SB2026091874 - Debian update for chromium



SB2026091874 - Debian update for chromium

Published: September 18, 2026

Security Bulletin ID SB2026091874
CSH Severity
Critical
Patch available
YES
Number of vulnerabilities 272
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Critical 0% High 22% Medium 21% Low 56%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 272 vulnerabilities.


1) Missing Authorization (CVE-ID: CVE-2026-87429)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to missing authorization in ServiceWorker when handling service worker operations. A remote attacker can induce a victim to interact with browser content to perform unauthorized actions.


2) Buffer overflow (CVE-ID: CVE-2026-87430)

CWE-ID: CWE-120 - Buffer overflow

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a buffer overflow in WebRTC when processing web content. A remote attacker can cause WebRTC to process crafted web content to cause a denial of service.

User interaction is required.


3) Missing Authorization (CVE-ID: CVE-2026-87431)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to missing authorization in Extensions when processing user interaction. A remote attacker can induce a victim to interact with content to perform unauthorized actions.


4) Incorrect authorization (CVE-ID: CVE-2026-87432)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization restrictions.

The vulnerability exists due to incorrect authorization in Navigation when handling navigation requests. A remote attacker can initiate a navigation request to bypass authorization restrictions.


5) Race condition (CVE-ID: CVE-2026-87433)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger a race condition.

The vulnerability exists due to a race condition in FileAPI when performing FileAPI operations. A remote attacker can perform FileAPI operations to trigger a race condition.


6) Missing Authorization (CVE-ID: CVE-2026-87434)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to missing authorization in CORS when handling cross-origin requests. A remote attacker can trick a victim into visiting a crafted website to disclose sensitive information.

User interaction is required.


7) Information disclosure (CVE-ID: CVE-2026-87435)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in ControlledFrame in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


8) Incomplete cleanup (CVE-ID: CVE-2026-87436)

CWE-ID: CWE-459 - Incomplete cleanup

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to incomplete cleanup in Browser in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.


9) Information disclosure (CVE-ID: CVE-2026-87437)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an unspecified flaw in Frames when handling frames. A remote attacker can induce a victim to interact with web content to disclose sensitive information.


10) Out-of-bounds write (CVE-ID: CVE-2026-87438)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted HTML content in WebGL. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.


11) Information disclosure (CVE-ID: CVE-2026-87439)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in ServiceWorker in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


12) Out-of-bounds read (CVE-ID: CVE-2026-87440)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the Media component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.


13) Missing Authorization (CVE-ID: CVE-2026-87441)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized download-related actions.

The vulnerability exists due to missing authorization in Downloads when handling download-related actions. A remote attacker can invoke download-related functionality without required authorization to perform unauthorized download-related actions.


14) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-87442)

CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to a confused deputy issue in Prerender when handling crafted web content. A remote attacker can trick a victim into interacting with crafted web content to perform unauthorized actions.


15) Missing Authorization (CVE-ID: CVE-2026-87443)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access unauthorized resources.

The vulnerability exists due to missing authorization in Actor when processing crafted web content. A remote attacker can trick a victim into interacting with crafted web content to access unauthorized resources.


16) Buffer overflow (CVE-ID: CVE-2026-87444)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a boundary error in Codecs in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger a buffer overflow and execute arbitrary code on the system.


17) Spoofing attack (CVE-ID: CVE-2026-87445)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent the user interface.

The vulnerability exists due to user interface misrepresentation in the Session component when interacting with the Session component. A remote attacker can trigger the UI misrepresentation to misrepresent the user interface.


18) Incomplete cleanup (CVE-ID: CVE-2026-87446)

CWE-ID: CWE-459 - Incomplete cleanup

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to incomplete cleanup in Extensions in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.


19) Improper Authorization (CVE-ID: CVE-2026-87447)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to incorrect authorization in Network in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.


20) Use-after-free (CVE-ID: CVE-2026-87448)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to use-after-free error in DevTools in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


21) Cross-site request forgery (CVE-ID: CVE-2026-87449)

CWE-ID: CWE-352 - Cross-Site Request Forgery (CSRF)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform cross-site request forgery.

The vulnerability exists due to cross-site request forgery in DeviceBoundSessionCredentials when handling cross-site requests. A remote attacker can send a crafted cross-site request to perform cross-site request forgery.


22) Incorrect authorization (CVE-ID: CVE-2026-87450)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in Permissions when handling permission requests. A remote attacker can exploit the authorization flaw to perform unauthorized actions.


23) Information disclosure (CVE-ID: CVE-2026-87451)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in Downloads in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


24) Incorrect authorization (CVE-ID: CVE-2026-87452)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in the GPU component when processing crafted web content. A remote attacker can cause a victim to interact with crafted web content to perform unauthorized actions.


25) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-87453)

CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to a confused deputy weakness in BackgroundFetch when handling web content. A remote attacker can cause BackgroundFetch to act on their behalf to perform unauthorized actions.


26) Information disclosure (CVE-ID: CVE-2026-87454)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in Enterprise in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


27) Use-after-free (CVE-ID: CVE-2026-87455)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within Aura in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


28) Use of uninitialized resource (CVE-ID: CVE-2026-87456)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger an unspecified impact.

The vulnerability exists due to use of an uninitialized resource in the Media component when processing media content. A remote attacker can interact with the Media component to trigger an unspecified impact.


29) Race condition (CVE-ID: CVE-2026-87457)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a race condition in in Updater in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and crash the browser.


30) Spoofing attack (CVE-ID: CVE-2026-87458)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent user interface elements.

The vulnerability exists due to UI misrepresentation in Geometry when rendering content. A remote attacker can exploit the UI misrepresentation to misrepresent user interface elements.

User interaction is required.


31) Observable discrepancy (CVE-ID: CVE-2026-87459)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to obtain information.

The vulnerability exists due to an observable discrepancy in Select when interacting with Select. A remote attacker can trigger the observable discrepancy to obtain information.


32) Use-after-free (CVE-ID: CVE-2026-87460)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Platform component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


33) Information disclosure (CVE-ID: CVE-2026-87461)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an unspecified information disclosure flaw in Core when processing content after user interaction. A remote attacker can cause a victim to interact with crafted content to disclose sensitive information.


34) Spoofing attack (CVE-ID: CVE-2026-87462)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent FedCM user interface elements.

The vulnerability exists due to UI misrepresentation in FedCM when rendering FedCM user interface elements. A remote attacker can induce a victim to interact with misleading FedCM user interface elements to misrepresent FedCM user interface elements.

