-87460)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Platform component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


174) Observable discrepancy (CVE-ID: CVE-2026-87459)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to obtain information.

The vulnerability exists due to an observable discrepancy in Select when interacting with Select. A remote attacker can trigger the observable discrepancy to obtain information.


175) Spoofing attack (CVE-ID: CVE-2026-87458)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent user interface elements.

The vulnerability exists due to UI misrepresentation in Geometry when rendering content. A remote attacker can exploit the UI misrepresentation to misrepresent user interface elements.

User interaction is required.


176) Race condition (CVE-ID: CVE-2026-87457)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a race condition in in Updater in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and crash the browser.


177) Use of uninitialized resource (CVE-ID: CVE-2026-87456)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger an unspecified impact.

The vulnerability exists due to use of an uninitialized resource in the Media component when processing media content. A remote attacker can interact with the Media component to trigger an unspecified impact.


178) Use-after-free (CVE-ID: CVE-2026-87455)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within Aura in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


179) Information disclosure (CVE-ID: CVE-2026-87454)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in Enterprise in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


180) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-87453)

CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to a confused deputy weakness in BackgroundFetch when handling web content. A remote attacker can cause BackgroundFetch to act on their behalf to perform unauthorized actions.


181) Incorrect authorization (CVE-ID: CVE-2026-87452)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in the GPU component when processing crafted web content. A remote attacker can cause a victim to interact with crafted web content to perform unauthorized actions.


182) Information disclosure (CVE-ID: CVE-2026-87451)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in Downloads in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


183) Incorrect authorization (CVE-ID: CVE-2026-87450)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in Permissions when handling permission requests. A remote attacker can exploit the authorization flaw to perform unauthorized actions.


184) Cross-site request forgery (CVE-ID: CVE-2026-87449)

CWE-ID: CWE-352 - Cross-Site Request Forgery (CSRF)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform cross-site request forgery.

The vulnerability exists due to cross-site request forgery in DeviceBoundSessionCredentials when handling cross-site requests. A remote attacker can send a crafted cross-site request to perform cross-site request forgery.


185) Use-after-free (CVE-ID: CVE-2026-87448)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to use-after-free error in DevTools in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


186) Improper Authorization (CVE-ID: CVE-2026-87447)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to incorrect authorization in Network in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.


187) Incomplete cleanup (CVE-ID: CVE-2026-87446)

CWE-ID: CWE-459 - Incomplete cleanup

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to incomplete cleanup in Extensions in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.


188) Spoofing attack (CVE-ID: CVE-2026-87445)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent the user interface.

The vulnerability exists due to user interface misrepresentation in the Session component when interacting with the Session component. A remote attacker can trigger the UI misrepresentation to misrepresent the user interface.


189) Buffer overflow (CVE-ID: CVE-2026-87444)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a boundary error in Codecs in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger a buffer overflow and execute arbitrary code on the system.


190) Missing Authorization (CVE-ID: CVE-2026-87443)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access unauthorized resources.

The vulnerability exists due to missing authorization in Actor when processing crafted web content. A remote attacker can trick a victim into interacting with crafted web content to access unauthorized resources.


191) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-87442)

CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to a confused deputy issue in Prerender when handling crafted web content. A remote attacker can trick a victim into interacting with crafted web content to perform unauthorized actions.


192) Missing Authorization (CVE-ID: CVE-2026-87441)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized download-related actions.

The vulnerability exists due to missing authorization in Downloads when handling download-related actions. A remote attacker can invoke download-related functionality without required authorization to perform unauthorized download-related actions.


193) Out-of-bounds read (CVE-ID: CVE-2026-87440)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the Media component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.


194) Information disclosure (CVE-ID: CVE-2026-87439)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in ServiceWorker in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


195) Information disclosure (CVE-ID: CVE-2026-87437)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an unspecified flaw in Frames when handling frames. A remote attacker can induce a victim to interact with web content to disclose sensitive information.


196) Incomplete cleanup (CVE-ID: CVE-2026-87436)

CWE-ID: CWE-459 - Incomplete cleanup

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to incomplete cleanup in Browser in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.


197) Information disclosure (CVE-ID: CVE-2026-87435)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in ControlledFrame in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


198) Missing Authorization (CVE-ID: CVE-2026-87434)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to missing authorization in CORS when handling cross-origin requests. A remote attacker can trick a victim into visiting a crafted website to disclose sensitive information.

User interaction is required.


Remediation

Install update from vendor's website.

References