SB2026092328 - Multiple vulnerabilities in Google Chrome
Published: September 23, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 108 vulnerabilities.
1) Buffer overflow (CVE-ID: CVE-2026-95350)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a boundary error in ANGLE in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger a buffer overflow and execute arbitrary code on the system.
2) Out-of-bounds write (CVE-ID: CVE-2026-95357)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted HTML content in GPU. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.
3) Use-after-free (CVE-ID: CVE-2026-95339)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the ServiceWorker component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
4) Buffer overflow (CVE-ID: CVE-2026-95281)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a boundary error in ANGLE in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger a buffer overflow and execute arbitrary code on the system.
5) Use-after-free (CVE-ID: CVE-2026-95313)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Fullscreen component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
6) Buffer overflow (CVE-ID: CVE-2026-95349)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a boundary error in WebGL in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger a buffer overflow and execute arbitrary code on the system.
7) Buffer overflow (CVE-ID: CVE-2026-95284)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a boundary error in ANGLE in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger a buffer overflow and execute arbitrary code on the system.
8) Out-of-bounds write (CVE-ID: CVE-2026-95322)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted HTML content in GPU. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.
9) Out-of-bounds write (CVE-ID: CVE-2026-95329)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted HTML content in WebGL. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.
10) Use-after-free (CVE-ID: CVE-2026-95356)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the WindowDialog component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
11) Use-after-free (CVE-ID: CVE-2026-95310)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the AdFilter component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
12) Missing Authorization (CVE-ID: CVE-2026-95301)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to missing authorization in Extensions when interacting with extension functionality. A remote attacker can invoke functionality without required authorization to perform unauthorized actions.
User interaction is required.
13) Spoofing attack (CVE-ID: CVE-2026-95291)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to misrepresent security indicators.
The vulnerability exists due to ui misrepresentation in SecurityIndicators when rendering security indicators. A remote attacker can cause a victim to view crafted web content to misrepresent security indicators.
14) Improper Authorization (CVE-ID: CVE-2026-95355)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to incorrect authorization in Navigation in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.
15) Use-after-free (CVE-ID: CVE-2026-95315)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Aura component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
16) Use-after-free (CVE-ID: CVE-2026-95298)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Browser component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
17) Use-after-free (CVE-ID: CVE-2026-95372)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Chromecast component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
18) Use of uninitialized resource (CVE-ID: CVE-2026-95324)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to usage of uninitialized resources in GPU in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger uninitialized usage of resources and compromise the affected system.
19) Buffer overflow (CVE-ID: CVE-2026-95283)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a boundary error in Tint in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger a buffer overflow and execute arbitrary code on the system.
20) Use of uninitialized resource (CVE-ID: CVE-2026-95293)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to usage of uninitialized resources in GPU in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger uninitialized usage of resources and compromise the affected system.
21) Improper Encoding or Escaping of Output (CVE-ID: CVE-2026-95274)
CWE-ID: CWE-116 - Improper Encoding or Escaping of Output
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to inject unintended content.
The vulnerability exists due to improper output encoding in DevTools when processing crafted web content. A remote attacker can trick the victim into interacting with crafted web content to inject unintended content.
User interaction is required.
22) Use-after-free (CVE-ID: CVE-2026-95282)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Platform component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
23) Use-after-free (CVE-ID: CVE-2026-95373)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the DevTools component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
24) Use-after-free (CVE-ID: CVE-2026-95277)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Views component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
25) Use-after-free (CVE-ID: CVE-2026-95348)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Bluetooth component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
26) Use-after-free (CVE-ID: CVE-2026-95335)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the HID component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
27) Use-after-free (CVE-ID: CVE-2026-95338)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the PDFium component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
28) Buffer overflow (CVE-ID: CVE-2026-95318)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a boundary error in Video in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger a buffer overflow and execute arbitrary code on the system.