User interaction is required.


35) Incorrect authorization (CVE-ID: CVE-2026-87463)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization controls.

The vulnerability exists due to incorrect authorization in Certificate when handling certificate-related operations. A remote attacker can exploit the issue to bypass authorization controls.

User interaction is required.


36) Use-after-free (CVE-ID: CVE-2026-87464)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the WebGL component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


37) Incorrect authorization (CVE-ID: CVE-2026-87465)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in Downloads when handling downloads. A remote attacker can exploit the authorization flaw to perform unauthorized actions.


38) Incorrect authorization (CVE-ID: CVE-2026-87466)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in Workers when processing crafted web content. A remote attacker can trick a victim into interacting with crafted web content to perform unauthorized actions.


39) Race condition (CVE-ID: CVE-2026-87467)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a race condition in Updater in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and execute arbitrary code on the target system.


40) Incorrect authorization (CVE-ID: CVE-2026-87468)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization restrictions.

The vulnerability exists due to incorrect authorization in the Isolated component when processing crafted web content. A remote attacker can trick a victim into interacting with crafted web content to bypass authorization restrictions.


41) Input validation error (CVE-ID: CVE-2026-87469)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a low-severity security impact.

The vulnerability exists due to improper input validation in Extensions when processing input. A remote attacker can provide specially crafted input to cause a low-severity security impact.


42) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-87470)

CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger an unspecified impact.

The vulnerability exists due to improper quantity validation in Tint when processing input. A remote attacker can provide input containing an improperly validated quantity to trigger an unspecified impact.


43) Incorrect authorization (CVE-ID: CVE-2026-87471)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization restrictions.

The vulnerability exists due to incorrect authorization in ServiceWorker when processing crafted web content. A remote attacker can trick the victim into interacting with crafted web content to bypass authorization restrictions.


44) Input validation error (CVE-ID: CVE-2026-87472)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to insufficient validation of user-supplied input in FedCM in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


45) Incorrect authorization (CVE-ID: CVE-2026-87473)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access resources without authorization.

The vulnerability exists due to improper authorization in FileHandling when processing content after user interaction. A remote attacker can induce a victim to interact with content to access resources without authorization.


46) Use-after-free (CVE-ID: CVE-2026-87474)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Payments component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


47) Missing Authorization (CVE-ID: CVE-2026-87475)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to missing authorization in Omnibox when processing omnibox input. A remote attacker can cause input to be processed without required authorization checks to perform unauthorized actions.

User interaction is required.


48) Incorrect authorization (CVE-ID: CVE-2026-87476)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization controls.

The vulnerability exists due to incorrect authorization in Loader when performing authorization checks. A remote attacker can exploit the authorization flaw to bypass authorization controls.


49) Information disclosure (CVE-ID: CVE-2026-87477)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an unspecified information disclosure flaw in Chrome Core when a user interacts with content processed by Chrome. A remote attacker can cause a user to interact with content processed by Chrome to disclose sensitive information.


50) Observable discrepancy (CVE-ID: CVE-2026-87478)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an observable discrepancy in Autofill when processing autofill data. A remote attacker can interact with Autofill to disclose sensitive information.

User interaction is required.


51) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2026-87479)

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient policy enforcement in Extensions in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and gain access to sensitive information.


52) Use-after-free (CVE-ID: CVE-2026-87480)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Printing component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


53) Incorrect authorization (CVE-ID: CVE-2026-87481)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access resources without authorization.

The vulnerability exists due to incorrect authorization in WebView when processing crafted web content. A remote attacker can cause WebView to process crafted web content to access resources without authorization.

User interaction is required.


54) Cleartext transmission of sensitive information (CVE-ID: CVE-2026-87482)

CWE-ID: CWE-319 - Cleartext Transmission of Sensitive Information

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to cleartext transmission of sensitive data in HttpsUpgrades when handling sensitive data. A remote attacker can cause HttpsUpgrades to transmit sensitive data in cleartext to disclose sensitive information.


55) Incorrect authorization (CVE-ID: CVE-2026-87483)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization controls.

The vulnerability exists due to incorrect authorization in Browser when processing content. A remote attacker can exploit the authorization flaw to bypass authorization controls.


56) Spoofing attack (CVE-ID: CVE-2026-87484)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to spoof user interface elements.

The vulnerability exists due to UI misrepresentation in Geometry when rendering crafted web content. A remote attacker can cause crafted web content to be rendered to spoof user interface elements.

User interaction is required to view the crafted web content.


57) Incorrect authorization (CVE-ID: CVE-2026-87485)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access cross-origin resources.

The vulnerability exists due to incorrect authorization in CORS when processing cross-origin requests. A remote attacker can trick the victim into visiting crafted web content to access cross-origin resources.


58) Improper Restriction of Rendered UI Layers or Frames (CVE-ID: CVE-2026-87486)

CWE-ID: CWE-1021 - Improper Restriction of Rendered UI Layers or Frames

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform clickjacking attacks.

The vulnerability exists due to clickjacking in TrustedWebActivities when rendering web content. A remote attacker can trick a victim into interacting with a crafted interface to perform clickjacking attacks.

User interaction is required.


59) Missing Authorization (CVE-ID: CVE-2026-87487)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access FileSystem resources without authorization.

The vulnerability exists due to missing authorization in FileSystem when accessing FileSystem resources. A remote attacker can access FileSystem resources without authorization to access FileSystem resources without authorization.

User interaction is required.


60) Use-after-free (CVE-ID: CVE-2026-87488)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the WebGL component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


61) Buffer overflow (CVE-ID: CVE-2026-87489)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger memory corruption.

The vulnerability exists due to memory corruption in V8 when processing web content. A remote attacker can induce a victim to interact with web content to trigger memory corruption.

User interaction is required.


62) Information disclosure (CVE-ID: CVE-2026-87490)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an unspecified flaw in the Transactions Platform when a victim interacts with content. A remote attacker can cause a victim to interact with content to disclose sensitive information.


63) Out-of-bounds write (CVE-ID: CVE-2026-87491) Exploited

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted HTML content in V8. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.

Note, the vulnerability is being actively exploited in the wild.


64) Improper Authorization (CVE-ID: CVE-2026-87492)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to incorrect authorization in DevTools in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.


65) Missing Authorization (CVE-ID: CVE-2026-87493)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized filesystem operations.

The vulnerability exists due to missing authorization in FileSystem when processing crafted web content. A remote attacker can provide crafted web content to perform unauthorized filesystem operations.

