Google Security Advisories · September 2026 — Google Security Advisories
560 advisories 557 CVEs 7 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2026-09. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 7 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2026-85046

GoogleExploitedCISA KEV listedCRITICAL2026-09-03

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-85046

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
v8 affected google
Upstream advisory

CVE-2026-85046

Project ZeroExploitedCISA KEV listed2026-09-03

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-85046

Upstream advisory

CVE-2026-87491

Project ZeroExploitedCISA KEV listed2026-09-09

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87491

Upstream advisory

CVE-2026-87491

GoogleExploitedCISA KEV listedCRITICAL2026-09-09

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87491

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-85880

GoogleExploitedCISA KEV listedHIGH2026-09-08

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

CVEs:CVE-2026-85880

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1607 affected microsoft
windows_10_1809 affected microsoft
windows_10_21h2 affected microsoft
windows_10_22h2 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
windows_server_2022 affected microsoft
Upstream advisory

CVE-2026-58704

Open SourceExploitedCISA KEV listedHIGH2026-09-15

In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2026-58704

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CLSA-2026-1788442788

Open SourceActive exploitation (sightings)2026-09-03

TuxCare security update for org.apache.logging.log4j (2 CVEs)

Affected products

ProductStatusVendorPackageEcosystem
org.apache.logging.log4j:log4j affected TuxCare:Maven org.apache.logging.log4j:log4j
org.apache.logging.log4j:log4j-1.2-api affected TuxCare:Maven org.apache.logging.log4j:log4j-1.2-api
org.apache.logging.log4j:log4j-api affected TuxCare:Maven org.apache.logging.log4j:log4j-api
org.apache.logging.log4j:log4j-appserver affected TuxCare:Maven org.apache.logging.log4j:log4j-appserver
org.apache.logging.log4j:log4j-bom affected TuxCare:Maven org.apache.logging.log4j:log4j-bom
org.apache.logging.log4j:log4j-cassandra affected TuxCare:Maven org.apache.logging.log4j:log4j-cassandra
org.apache.logging.log4j:log4j-core affected TuxCare:Maven org.apache.logging.log4j:log4j-core
org.apache.logging.log4j:log4j-couchdb affected TuxCare:Maven org.apache.logging.log4j:log4j-couchdb
org.apache.logging.log4j:log4j-docker affected TuxCare:Maven org.apache.logging.log4j:log4j-docker
org.apache.logging.log4j:log4j-flume-ng affected TuxCare:Maven org.apache.logging.log4j:log4j-flume-ng
org.apache.logging.log4j:log4j-iostreams affected TuxCare:Maven org.apache.logging.log4j:log4j-iostreams
org.apache.logging.log4j:log4j-jakarta-web affected TuxCare:Maven org.apache.logging.log4j:log4j-jakarta-web
org.apache.logging.log4j:log4j-jcl affected TuxCare:Maven org.apache.logging.log4j:log4j-jcl
org.apache.logging.log4j:log4j-jdbc-dbcp2 affected TuxCare:Maven org.apache.logging.log4j:log4j-jdbc-dbcp2
org.apache.logging.log4j:log4j-jmx-gui affected TuxCare:Maven org.apache.logging.log4j:log4j-jmx-gui
org.apache.logging.log4j:log4j-jpa affected TuxCare:Maven org.apache.logging.log4j:log4j-jpa
org.apache.logging.log4j:log4j-jpl affected TuxCare:Maven org.apache.logging.log4j:log4j-jpl
org.apache.logging.log4j:log4j-jul affected TuxCare:Maven org.apache.logging.log4j:log4j-jul
org.apache.logging.log4j:log4j-kubernetes affected TuxCare:Maven org.apache.logging.log4j:log4j-kubernetes
org.apache.logging.log4j:log4j-layout-template-json affected TuxCare:Maven org.apache.logging.log4j:log4j-layout-template-json
org.apache.logging.log4j:log4j-liquibase affected TuxCare:Maven org.apache.logging.log4j:log4j-liquibase
org.apache.logging.log4j:log4j-mongodb3 affected TuxCare:Maven org.apache.logging.log4j:log4j-mongodb3
org.apache.logging.log4j:log4j-mongodb4 affected TuxCare:Maven org.apache.logging.log4j:log4j-mongodb4
org.apache.logging.log4j:log4j-osgi affected TuxCare:Maven org.apache.logging.log4j:log4j-osgi
org.apache.logging.log4j:log4j-slf4j18-impl affected TuxCare:Maven org.apache.logging.log4j:log4j-slf4j18-impl
org.apache.logging.log4j:log4j-slf4j-impl affected TuxCare:Maven org.apache.logging.log4j:log4j-slf4j-impl
org.apache.logging.log4j:log4j-spring-boot affected TuxCare:Maven org.apache.logging.log4j:log4j-spring-boot
org.apache.logging.log4j:log4j-spring-cloud-config affected TuxCare:Maven org.apache.logging.log4j:log4j-spring-cloud-config
org.apache.logging.log4j:log4j-spring-cloud-config-client affected TuxCare:Maven org.apache.logging.log4j:log4j-spring-cloud-config-client
org.apache.logging.log4j:log4j-taglib affected TuxCare:Maven org.apache.logging.log4j:log4j-taglib
org.apache.logging.log4j:log4j-to-slf4j affected TuxCare:Maven org.apache.logging.log4j:log4j-to-slf4j
org.apache.logging.log4j:log4j-web affected TuxCare:Maven org.apache.logging.log4j:log4j-web
Upstream advisory