29) Type Confusion (CVE-ID: CVE-2026-95286)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a type confusion error within the Bindings component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger a type confusion error and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
30) Type Confusion (CVE-ID: CVE-2026-95365)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a type confusion error within the IndexedDB component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger a type confusion error and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
31) Use-after-free (CVE-ID: CVE-2026-95343)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the WebAudio component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
32) Race condition (CVE-ID: CVE-2026-95280)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a race condition in V8 in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and execute arbitrary code on the target system.
33) Out-of-bounds write (CVE-ID: CVE-2026-95304)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted HTML content in V8. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.
34) Type Confusion (CVE-ID: CVE-2026-95306)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a type confusion error within the V8 component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger a type confusion error and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
35) Use-after-free (CVE-ID: CVE-2026-95299)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the GPU component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
36) Use-after-free (CVE-ID: CVE-2026-95351)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Views component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
37) Missing Authorization (CVE-ID: CVE-2026-95287)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to access unauthorized resources.
The vulnerability exists due to missing authorization in Navigation when handling navigation requests. A remote user can initiate navigation to access unauthorized resources.
38) Use-after-free (CVE-ID: CVE-2026-95366)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger use of a released resource.
The vulnerability exists due to use-after-free in Core when Core accesses a released resource. A remote attacker can cause Core to access a released resource to trigger use of a released resource.
User interaction is required.
39) Input validation error (CVE-ID: CVE-2026-95382)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to insufficient validation of user-supplied input in Auth in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.
40) Input validation error (CVE-ID: CVE-2026-95381)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to insufficient validation of user-supplied input in Printing in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.
41) Out-of-bounds write (CVE-ID: CVE-2026-95331)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted HTML content in ANGLE. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.
42) Missing Authorization (CVE-ID: CVE-2026-95297)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to missing authorization in Contextual Tasks when handling contextual task actions. A remote attacker can cause a victim to interact with Contextual Tasks to perform unauthorized actions.
43) Incorrect authorization (CVE-ID: CVE-2026-95375)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to improper authorization in BrowserTag when performing authorization checks. A remote attacker can exploit the improper authorization checks to perform unauthorized actions.
44) Incorrect authorization (CVE-ID: CVE-2026-95302)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to incorrect authorization in WebAPKs when processing a WebAPK. A remote attacker can provide a WebAPK for processing to perform unauthorized actions.
User interaction is required.
45) Cross-site request forgery (CVE-ID: CVE-2026-95362)
CWE-ID: CWE-352 - Cross-Site Request Forgery (CSRF)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to cross-site request forgery in DevTools when handling requests initiated by crafted web content. A remote attacker can trick a victim into visiting crafted web content to perform unauthorized actions.
User interaction is required.
46) Improperly implemented security check for standard (CVE-ID: CVE-2026-95369)
CWE-ID: CWE-358 - Improperly Implemented Security Check for Standard
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to incorrect implementation in XML in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.
47) Externally Controlled Reference to a Resource in Another Sphere (CVE-ID: CVE-2026-95376)
CWE-ID: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause Chrome DevTools to access an externally controlled resource.
The vulnerability exists due to an externally controlled reference in DevTools when processing externally supplied references. A remote attacker can provide an externally controlled reference to cause Chrome DevTools to access an externally controlled resource.
User interaction is required.
48) Use of uninitialized resource (CVE-ID: CVE-2026-95359)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an uninitialized resource in the GPU component when rendering crafted content. A remote attacker can trick the victim into rendering crafted content to cause a denial of service.
User interaction is required.
49) Spoofing attack (CVE-ID: CVE-2026-95294)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to misrepresent browser user interface elements.
The vulnerability exists due to UI misrepresentation in the Browser component when rendering web content. A remote attacker can trick the victim into visiting a crafted website to misrepresent browser user interface elements.
50) Spoofing attack (CVE-ID: CVE-2026-95337)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause UI misrepresentation.
The vulnerability exists due to UI misrepresentation in Messages when rendering content. A remote attacker can cause misleading interface elements to be displayed to cause UI misrepresentation.
User interaction is required.
51) Spoofing attack (CVE-ID: CVE-2026-95346)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to misrepresent the user interface.