User interaction is required.


66) Use-after-free (CVE-ID: CVE-2026-87494)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within Browser in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


67) Information disclosure (CVE-ID: CVE-2026-87495)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in Scroll in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


68) Spoofing attack (CVE-ID: CVE-2026-87496)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to mislead users.

The vulnerability exists due to UI misrepresentation in the Browser component when displaying browser UI. A remote attacker can cause browser UI to be misrepresented to mislead users.


69) Use of uninitialized resource (CVE-ID: CVE-2026-87497)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to use of an uninitialized resource in Codecs when processing media content. A remote attacker can cause the browser to process media content to cause a denial of service.

User interaction is required.


70) Missing Authorization (CVE-ID: CVE-2026-87498)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access WebUI functionality without authorization.

The vulnerability exists due to missing authorization in WebUI when accessing WebUI functionality. A remote attacker can access WebUI functionality without authorization to access WebUI functionality without authorization.


71) Improper Authorization (CVE-ID: CVE-2026-87499)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to incorrect authorization in Network in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.


72) Improper Validation of Array Index (CVE-ID: CVE-2026-87500)

CWE-ID: CWE-129 - Improper Validation of Array Index

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause an unspecified security impact.

The vulnerability exists due to improper validation of an array index in ANGLE when processing a crafted array index. A remote attacker can provide a crafted array index to cause an unspecified security impact.

User interaction is required.


73) Spoofing attack (CVE-ID: CVE-2026-87501)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause UI misrepresentation.

The vulnerability exists due to UI misrepresentation in the Passwords feature when handling user interaction. A remote attacker can exploit the issue to cause UI misrepresentation.


74) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-87502)

CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause the browser to perform unauthorized actions.

The vulnerability exists due to a confused deputy condition in the Fullscreen feature when handling fullscreen requests. A remote attacker can trick a victim into interacting with fullscreen content to cause the browser to perform unauthorized actions.


75) Improperly implemented security check for standard (CVE-ID: CVE-2026-87503)

CWE-ID: CWE-358 - Improperly Implemented Security Check for Standard

CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to incorrect implementation in Downloads in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.


76) Use-after-free (CVE-ID: CVE-2026-87504)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within Core in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


77) Incorrect authorization (CVE-ID: CVE-2026-87505)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization checks.

The vulnerability exists due to incorrect authorization in FileSystem when processing user-initiated filesystem operations. A remote attacker can induce a victim to interact with web content that invokes filesystem operations to bypass authorization checks.


78) Improper privilege management (CVE-ID: CVE-2026-87506)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper privilege management in WebUI when processing user-initiated WebUI interactions. A remote attacker can cause the victim to interact with WebUI content to escalate privileges.

User interaction is required.


79) Spoofing attack (CVE-ID: CVE-2026-87507)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent download-related information.

The vulnerability exists due to improper presentation of critical information in Downloads when displaying download-related information. A remote attacker can cause download-related information to be misrepresented to misrepresent download-related information.

User interaction is required.


80) Incorrect authorization (CVE-ID: CVE-2026-87508)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization controls.

The vulnerability exists due to incorrect authorization in Loader when loading content. A remote attacker can cause the browser to load crafted content to bypass authorization controls.

User interaction is required.


81) Incorrect authorization (CVE-ID: CVE-2026-87509)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization restrictions.

The vulnerability exists due to incorrect authorization in the Updater when handling update operations. A remote attacker can exploit the authorization flaw to bypass authorization restrictions.


82) Input validation error (CVE-ID: CVE-2026-87510)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to insufficient validation of user-supplied input in FileAPI in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


83) Missing Authorization (CVE-ID: CVE-2026-87511)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access DevTools functionality without authorization.

The vulnerability exists due to missing authorization in DevTools when accessing DevTools functionality. A remote attacker can access DevTools functionality without authorization to access DevTools functionality without authorization.


84) Use-after-free (CVE-ID: CVE-2026-87512)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the ANGLE component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


85) Missing Authorization (CVE-ID: CVE-2026-87513)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization.

The vulnerability exists due to missing authorization in ControlledFrame when processing ControlledFrame operations. A remote attacker can perform ControlledFrame operations to bypass authorization.

User interaction is required.


86) Use-after-free (CVE-ID: CVE-2026-87514)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Views component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


87) Incorrect authorization (CVE-ID: CVE-2026-87515)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access resources without authorization.

The vulnerability exists due to incorrect authorization in FileAPI when handling FileAPI operations. A remote attacker can exploit the authorization flaw to access resources without authorization.

User interaction is required.


88) Observable discrepancy (CVE-ID: CVE-2026-87516)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an observable discrepancy in Navigation when handling navigation requests. A remote attacker can trick the victim into navigating to crafted content to disclose sensitive information.


89) Race condition (CVE-ID: CVE-2026-87517)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a race condition in Mobile in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and execute arbitrary code on the target system.


90) Observable discrepancy (CVE-ID: CVE-2026-87518)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to obtain information about Safe Browsing behavior.

The vulnerability exists due to an observable discrepancy in Safe Browsing when handling Safe Browsing checks. A remote attacker can trigger the discrepancy to obtain information about Safe Browsing behavior.

User interaction is required.


91) Incorrect authorization (CVE-ID: CVE-2026-87519)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access protected Safe Browsing functionality.

The vulnerability exists due to incorrect authorization in Safe Browsing when using the Safe Browsing feature. A remote attacker can exploit the authorization flaw to access protected Safe Browsing functionality.

User interaction is required.


92) Use-after-free (CVE-ID: CVE-2026-87520)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Dawn component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


93) Information disclosure (CVE-ID: CVE-2026-87521)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in WebMCP in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


94) Missing Authorization (CVE-ID: CVE-2026-87522)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to missing authorization in WebView when handling web content. A remote attacker can access functionality without authorization to perform unauthorized actions.


95) Race condition (CVE-ID: CVE-2026-87523)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a race condition in in DataTransfer in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and crash the browser.


96) Use-after-free (CVE-ID: CVE-2026-87524)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Core component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


97) Out-of-bounds read (CVE-ID: CVE-2026-87525)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the Chromoting component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.


98) Use-after-free (CVE-ID: CVE-2026-87526)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within Passwords in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


99) Buffer overflow (CVE-ID: CVE-2026-87527)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a boundary error in WebGL in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger a buffer overflow and execute arbitrary code on the system.