CLSA-2026-1788348158

Open SourceActive exploitation (sightings)2026-09-02

TuxCare security update for firebase/php-jwt (1 CVE)

Affected products

ProductStatusVendorPackageEcosystem
php-jwt affected firebase firebase/php-jwt
Upstream advisory

CLSA-2026-1788858730

Open SourcePoC exploit2026-09-08

TuxCare security update for protobuf (1 CVE)

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected TuxCare:PyPI protobuf
Upstream advisory

RLSA-2026:62631

Open SourcePoC exploitHIGH2026-09-03

Important: golang-github-openprinting-ipp-usb security update

Affected products

ProductStatusVendorPackageEcosystem
golang-github-openprinting-ipp-usb affected Rocky Linux:10 golang-github-openprinting-ipp-usb
Upstream advisory

CVE-2026-75865

GooglePoC exploitCRITICAL2026-09-01

The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the saas_upload_logo() function combined with an auth...

CVEs:CVE-2026-75865

Affected products

ProductStatusVendorPackageEcosystem
WPLP Cookie Consent affected WordPress
WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode (gdpr-cookie-consent) affected wplegalpages
Upstream advisory

MINI-2cgw-w5mh-ww2r

Open SourcePoC exploit2026-09-02

MINI-2cgw-w5mh-ww2r

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

MINI-4hhx-mcvw-w5x6

Open SourcePoC exploit2026-09-02

MINI-4hhx-mcvw-w5x6

Affected products

ProductStatusVendorPackageEcosystem
google-cloud-sdk-core affected MinimOS google-cloud-sdk-core
Upstream advisory

MINI-4jch-224p-m4c8

Open SourcePoC exploit2026-09-02

MINI-4jch-224p-m4c8

Affected products

ProductStatusVendorPackageEcosystem
google-cloud-sdk-core affected MinimOS google-cloud-sdk-core
Upstream advisory

MINI-45wm-jc6h-wcph

Open SourcePoC exploit2026-09-02

MINI-45wm-jc6h-wcph

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

MINI-4423-mf5w-88cp

Open SourcePoC exploit2026-09-02

MINI-4423-mf5w-88cp

Affected products

ProductStatusVendorPackageEcosystem
google-cloud-sdk-core affected MinimOS google-cloud-sdk-core
Upstream advisory