The vulnerability exists due to ui misrepresentation in Chromoting when interacting with Chromoting. A remote attacker can trigger misleading user interface presentation to misrepresent the user interface.
52) Missing Authorization (CVE-ID: CVE-2026-95320)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to missing authorization in Navigation when handling navigation requests. A remote attacker can trick a victim into initiating a crafted navigation to perform unauthorized actions.
53) Incorrect authorization (CVE-ID: CVE-2026-95317)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access media capture resources.
The vulnerability exists due to incorrect authorization in MediaCapture when handling user interaction. A remote attacker can cause a victim to interact with crafted content to access media capture resources.
54) Use-after-free (CVE-ID: CVE-2026-95345)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Actor in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
55) State Issues (CVE-ID: CVE-2026-95330)
CWE-ID: CWE-371 - State Issues
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to improper state validation in Downloads in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.
56) Improperly implemented security check for standard (CVE-ID: CVE-2026-95370)
CWE-ID: CWE-358 - Improperly Implemented Security Check for Standard
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to incorrect implementation in NFC in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.
57) Incomplete cleanup (CVE-ID: CVE-2026-95303)
CWE-ID: CWE-459 - Incomplete cleanup
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to incomplete cleanup in SmartCard in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.
58) Race condition (CVE-ID: CVE-2026-95360)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to a race condition in in Editing in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and crash the browser.
59) Information disclosure (CVE-ID: CVE-2026-95295)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in Mobile in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
60) Input validation error (CVE-ID: CVE-2026-95276)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to insufficient validation of user-supplied input in Themes in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.
61) Incorrect authorization (CVE-ID: CVE-2026-95314)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions through HID devices.
The vulnerability exists due to incorrect authorization in HID when handling HID access requests. A remote attacker can submit a crafted HID access request to perform unauthorized actions through HID devices.
62) Missing Authorization (CVE-ID: CVE-2026-95371)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization controls.
The vulnerability exists due to missing authorization in Views when handling web content. A remote attacker can exploit missing authorization checks to bypass authorization controls.
63) Use-after-free (CVE-ID: CVE-2026-95353)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Bindings in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
64) Spoofing attack (CVE-ID: CVE-2026-95363)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to mislead a victim.
The vulnerability exists due to UI misrepresentation in FileSystem when rendering content. A remote attacker can cause FileSystem to display misleading information to a victim to mislead a victim.
65) Input validation error (CVE-ID: CVE-2026-95341)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to insufficient validation of user-supplied input in Desktop in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.
66) Use-after-free (CVE-ID: CVE-2026-95354)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Verifier in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
67) Race condition (CVE-ID: CVE-2026-95384)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to a race condition in in Transactions Platform in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and crash the browser.
68) Information disclosure (CVE-ID: CVE-2026-95336)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in Transactions Platform in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
69) Missing Authorization (CVE-ID: CVE-2026-95290)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to missing authorization in NFC functionality when using NFC functionality. A remote attacker can exploit the missing authorization to perform unauthorized actions.
70) Use-after-free (CVE-ID: CVE-2026-95325)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within ANGLE in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
71) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-95275)
CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to use of incorrectly resolved reference in MediaStream in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.
72) Incorrect authorization (CVE-ID: CVE-2026-95374)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access resources without authorization.
The vulnerability exists due to incorrect authorization in the Network component when handling network requests. A remote attacker can cause the victim to handle a network request to access resources without authorization.
User interaction is required.
73) Missing Authorization (CVE-ID: CVE-2026-95300)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access DevTools functionality without authorization.
The vulnerability exists due to missing authorization in DevTools when accessing DevTools functionality. A remote attacker can access DevTools functionality without authorization to access DevTools functionality without authorization.
74) Spoofing attack (CVE-ID: CVE-2026-95321)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to mislead users.
The vulnerability exists due to UI misrepresentation in Payments when displaying payment-related user interface. A remote attacker can exploit the UI misrepresentation to mislead users.
75) Spoofing attack (CVE-ID: CVE-2026-95323)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to mislead users through user interface misrepresentation.