100) Type Confusion (CVE-ID: CVE-2026-87528)

CWE-ID: CWE-843 - Type confusion

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a type confusion error within the Rust component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a type confusion error and gain access to sensitive information.


101) Numeric Truncation Error (CVE-ID: CVE-2026-87529)

CWE-ID: CWE-197 - Numeric Truncation Error

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger an incorrect numeric conversion during media processing.

The vulnerability exists due to numeric truncation in the Media component when processing media content. A remote attacker can induce the victim to process crafted media content to trigger an incorrect numeric conversion during media processing.


102) Insecure DLL loading (CVE-ID: CVE-2026-87530)

CWE-ID: CWE-427 - Uncontrolled Search Path Element

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to an uncontrolled search path element in CredentialProvider when resolving files through an uncontrolled search path. A remote attacker can cause a malicious file to be loaded to execute arbitrary code.

User interaction is required.


103) Information disclosure (CVE-ID: CVE-2026-87531)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in CORS in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


104) Improper Enforcement of Behavioral Workflow (CVE-ID: CVE-2026-87532)

CWE-ID: CWE-841 - Improper Enforcement of Behavioral Workflow

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to affect Safebrowsing functionality.

The vulnerability exists due to improper state validation in Safebrowsing when processing user-initiated browsing activity. A remote attacker can induce a victim to interact with crafted web content to affect Safebrowsing functionality.


105) Use-after-free (CVE-ID: CVE-2026-87533)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within DevTools in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


106) Missing Authorization (CVE-ID: CVE-2026-87534)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to missing authorization in WebView when processing web content. A remote attacker can cause a victim to interact with crafted web content to perform unauthorized actions.

User interaction is required.


107) Information Loss or Omission (CVE-ID: CVE-2026-87535)

CWE-ID: CWE-221 - Information Loss or Omission

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause information loss.

The vulnerability exists due to information loss or omission in Safe Browsing when processing crafted web content. A remote attacker can trick the victim into visiting a crafted website to cause information loss.


108) Use-after-free (CVE-ID: CVE-2026-87536)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the V8 component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


109) Missing Authorization (CVE-ID: CVE-2026-87537)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to missing authorization in Extensions when processing extension requests. A remote attacker can send a crafted extension request to perform unauthorized actions.

User interaction is required.


110) Improper Restriction of Rendered UI Layers or Frames (CVE-ID: CVE-2026-87538)

CWE-ID: CWE-1021 - Improper Restriction of Rendered UI Layers or Frames

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause users to perform unintended actions.

The vulnerability exists due to clickjacking in Input when rendering crafted web content. A remote attacker can trick a victim into interacting with crafted web content to cause users to perform unintended actions.


111) Observable discrepancy (CVE-ID: CVE-2026-87539)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an observable discrepancy in the Network component when processing network-related content. A remote attacker can induce user interaction with network-related content to disclose sensitive information.


112) Incorrect authorization (CVE-ID: CVE-2026-87540)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in the Isolated component when processing crafted web content. A remote attacker can trick the victim into interacting with crafted web content to perform unauthorized actions.

User interaction is required.


113) Information disclosure (CVE-ID: CVE-2026-87541)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in Navigation in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


114) Use-after-free (CVE-ID: CVE-2026-87542)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Input component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


115) Missing Authorization (CVE-ID: CVE-2026-87543)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to missing authorization in Core when a victim interacts with web content. A remote attacker can cause a victim to interact with web content to perform unauthorized actions.


116) Incorrect authorization (CVE-ID: CVE-2026-87544)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization restrictions.

The vulnerability exists due to incorrect authorization in Extensions when handling extension-related requests. A remote attacker can send a crafted extension-related request to bypass authorization restrictions.

User interaction is required.


117) Information disclosure (CVE-ID: CVE-2026-87545)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an unspecified flaw in Mobile Chrome when handling crafted content. A remote attacker can trick a victim into interacting with crafted content to disclose sensitive information.


118) Type conversion (CVE-ID: CVE-2026-87546)

CWE-ID: CWE-704 - Type conversion

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a low-severity security impact.

The vulnerability exists due to incorrect type conversion or cast in Safe Browsing when performing type conversions or casts. A remote attacker can trigger the vulnerable code path to cause a low-severity security impact.


119) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-87547)

CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access unintended files.

The vulnerability exists due to incorrect reference resolution in FileSystem when resolving crafted filesystem references. A remote attacker can supply crafted references to access unintended files.

User interaction is required.


120) Improper Enforcement of Behavioral Workflow (CVE-ID: CVE-2026-87548)

CWE-ID: CWE-841 - Improper Enforcement of Behavioral Workflow

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass intended installer state validation.

The vulnerability exists due to improper state validation in the installer when processing installer state. A remote attacker can cause the installer to accept an invalid state to bypass intended installer state validation.

User interaction is required.


121) Incomplete cleanup (CVE-ID: CVE-2026-87549)

CWE-ID: CWE-459 - Incomplete cleanup

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to incomplete cleanup in Downloads in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.


122) Improper Encoding or Escaping of Output (CVE-ID: CVE-2026-87550)

CWE-ID: CWE-116 - Improper Encoding or Escaping of Output

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to inject CSS.

The vulnerability exists due to improper encoding or escaping of output in CSS when rendering crafted CSS content. A remote attacker can provide crafted CSS content to inject CSS.


123) Improper Certificate Validation (CVE-ID: CVE-2026-87551)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass certificate validation.

The vulnerability exists due to improper certificate validation in CORS when handling CORS requests. A remote attacker can send a crafted CORS request to bypass certificate validation.


124) Missing Authorization (CVE-ID: CVE-2026-87552)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to missing authorization in TrustedWebActivities when handling TrustedWebActivities. A remote attacker can invoke a TrustedWebActivity to perform unauthorized actions.

User interaction is required.


125) Input validation error (CVE-ID: CVE-2026-87553)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to insufficient validation of user-supplied input in SiteIsolation in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


126) Race condition (CVE-ID: CVE-2026-87554)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a race condition in Chromoting in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and execute arbitrary code on the target system.


127) Use of uninitialized resource (CVE-ID: CVE-2026-87555)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger an unspecified impact.

The vulnerability exists due to use of an uninitialized resource in the GPU component when processing web content. A remote attacker can trick a victim into accessing web content to trigger an unspecified impact.

User interaction is required.


128) Missing Authorization (CVE-ID: CVE-2026-87556)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization controls.