CVE-2026-87492

GooglePoC exploitCRITICAL2026-09-09

Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-87492

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-85048

GooglePoC exploitCRITICAL2026-09-03

Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-85048

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-0159

Open SourcePoC exploitHIGH2026-09-15

In Cellular Modem, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-0159

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-87606

GooglePoC exploitHIGH2026-09-09

Missing authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87606

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-85045

GooglePoC exploitCRITICAL2026-09-03

Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-85045

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

MINI-3qph-pgr9-fc22

Open SourcePoC exploit2026-09-02

MINI-3qph-pgr9-fc22

Affected products

ProductStatusVendorPackageEcosystem
ceph-20.2 affected MinimOS ceph-20.2
ceph-20.2-base affected MinimOS ceph-20.2-base
ceph-20.2-cephadm affected MinimOS ceph-20.2-cephadm
ceph-20.2-common affected MinimOS ceph-20.2-common
ceph-20.2-dev affected MinimOS ceph-20.2-dev
ceph-20.2-doc affected MinimOS ceph-20.2-doc
ceph-20.2-exporter affected MinimOS ceph-20.2-exporter
ceph-20.2-fuse affected MinimOS ceph-20.2-fuse
ceph-20.2-immutable-object-cache affected MinimOS ceph-20.2-immutable-object-cache
ceph-20.2-libcephfs affected MinimOS ceph-20.2-libcephfs
ceph-20.2-librados affected MinimOS ceph-20.2-librados
ceph-20.2-librbd affected MinimOS ceph-20.2-librbd
ceph-20.2-librgw affected MinimOS ceph-20.2-librgw
ceph-20.2-libs affected MinimOS ceph-20.2-libs
ceph-20.2-mds affected MinimOS ceph-20.2-mds
ceph-20.2-mgr affected MinimOS ceph-20.2-mgr
ceph-20.2-mgr-cephadm affected MinimOS ceph-20.2-mgr-cephadm
ceph-20.2-mgr-dashboard affected MinimOS ceph-20.2-mgr-dashboard
ceph-20.2-mgr-diskprediction-local affected MinimOS ceph-20.2-mgr-diskprediction-local
ceph-20.2-mgr-k8sevents affected MinimOS ceph-20.2-mgr-k8sevents
ceph-20.2-mgr-rook affected MinimOS ceph-20.2-mgr-rook
ceph-20.2-mirror affected MinimOS ceph-20.2-mirror
ceph-20.2-mon affected MinimOS ceph-20.2-mon
ceph-20.2-osd affected MinimOS ceph-20.2-osd
ceph-20.2-python affected MinimOS ceph-20.2-python
ceph-20.2-radosgw affected MinimOS ceph-20.2-radosgw
ceph-20.2-test affected MinimOS ceph-20.2-test
py3.10-ceph-20.2-ceph-argparse affected MinimOS py3.10-ceph-20.2-ceph-argparse
py3.10-ceph-20.2-ceph-common affected MinimOS py3.10-ceph-20.2-ceph-common
py3.10-ceph-20.2-cephfs affected MinimOS py3.10-ceph-20.2-cephfs
py3.10-ceph-20.2-rados affected MinimOS py3.10-ceph-20.2-rados
py3.10-ceph-20.2-rbd affected MinimOS py3.10-ceph-20.2-rbd
py3.10-ceph-20.2-rgw affected MinimOS py3.10-ceph-20.2-rgw
py3.11-ceph-20.2-ceph-argparse affected MinimOS py3.11-ceph-20.2-ceph-argparse
py3.11-ceph-20.2-ceph-common affected MinimOS py3.11-ceph-20.2-ceph-common
py3.11-ceph-20.2-cephfs affected MinimOS py3.11-ceph-20.2-cephfs
py3.11-ceph-20.2-rados affected MinimOS py3.11-ceph-20.2-rados
py3.11-ceph-20.2-rbd affected MinimOS py3.11-ceph-20.2-rbd
py3.11-ceph-20.2-rgw affected MinimOS py3.11-ceph-20.2-rgw
py3.12-ceph-20.2-ceph-argparse affected MinimOS py3.12-ceph-20.2-ceph-argparse
py3.12-ceph-20.2-ceph-common affected MinimOS py3.12-ceph-20.2-ceph-common
py3.12-ceph-20.2-cephfs affected MinimOS py3.12-ceph-20.2-cephfs
py3.12-ceph-20.2-rados affected MinimOS py3.12-ceph-20.2-rados
py3.12-ceph-20.2-rbd affected MinimOS py3.12-ceph-20.2-rbd
py3.12-ceph-20.2-rgw affected MinimOS py3.12-ceph-20.2-rgw
py3.13-ceph-20.2-ceph-argparse affected MinimOS py3.13-ceph-20.2-ceph-argparse
py3.13-ceph-20.2-ceph-common affected MinimOS py3.13-ceph-20.2-ceph-common
py3.13-ceph-20.2-cephfs affected MinimOS py3.13-ceph-20.2-cephfs
py3.13-ceph-20.2-rados affected MinimOS py3.13-ceph-20.2-rados
py3.13-ceph-20.2-rbd affected MinimOS py3.13-ceph-20.2-rbd
py3.13-ceph-20.2-rgw affected MinimOS py3.13-ceph-20.2-rgw
py3-supported-ceph-20.2-ceph-argparse affected MinimOS py3-supported-ceph-20.2-ceph-argparse
py3-supported-ceph-20.2-ceph-common affected MinimOS py3-supported-ceph-20.2-ceph-common
py3-supported-ceph-20.2-cephfs affected MinimOS py3-supported-ceph-20.2-cephfs
py3-supported-ceph-20.2-rados affected MinimOS py3-supported-ceph-20.2-rados
py3-supported-ceph-20.2-rbd affected MinimOS py3-supported-ceph-20.2-rbd
py3-supported-ceph-20.2-rgw affected MinimOS py3-supported-ceph-20.2-rgw
Upstream advisory

CVE-2026-87575

GooglePoC exploitMEDIUM2026-09-09

Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87575

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-49881

Open SourcePoC exploitHIGH2026-09-08

In serviceClassExists of InCallController.java, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need...

CVEs:CVE-2026-49881

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-28668

Open SourcePoC exploitHIGH2026-09-08

In LimitRealloc of malloc_limit.cpp, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-28668

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-0084

Open SourcePoC exploitHIGH2026-09-08

In multiple functions of HostEmulationManager.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is no...

CVEs:CVE-2026-0084

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-0065

Open SourcePoC exploitHIGH2026-09-08

In areBackgroundActivityStartsAllowed of BackgroundLaunchProcessController.java, there is a possible unintended way to launch activities in the background due to a logic error in the code. This could lead to local escalation of privilege with User exec...