The vulnerability exists due to user interface misrepresentation in Chromium when rendering web content. A remote attacker can cause user interface elements to be misrepresented to mislead users through user interface misrepresentation.
User interaction is required.
76) Use of Uninitialized Variable (CVE-ID: CVE-2026-95332)
CWE-ID: CWE-457 - Use of Uninitialized Variable
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to the use of an uninitialized variable in Tint when processing crafted web content. A remote attacker can cause the browser to process crafted web content to cause a denial of service.
User interaction is required.
77) Information disclosure (CVE-ID: CVE-2026-95312)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in Passwords in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.
78) Race condition (CVE-ID: CVE-2026-95344)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to a race condition in in DevTools in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and crash the browser.
79) Incorrect authorization (CVE-ID: CVE-2026-95289)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to incorrect authorization in Scroll when processing crafted web content. A remote attacker can trick a victim into interacting with crafted web content to perform unauthorized actions.
80) Use-after-free (CVE-ID: CVE-2026-95347)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Updater in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
81) Free of Memory not on the Heap (CVE-ID: CVE-2026-95311)
CWE-ID: CWE-590 - Free of Memory not on the Heap
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to freeing memory that is not allocated on the heap in Fonts when rendering crafted font data. A remote attacker can trick a victim into viewing crafted web content to cause a denial of service.
User interaction is required.
82) Incorrect authorization (CVE-ID: CVE-2026-95358)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to incorrect authorization in Mobile Chrome when a user interacts with crafted web content. A remote attacker can trick a user into interacting with crafted web content to perform unauthorized actions.
83) Use-after-free (CVE-ID: CVE-2026-95333)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Metrics in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
84) Spoofing attack (CVE-ID: CVE-2026-95307)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to misrepresent user interface elements.
The vulnerability exists due to user interface misrepresentation in ExtensionsMenu when handling user interaction. A remote attacker can exploit the issue to misrepresent user interface elements.
85) Missing Authorization (CVE-ID: CVE-2026-95285)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization.
The vulnerability exists due to missing authorization in WebView when handling web content. A remote attacker can provide web content to bypass authorization.
User interaction is required.
86) Missing Authorization (CVE-ID: CVE-2026-95278)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to improper authorization in WakeLock when processing WakeLock requests. A remote attacker can submit a WakeLock request to perform unauthorized actions.
87) Information disclosure (CVE-ID: CVE-2026-95327)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper handling of information in the Networking component when processing network data. A remote attacker can trigger the information leak to disclose sensitive information.
88) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-95334)
CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause incorrect reference resolution.
The vulnerability exists due to incorrect reference resolution in WebProtect when processing references. A remote attacker can trigger vulnerable reference resolution to cause incorrect reference resolution.
User interaction is required.
89) Integer overflow (CVE-ID: CVE-2026-95308)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to crash the browser.
The vulnerability exists due to a integer overflow in Metrics in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.
90) Incorrect authorization (CVE-ID: CVE-2026-95292)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to incorrect authorization in Safe Browsing when processing Safe Browsing data. A remote attacker can exploit the authorization flaw to perform unauthorized actions.
91) Incorrect authorization (CVE-ID: CVE-2026-95352)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain unauthorized access to DevTools functionality.
The vulnerability exists due to incorrect authorization in DevTools when a victim interacts with crafted web content. A remote attacker can exploit the authorization flaw to gain unauthorized access to DevTools functionality.
92) Spoofing attack (CVE-ID: CVE-2026-95279)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to mislead users through the Omnibox.
The vulnerability exists due to improper user interface representation in the Omnibox when presenting browser interface information. A remote attacker can cause the Omnibox to present misleading information to mislead users through the Omnibox.
93) Information disclosure (CVE-ID: CVE-2026-95367)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper information exposure in DataTransfer when processing DataTransfer data. A remote attacker can trigger the processing of DataTransfer data to disclose sensitive information.
User interaction is required.
94) Improperly implemented security check for standard (CVE-ID: CVE-2026-95385)
CWE-ID: CWE-358 - Improperly Implemented Security Check for Standard
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to incorrect implementation in PlatformIntegration in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.