The vulnerability exists due to missing authorization in the Browser component when processing authorization checks. A remote attacker can exploit the missing authorization to bypass authorization controls.


129) Missing Authorization (CVE-ID: CVE-2026-87557)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access local network resources without authorization.

The vulnerability exists due to missing authorization in LocalNetworkAccess when handling crafted web content. A remote attacker can induce the victim to interact with crafted web content to access local network resources without authorization.

User interaction is required.


130) Use-after-free (CVE-ID: CVE-2026-87558)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Payments component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


131) Spoofing attack (CVE-ID: CVE-2026-87559)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent the user interface.

The vulnerability exists due to UI misrepresentation in the UI when rendering web content. A remote attacker can trick the victim into interacting with misrepresented UI elements to misrepresent the user interface.


132) Missing Authorization (CVE-ID: CVE-2026-87560)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to missing authorization in the Browser component when using the browser. A remote attacker can exploit the missing authorization to perform unauthorized actions.

User interaction is required.


133) Incorrect authorization (CVE-ID: CVE-2026-87561)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in Web Authentication when processing Web Authentication requests. A remote attacker can submit a crafted Web Authentication request to perform unauthorized actions.


134) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-87562)

CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause incorrect reference resolution.

The vulnerability exists due to incorrect reference resolution in the Accessibility component when a victim interacts with web content. A remote attacker can induce a victim to interact with web content to cause incorrect reference resolution.


135) Origin validation error (CVE-ID: CVE-2026-87563)

CWE-ID: CWE-346 - Origin Validation Error

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass origin-based security restrictions.

The vulnerability exists due to improper origin validation in Paint when processing web content. A remote attacker can trick a victim into visiting a crafted website to bypass origin-based security restrictions.


136) Type Confusion (CVE-ID: CVE-2026-87564)

CWE-ID: CWE-843 - Type confusion

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a type confusion error within the V8 component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger a type confusion error and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


137) Information disclosure (CVE-ID: CVE-2026-87565)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an unspecified flaw in the Passwords component when a victim interacts with content. A remote attacker can induce a victim to interact with content to disclose sensitive information.


138) Observable discrepancy (CVE-ID: CVE-2026-87566)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an observable discrepancy in Layout when rendering crafted web content. A remote attacker can trick the victim into visiting a crafted website to disclose sensitive information.

User interaction is required.


139) Spoofing attack (CVE-ID: CVE-2026-87567)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent URL information.

The vulnerability exists due to UI misrepresentation in UrlFormatting when formatting URLs. A remote attacker can cause URL information to be misrepresented to misrepresent URL information.

User interaction is required.


140) Input validation error (CVE-ID: CVE-2026-87568)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger an unspecified security impact.

The vulnerability exists due to improper input validation in Chromium when processing input. A remote attacker can provide specially crafted input to trigger an unspecified security impact.


141) Missing Authorization (CVE-ID: CVE-2026-87569)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization.

The vulnerability exists due to missing authorization in Views when performing operations in Views. A remote attacker can trigger an operation in Views to bypass authorization.

User interaction is required.


142) Incorrect authorization (CVE-ID: CVE-2026-87570)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access resources without proper authorization.

The vulnerability exists due to incorrect authorization in SiteIsolation when processing web content. A remote attacker can cause SiteIsolation to incorrectly authorize access to resources.


143) Improper Certificate Validation (CVE-ID: CVE-2026-87571)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause Chrome to accept improperly validated certificates.

The vulnerability exists due to improper certificate validation in Loader when processing certificates. A remote attacker can provide an improperly validated certificate to cause Chrome to accept improperly validated certificates.

User interaction is required.


144) Improper Neutralization of Special Elements in Output Used by a Downstream Component (CVE-ID: CVE-2026-87572)

CWE-ID: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to inject content into DevTools.

The vulnerability exists due to improper input neutralization in DevTools when handling crafted content. A remote attacker can provide crafted content to inject content into DevTools.

User interaction is required.


145) Input validation error (CVE-ID: CVE-2026-87573)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to insufficient validation of user-supplied input in Network in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


146) Information disclosure (CVE-ID: CVE-2026-87574)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in ServiceWorker in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


147) Incorrect authorization (CVE-ID: CVE-2026-87575)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in Loader when performing authorization checks. A remote attacker can exploit the authorization flaw to perform unauthorized actions.


148) Use of uninitialized resource (CVE-ID: CVE-2026-87576)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to use of an uninitialized resource in the GPU component when processing content. A remote attacker can trigger the vulnerable GPU resource to cause a denial of service.


149) Incorrect authorization (CVE-ID: CVE-2026-87577)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access resources without proper authorization.

The vulnerability exists due to incorrect authorization in Isolated. Chrome Medium when handling crafted web content. A remote attacker can trick a victim into interacting with crafted web content to access resources without proper authorization.

User interaction is required.


150) Use-after-free (CVE-ID: CVE-2026-87578)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Receiver component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


151) Buffer overflow (CVE-ID: CVE-2026-87579)

CWE-ID: CWE-120 - Buffer overflow

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a buffer overflow in WebRTC when processing crafted WebRTC content. A remote attacker can trick the victim into processing crafted WebRTC content to cause a denial of service.


152) Incorrect authorization (CVE-ID: CVE-2026-87580)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to improper authorization in WebAppInstalls when handling web application installation requests. A remote attacker can exploit the incorrect authorization to perform unauthorized actions.

User interaction is required.


153) Use-after-free (CVE-ID: CVE-2026-87581)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Payments component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


154) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-87582)

CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to a confused deputy vulnerability in DataTransfer when handling crafted web content. A remote attacker can trick a victim into interacting with crafted web content to perform unauthorized actions.


155) Spoofing attack (CVE-ID: CVE-2026-87583)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent password-related user interface elements.

The vulnerability exists due to user interface misrepresentation in Passwords when rendering password-related user interface elements. A remote attacker can cause password-related user interface elements to be misrepresented to mislead users.

User interaction is required.


156) Incorrect authorization (CVE-ID: CVE-2026-87584)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to improper authorization in WebUI when handling WebUI requests. A remote attacker can induce a user to interact with WebUI functionality to perform unauthorized actions.

User interaction is required.


157) Double free (CVE-ID: CVE-2026-87585)

CWE-ID: CWE-415 - Double Free

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger a double-free condition.

The vulnerability exists due to a double free in PDFium when processing a PDF document. A remote attacker can trick a victim into opening a PDF document to trigger a double-free condition.


158) Out-of-bounds read (CVE-ID: CVE-2026-87586)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the ANGLE component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.


159) Use-after-free (CVE-ID: CVE-2026-87587)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the V8 component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


160) Use-after-free (CVE-ID: CVE-2026-87588)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within Chromecast in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


161) Incorrect authorization (CVE-ID: CVE-2026-87589)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in SiteIsolation when handling web content. A remote attacker can cause a victim to interact with web content to perform unauthorized actions.


162) Input validation error (CVE-ID: CVE-2026-87590)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause an unspecified security impact.

The vulnerability exists due to improper input validation in Passwords when processing input. A remote attacker can provide specially crafted input to cause an unspecified security impact.


163) Incorrect authorization (CVE-ID: CVE-2026-87591)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in Extensions when handling extension-related operations. A remote attacker can invoke extension functionality without proper authorization to perform unauthorized actions.


164) Out-of-bounds read (CVE-ID: CVE-2026-87592)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a boundary condition within the Tint component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and crash the browser.


165) Information disclosure (CVE-ID: CVE-2026-87593)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper information disclosure in the Editing component when rendering web content. A remote attacker can cause web content to be rendered to disclose sensitive information.

User interaction is required.


166) Incorrect authorization (CVE-ID: CVE-2026-87594)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in DataTransfer when handling DataTransfer operations. A remote attacker can invoke DataTransfer operations to perform unauthorized actions.


167) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2026-87595)

CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause the browser to send requests to arbitrary destinations.

The vulnerability exists due to server-side request forgery in Mobile when processing crafted content. A remote attacker can trick the victim into processing crafted content to cause the browser to send requests to arbitrary destinations.


168) Out-of-bounds read (CVE-ID: CVE-2026-87596)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the ANGLE component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.


169) Spoofing attack (CVE-ID: CVE-2026-87597)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent user interface content.

The vulnerability exists due to UI misrepresentation in CustomTabs when displaying CustomTabs content. A remote attacker can present misleading user interface content to misrepresent user interface content.

User interaction is required.


170) Incorrect authorization (CVE-ID: CVE-2026-87598)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access ServiceWorker functionality without authorization.

The vulnerability exists due to incorrect authorization in ServiceWorker when processing crafted web content. A remote attacker can induce a victim to interact with crafted web content to access ServiceWorker functionality without authorization.


171) Input validation error (CVE-ID: CVE-2026-87599)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to insufficient validation of user-supplied input in Interstitials in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


172) Input validation error (CVE-ID: CVE-2026-87600)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause an unspecified impact.

The vulnerability exists due to improper input validation in Safebrowsing when processing input. A remote attacker can provide specially crafted input to cause an unspecified impact.

User interaction is required.


173) Race condition (CVE-ID: CVE-2026-87601)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a race condition in in V8 in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and crash the browser.


174) Out-of-bounds read (CVE-ID: CVE-2026-87602)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a boundary condition within the ANGLE component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and crash the browser.


175) Missing Authorization (CVE-ID: CVE-2026-87603)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization controls for the FileSystem.

The vulnerability exists due to missing authorization checks in the FileSystem when a victim interacts with affected FileSystem functionality. A remote attacker can cause a victim to interact with the affected FileSystem functionality to bypass authorization controls for the FileSystem.

User interaction is required.


176) Out-of-bounds read (CVE-ID: CVE-2026-87604)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the ANGLE component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.


177) Missing Authorization (CVE-ID: CVE-2026-87605)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to missing authorization in the Contacts feature when processing contact-related requests. A remote attacker can interact with the Contacts feature to disclose sensitive information.


178) Missing Authorization (CVE-ID: CVE-2026-87606)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization controls.

The vulnerability exists due to missing authorization in SiteIsolation when handling site isolation operations. A remote attacker can exploit the missing authorization controls to bypass authorization controls.


179) Use-after-free (CVE-ID: CVE-2026-87607)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Device component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


180) Improper Certificate Validation (CVE-ID: CVE-2026-87608)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass certificate validation.

The vulnerability exists due to improper certificate validation in FedCM when validating certificates. A remote attacker can cause FedCM to improperly validate a certificate to bypass certificate validation.

User interaction is required.


181) Use-after-free (CVE-ID: CVE-2026-87609)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within Sharing in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


182) Incorrect authorization (CVE-ID: CVE-2026-87610)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in the Omnibox when processing Omnibox input. A remote attacker can cause a victim to interact with the Omnibox to perform unauthorized actions.


183) Missing Authorization (CVE-ID: CVE-2026-87611)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access file system resources without authorization.

The vulnerability exists due to missing authorization in the FileSystem component when a victim interacts with web content. A remote attacker can cause a victim to interact with web content to access file system resources without authorization.


184) Type Confusion (CVE-ID: CVE-2026-87612)

CWE-ID: CWE-843 - Type confusion

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a type confusion error within the V8 component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger a type confusion error and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


185) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-87613)

CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass security restrictions.

The vulnerability exists due to incorrect reference resolution in Extensions when processing extension references. A remote attacker can provide crafted extension references to bypass security restrictions.

User interaction is required.


186) Incorrect authorization (CVE-ID: CVE-2026-87614)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization controls.

The vulnerability exists due to incorrect authorization in ServiceWorker when handling ServiceWorker operations. A remote attacker can exploit the incorrect authorization to bypass authorization controls.


187) Race condition (CVE-ID: CVE-2026-87615)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger a race condition in payment processing.

The vulnerability exists due to a race condition in Payments when using payment-related functionality. A remote attacker can interact with the Payments feature to trigger a race condition in payment processing.

User interaction is required.


188) Improper initialization (CVE-ID: CVE-2026-87616)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to improper initialization in Views in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


189) Use-after-free (CVE-ID: CVE-2026-87617)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to use-after-free error in DevTools in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


190) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-87618)

CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause incorrect reference resolution.

The vulnerability exists due to incorrect reference resolution in Storage when resolving references. A remote attacker can cause a reference to be resolved incorrectly to cause incorrect reference resolution.


191) Observable discrepancy (CVE-ID: CVE-2026-87619)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an observable discrepancy in Prefetch when prefetching content. A remote attacker can observe differences in Prefetch behavior to disclose sensitive information.


192) Observable discrepancy (CVE-ID: CVE-2026-87620)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an observable discrepancy in SVG when rendering crafted SVG content. A remote attacker can cause the browser to render crafted SVG content to disclose sensitive information.


193) Out-of-bounds write (CVE-ID: CVE-2026-87621)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted HTML content in ANGLE. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.