95) Incorrect authorization (CVE-ID: CVE-2026-95368)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization controls.
The vulnerability exists due to incorrect authorization in DevTools when handling user-initiated DevTools operations. A remote attacker can induce a victim to interact with content to bypass authorization controls.
96) Use-after-free (CVE-ID: CVE-2026-95319)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to use-after-free error in Printing in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.
97) Incomplete cleanup (CVE-ID: CVE-2026-95326)
CWE-ID: CWE-459 - Incomplete cleanup
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to incomplete cleanup in Bluetooth in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.
98) Spoofing attack (CVE-ID: CVE-2026-95309)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to misrepresent the user interface.
The vulnerability exists due to UI misrepresentation in Mobile when displaying browser content. A remote attacker can cause a user interface element to be misrepresented to misrepresent the user interface.
99) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-95361)
CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to a confused deputy issue in DevTools when handling DevTools operations. A remote attacker can cause DevTools to act on their behalf to perform unauthorized actions.
100) Spoofing attack (CVE-ID: CVE-2026-95288)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to deceive users.
The vulnerability exists due to UI misrepresentation in Mobile when rendering web content. A remote attacker can cause user interface elements to be misrepresented to deceive users.
101) Type Confusion (CVE-ID: CVE-2026-95380)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a type confusion error within the V8 component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a type confusion error and crash the browser.
102) Missing Authorization (CVE-ID: CVE-2026-95342)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization controls.
The vulnerability exists due to missing authorization in V8 when processing crafted web content. A remote attacker can provide crafted web content to bypass authorization controls.
103) Missing Authorization (CVE-ID: CVE-2026-95296)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to missing authorization in Core when user interaction occurs. A remote attacker can trigger the authorization flaw to perform unauthorized actions.
104) Unchecked Return Value (CVE-ID: CVE-2026-95316)
CWE-ID: CWE-252 - Unchecked Return Value
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to unchecked return value in Performance in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.
105) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-95328)
CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to a confused deputy condition in Mobile when a user interacts with content. A remote attacker can cause Mobile to act on their behalf to perform unauthorized actions.
106) Incorrect authorization (CVE-ID: CVE-2026-95340)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization restrictions.
The vulnerability exists due to incorrect authorization in PictureInPicture when processing user interaction. A remote attacker can exploit the incorrect authorization to bypass authorization restrictions.
107) Input validation error (CVE-ID: CVE-2026-95364)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to insufficient validation of user-supplied input in Passwords in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.
108) Spoofing attack (CVE-ID: CVE-2026-95305)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to misrepresent user interface elements.
The vulnerability exists due to UI misrepresentation in Chromoting when handling Chromoting interactions. A remote attacker can cause user interface elements to be misrepresented to misrepresent user interface elements.
Remediation
Install update from vendor's website.