194) Missing Authorization (CVE-ID: CVE-2026-87622)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to missing authorization in FedCM when processing FedCM requests. A remote attacker can induce the victim to interact with web content to perform unauthorized actions.

User interaction is required.


195) Observable discrepancy (CVE-ID: CVE-2026-87623)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose information.

The vulnerability exists due to an observable discrepancy in the DOM when rendering crafted web content. A remote attacker can cause an observable discrepancy in the DOM to disclose information.

User interaction is required to render the crafted web content.


196) Spoofing attack (CVE-ID: CVE-2026-87624)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to display misleading password-related information.

The vulnerability exists due to user interface misrepresentation in the Passwords feature when a victim interacts with crafted web content. A remote attacker can induce the victim to interact with misleading password-related information to display misleading password-related information.


197) Use-after-free (CVE-ID: CVE-2026-87625)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within V8 in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


198) Incorrect authorization (CVE-ID: CVE-2026-87626)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access DeviceBoundSessionCredentials without authorization.

The vulnerability exists due to incorrect authorization in DeviceBoundSessionCredentials when performing authorization checks. A remote attacker can trigger the flawed authorization check to access DeviceBoundSessionCredentials without authorization.

User interaction is required.


199) Interpretation Conflict (CVE-ID: CVE-2026-87627)

CWE-ID: CWE-436 - Interpretation Conflict

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass Safe Browsing protections.

The vulnerability exists due to an interpretation conflict in Safe Browsing when processing web content. A remote attacker can provide crafted web content to bypass Safe Browsing protections.

User interaction is required.


200) Use-after-free (CVE-ID: CVE-2026-87628)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Cast component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


201) Incorrect authorization (CVE-ID: CVE-2026-87629)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in sources when handling crafted content. A remote attacker can induce a victim to interact with crafted content to perform unauthorized actions.


202) Integer overflow (CVE-ID: CVE-2026-87630)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a integer overflow in WebRTC in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.


203) Missing Authorization (CVE-ID: CVE-2026-87631)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access restricted DOM resources.

The vulnerability exists due to missing authorization in the DOM when rendering crafted web content. A remote attacker can induce a victim to render crafted web content to access restricted DOM resources.

User interaction is required to render crafted web content.


204) Cross-site scripting (CVE-ID: CVE-2026-87632)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote attacker to execute arbitrary script in a victim's browser.

The vulnerability exists due to improper neutralization of input during web page generation in SanitizerAPI when processing crafted web content. A remote attacker can cause a victim to process crafted web content to execute arbitrary script in a victim's browser.

User interaction is required.


205) Use-after-free (CVE-ID: CVE-2026-87633)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Views component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


206) Use-after-free (CVE-ID: CVE-2026-87634)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to use-after-free error in WebPackaging in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


207) Spoofing attack (CVE-ID: CVE-2026-87635)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent payment-related user interface elements.

The vulnerability exists due to UI misrepresentation in Payments when rendering payment-related user interface elements. A remote attacker can cause payment-related user interface elements to be misrepresented.

User interaction is required.


208) Type Confusion (CVE-ID: CVE-2026-87636)

CWE-ID: CWE-843 - Type confusion

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a type confusion error within the XML component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a type confusion error and gain access to sensitive information.


209) Use-after-free (CVE-ID: CVE-2026-87637)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within Extensions in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


210) Out-of-bounds write (CVE-ID: CVE-2026-87638)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted HTML content in Media. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.


211) Use-after-free (CVE-ID: CVE-2026-87639)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the WebPackaging component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


212) Out-of-bounds read (CVE-ID: CVE-2026-87640)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the WebView component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.


213) Race condition (CVE-ID: CVE-2026-87641)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a race condition in in Browser in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and crash the browser.


214) Use of uninitialized resource (CVE-ID: CVE-2026-87642)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger unspecified behavior.

The vulnerability exists due to use of an uninitialized resource in WebGL when handling WebGL resources. A remote attacker can trigger the uninitialized resource condition to trigger unspecified behavior.


215) Integer overflow (CVE-ID: CVE-2026-87643)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a integer overflow in GPU in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.


216) Incorrect authorization (CVE-ID: CVE-2026-87644)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in Views when processing crafted web content. A remote attacker can trick a victim into interacting with crafted web content to perform unauthorized actions.

User interaction is required.


217) State Issues (CVE-ID: CVE-2026-87645)

CWE-ID: CWE-371 - State Issues

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to improper state validation in Safebrowsing in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.


218) Use-after-free (CVE-ID: CVE-2026-87646)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Web Authentication component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


219) Use of uninitialized resource (CVE-ID: CVE-2026-87647)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to usage of uninitialized resources in GPU in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger uninitialized usage of resources and compromise the affected system.


220) Use-after-free (CVE-ID: CVE-2026-87648)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within ANGLE in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


221) Spoofing attack (CVE-ID: CVE-2026-87649)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to deceive users through download-related UI.

The vulnerability exists due to UI misrepresentation in Downloads when presenting download-related information. A remote attacker can exploit this flaw to deceive users through download-related UI.


222) Out-of-bounds read (CVE-ID: CVE-2026-87650)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the WebGL component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.


223) Improper Authorization (CVE-ID: CVE-2026-87651)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to incorrect authorization in Paint in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.


224) Incorrect authorization (CVE-ID: CVE-2026-87652)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to incorrect authorization in PushAPI when processing PushAPI requests. A remote attacker can send a crafted PushAPI request to perform unauthorized actions.

User interaction is required.


225) Spoofing attack (CVE-ID: CVE-2026-87653)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent browser user interface elements.

The vulnerability exists due to user interface misrepresentation in the FullScreen feature when displaying crafted web content in fullscreen mode. A remote attacker can trick a victim into viewing crafted web content to misrepresent browser user interface elements.

User interaction is required.


226) Buffer overflow (CVE-ID: CVE-2026-87654)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a boundary error in ANGLE in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger a buffer overflow and execute arbitrary code on the system.


227) Improper Restriction of Rendered UI Layers or Frames (CVE-ID: CVE-2026-87655)

CWE-ID: CWE-1021 - Improper Restriction of Rendered UI Layers or Frames

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unintended download-related actions.

The vulnerability exists due to clickjacking in the Downloads feature when rendering web content. A remote attacker can trick a victim into interacting with crafted web content to perform unintended download-related actions.

User interaction is required.


228) Improper Enforcement of Behavioral Workflow (CVE-ID: CVE-2026-87656)

CWE-ID: CWE-841 - Improper Enforcement of Behavioral Workflow

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause an unspecified impact.

The vulnerability exists due to improper state validation in Safebrowsing when handling Safe Browsing state. A remote attacker can trigger an invalid state to cause an unspecified impact.


229) Use-after-free (CVE-ID: CVE-2026-87657)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within V8 in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


230) Information disclosure (CVE-ID: CVE-2026-87658)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in Extensions in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


231) Race condition (CVE-ID: CVE-2026-91708)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a race condition in Network in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and execute arbitrary code on the target system.


232) Type Confusion (CVE-ID: CVE-2026-91709)

CWE-ID: CWE-843 - Type confusion

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a type confusion error within the ServiceWorker component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger a type confusion error and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


233) Use-after-free (CVE-ID: CVE-2026-91710)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the WebAppInstalls component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


234) Out-of-bounds write (CVE-ID: CVE-2026-91711)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted HTML content in ServiceWorker. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.


235) Race condition (CVE-ID: CVE-2026-91712)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a race condition in Extensions in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and execute arbitrary code on the target system.


236) Missing Authorization (CVE-ID: CVE-2026-91713)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization.

The vulnerability exists due to missing authorization in Browser when handling content. A remote attacker can induce a victim to interact with content to bypass authorization.


237) Observable discrepancy (CVE-ID: CVE-2026-91714)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose information.

The vulnerability exists due to an observable discrepancy in Fonts when rendering web content. A remote attacker can trick the victim into visiting a website to disclose information.


238) Type Confusion (CVE-ID: CVE-2026-91715)

CWE-ID: CWE-843 - Type confusion

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a type confusion error within the ServiceWorker component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger a type confusion error and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


239) Use-after-free (CVE-ID: CVE-2026-91716)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Auth component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


240) Missing Authorization (CVE-ID: CVE-2026-91717)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to missing authorization in Chrome for Android when handling user interaction. A remote attacker can exploit the authorization flaw to perform unauthorized actions.

User interaction is required.


241) Use-after-free (CVE-ID: CVE-2026-91718)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Core component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


242) Code Injection (CVE-ID: CVE-2026-91719)

CWE-ID: CWE-94 - Improper Control of Generation of Code ('Code Injection')

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper control of code generation in XML processing when processing crafted XML content. A remote attacker can trick the victim into processing crafted XML content to execute arbitrary code.


243) Use of uninitialized resource (CVE-ID: CVE-2026-91720)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to usage of uninitialized resources in ANGLE in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger uninitialized usage of resources and compromise the affected system.


244) Use-after-free (CVE-ID: CVE-2026-91721)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Internals component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


245) Use-after-free (CVE-ID: CVE-2026-91722)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within Input in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


246) Race condition (CVE-ID: CVE-2026-91723)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a race condition in in WebAppInstalls in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and crash the browser.


247) Use-after-free (CVE-ID: CVE-2026-91724)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Input component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


248) Observable discrepancy (CVE-ID: CVE-2026-91725)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an observable discrepancy in CSS when rendering crafted web content. A remote attacker can trick a victim into visiting a crafted website to disclose sensitive information.


249) Out-of-bounds read (CVE-ID: CVE-2026-91726)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a boundary condition within the WebGL component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and execute arbitrary code on the system.


250) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-91727)

CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference

CVSSv4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to an incorrectly resolved reference in Extensions in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and overwrite arbitrary files on the system.


251) Integer overflow (CVE-ID: CVE-2026-91728)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in V8 component in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page, trigger an integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


252) Use-after-free (CVE-ID: CVE-2026-91729)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the DigitalCredentials component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


253) Incomplete cleanup (CVE-ID: CVE-2026-91730)

CWE-ID: CWE-459 - Incomplete cleanup

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to incomplete cleanup in GetUserMedia in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.


254) Type Confusion (CVE-ID: CVE-2026-91731)

CWE-ID: CWE-843 - Type confusion

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a type confusion error within the Compositing component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger a type confusion error and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


255) Missing Authorization (CVE-ID: CVE-2026-91732)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to missing authorization in AppManifest when processing a user interaction. A remote attacker can trigger the authorization flaw to perform unauthorized actions.


256) Input validation error (CVE-ID: CVE-2026-91733)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger an improper state validation condition.

The vulnerability exists due to improper state validation in Skia when processing content. A remote attacker can cause Skia to process content that triggers the condition.


257) Improper Authorization (CVE-ID: CVE-2026-91734)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to incorrect authorization in Core in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.


258) Improper Authorization (CVE-ID: CVE-2026-91735)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to incorrect authorization in WebUI in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.


259) Use-after-free (CVE-ID: CVE-2026-91736)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the DOM component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


260) Use-after-free (CVE-ID: CVE-2026-91737)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the PDF component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


261) Input validation error (CVE-ID: CVE-2026-91738)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to insufficient validation of user-supplied input in ANGLE in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


262) Missing Authorization (CVE-ID: CVE-2026-91739)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to missing authorization in the Transactions Platform when processing transactions. A remote attacker can exploit the missing authorization to perform unauthorized actions.

User interaction is required.


263) Use of uninitialized resource (CVE-ID: CVE-2026-91740)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to usage of uninitialized resources in Skia in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger uninitialized usage of resources and compromise the affected system.


264) Type Confusion (CVE-ID: CVE-2026-91741)

CWE-ID: CWE-843 - Type confusion

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a type confusion error within the CacheStorage component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger a type confusion error and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


265) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-91742)

CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to a confused deputy flaw in PriceTracking when using the PriceTracking feature. A remote attacker can trigger the confused deputy condition to perform unauthorized actions.


266) Race condition (CVE-ID: CVE-2026-91743)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a race condition in Core in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and execute arbitrary code on the target system.


267) Race condition (CVE-ID: CVE-2026-91744)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a race condition in PlatformIntegration in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and execute arbitrary code on the target system.


268) Use-after-free (CVE-ID: CVE-2026-91745)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the V8 component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


269) Integer overflow (CVE-ID: CVE-2026-91746)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in Compositing component in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page, trigger an integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


270) Use-after-free (CVE-ID: CVE-2026-91747)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Skia component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


271) Race condition (CVE-ID: CVE-2026-91748)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a race condition in Extensions in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and execute arbitrary code on the target system.


272) Use-after-free (CVE-ID: CVE-2026-91749)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Workers component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Remediation

Install update from vendor's website.