References
- https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html
- https://issues.chromium.org/issues/551573368
- https://issues.chromium.org/issues/530045332
- https://issues.chromium.org/issues/548585299
- https://issues.chromium.org/issues/551708184
- https://issues.chromium.org/issues/552665794
- https://issues.chromium.org/issues/553172761
- https://issues.chromium.org/issues/556435507
- https://issues.chromium.org/issues/556576992
- https://issues.chromium.org/issues/559320837
- https://issues.chromium.org/issues/560439699
- https://issues.chromium.org/issues/562151598
- https://issues.chromium.org/issues/540265100
- https://issues.chromium.org/issues/543471693
- https://issues.chromium.org/issues/508462481
- https://issues.chromium.org/issues/517661385
- https://issues.chromium.org/issues/520516206
- https://issues.chromium.org/issues/534997484
- https://issues.chromium.org/issues/537857253
- https://issues.chromium.org/issues/543141419
- https://issues.chromium.org/issues/550953039
- https://issues.chromium.org/issues/553116160
- https://issues.chromium.org/issues/553129513
- https://issues.chromium.org/issues/553130481
- https://issues.chromium.org/issues/553136141
- https://issues.chromium.org/issues/554558320
- https://issues.chromium.org/issues/555299641
- https://issues.chromium.org/issues/556535630
- https://issues.chromium.org/issues/556576976
- https://issues.chromium.org/issues/557523002
- https://issues.chromium.org/issues/558764482
- https://issues.chromium.org/issues/559815527
- https://issues.chromium.org/issues/560406548
- https://issues.chromium.org/issues/560536731
- https://issues.chromium.org/issues/560536735
- https://issues.chromium.org/issues/561997427
- https://issues.chromium.org/issues/562242429
- https://issues.chromium.org/issues/495529018
- https://issues.chromium.org/issues/497204165
- https://issues.chromium.org/issues/497212105
- https://issues.chromium.org/issues/497603247
- https://issues.chromium.org/issues/500127519
- https://issues.chromium.org/issues/501648493
- https://issues.chromium.org/issues/502179319
- https://issues.chromium.org/issues/502242455
- https://issues.chromium.org/issues/511791538
- https://issues.chromium.org/issues/513049042
- https://issues.chromium.org/issues/513134076
- https://issues.chromium.org/issues/513162143
- https://issues.chromium.org/issues/513992281
- https://issues.chromium.org/issues/514019137
- https://issues.chromium.org/issues/514059630
- https://issues.chromium.org/issues/514072284
- https://issues.chromium.org/issues/514487499
- https://issues.chromium.org/issues/516404074
- https://issues.chromium.org/issues/517163294
- https://issues.chromium.org/issues/517417437
- https://issues.chromium.org/issues/517442714
- https://issues.chromium.org/issues/517584808
- https://issues.chromium.org/issues/517596255
- https://issues.chromium.org/issues/517730821
- https://issues.chromium.org/issues/517802696
- https://issues.chromium.org/issues/520504291
- https://issues.chromium.org/issues/522061704
- https://issues.chromium.org/issues/522344883
- https://issues.chromium.org/issues/523719002
- https://issues.chromium.org/issues/524582798
- https://issues.chromium.org/issues/526550688
- https://issues.chromium.org/issues/532962621
- https://issues.chromium.org/issues/536161355
- https://issues.chromium.org/issues/536648933
- https://issues.chromium.org/issues/542926849
- https://issues.chromium.org/issues/543464436
- https://issues.chromium.org/issues/545449081
- https://issues.chromium.org/issues/545879261
- https://issues.chromium.org/issues/546438368
- https://issues.chromium.org/issues/546639650
- https://issues.chromium.org/issues/547832510
- https://issues.chromium.org/issues/548611433
- https://issues.chromium.org/issues/549911100
- https://issues.chromium.org/issues/550181232
- https://issues.chromium.org/issues/553123003
- https://issues.chromium.org/issues/553141660
- https://issues.chromium.org/issues/559682346
- https://issues.chromium.org/issues/423956129
- https://issues.chromium.org/issues/497094708
- https://issues.chromium.org/issues/497344014
- https://issues.chromium.org/issues/502077689
- https://issues.chromium.org/issues/513403696
- https://issues.chromium.org/issues/513714849
- https://issues.chromium.org/issues/513781838
- https://issues.chromium.org/issues/513791872
- https://issues.chromium.org/issues/514012689
- https://issues.chromium.org/issues/514524620
- https://issues.chromium.org/issues/517192965
- https://issues.chromium.org/issues/522413520
- https://issues.chromium.org/issues/523765972
- https://issues.chromium.org/issues/533041383
- https://issues.chromium.org/issues/533074595
- https://issues.chromium.org/issues/533095855
- https://issues.chromium.org/issues/533102653
- https://issues.chromium.org/issues/534579660
- https://issues.chromium.org/issues/547027738
- https://issues.chromium.org/issues/551296612
- https://issues.chromium.org/issues/552023752
- https://issues.chromium.org/issues/553148673
- https://issues.chromium.org/issues/553268567
- https://issues.chromium.org/issues/553271219
- https://issues.chromium.org/issues/553921181