CVEs:CVE-2026-0065

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-0054

Open SourcePoC exploitMEDIUM2026-09-08

In isCallerAllowed of WalletContextualLocationsService.kt, there is a possible way to get wallet information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interac...

CVEs:CVE-2026-0054

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

RHBA-2020:0582

Open SourceCoalition ESS < 30%HIGH2026-09-06

Red Hat Bug Fix Advisory: OpenShift Container Platform 4.4 RPM release advisory

Affected products

ProductStatusVendorPackageEcosystem
afterburn affected Red Hat:openshift:4.4::el8 afterburn
afterburn-debuginfo affected Red Hat:openshift:4.4::el8 afterburn-debuginfo
ansible-asb-modules affected Red Hat:openshift:4.4::el7 ansible-asb-modules
ansible-kubernetes-modules affected Red Hat:openshift:4.4::el7 ansible-kubernetes-modules
ansible-runner affected Red Hat:openshift:4.4::el7 ansible-runner
ansible-runner-http affected Red Hat:openshift:4.4::el7 ansible-runner-http
apb affected Red Hat:openshift:4.4::el7 apb
apb-base-scripts affected Red Hat:openshift:4.4::el7 apb-base-scripts
apb-container-scripts affected Red Hat:openshift:4.4::el7 apb-container-scripts
apb-devel affected Red Hat:openshift:4.4::el7 apb-devel
atomic-enterprise-service-catalog affected Red Hat:openshift:4.4::el7 atomic-enterprise-service-catalog
atomic-enterprise-service-catalog-svcat affected Red Hat:openshift:4.4::el7 atomic-enterprise-service-catalog-svcat
atomic-openshift-service-idler affected Red Hat:openshift:4.4::el7 atomic-openshift-service-idler
buildah affected Red Hat:openshift:4.4::el8 buildah
buildah-debuginfo affected Red Hat:openshift:4.4::el8 buildah-debuginfo
buildah-debugsource affected Red Hat:openshift:4.4::el8 buildah-debugsource
buildah-tests affected Red Hat:openshift:4.4::el8 buildah-tests
buildah-tests-debuginfo affected Red Hat:openshift:4.4::el8 buildah-tests-debuginfo
conmon affected Red Hat:openshift:4.4::el7 conmon
conmon affected Red Hat:openshift:4.4::el8 conmon
console-login-helper-messages affected Red Hat:openshift:4.4::el8 console-login-helper-messages
console-login-helper-messages-issuegen affected Red Hat:openshift:4.4::el8 console-login-helper-messages-issuegen
console-login-helper-messages-profile affected Red Hat:openshift:4.4::el8 console-login-helper-messages-profile
containernetworking-plugins affected Red Hat:openshift:4.4::el7 containernetworking-plugins
containernetworking-plugins affected Red Hat:openshift:4.4::el8 containernetworking-plugins
containernetworking-plugins-debuginfo affected Red Hat:openshift:4.4::el7 containernetworking-plugins-debuginfo
containernetworking-plugins-debuginfo affected Red Hat:openshift:4.4::el8 containernetworking-plugins-debuginfo
containernetworking-plugins-debugsource affected Red Hat:openshift:4.4::el8 containernetworking-plugins-debugsource
containers-common affected Red Hat:openshift:4.4::el8 containers-common
containers-common affected Red Hat:openshift:4.4::el7 containers-common
coreos-installer affected Red Hat:openshift:4.4::el8 coreos-installer
coreos-installer-dracut affected Red Hat:openshift:4.4::el8 coreos-installer-dracut
cri-tools affected Red Hat:openshift:4.4::el8 cri-tools
cri-tools affected Red Hat:openshift:4.4::el7 cri-tools
cri-tools-debuginfo affected Red Hat:openshift:4.4::el7 cri-tools-debuginfo
cri-tools-debuginfo affected Red Hat:openshift:4.4::el8 cri-tools-debuginfo
cri-tools-debugsource affected Red Hat:openshift:4.4::el8 cri-tools-debugsource
dracut affected Red Hat:openshift:4.4::el8 dracut
dracut-caps affected Red Hat:openshift:4.4::el8 dracut-caps
dracut-config-generic affected Red Hat:openshift:4.4::el8 dracut-config-generic
dracut-config-rescue affected Red Hat:openshift:4.4::el8 dracut-config-rescue
dracut-debuginfo affected Red Hat:openshift:4.4::el8 dracut-debuginfo
dracut-debugsource affected Red Hat:openshift:4.4::el8 dracut-debugsource
dracut-live affected Red Hat:openshift:4.4::el8 dracut-live
dracut-network affected Red Hat:openshift:4.4::el8 dracut-network
dracut-squash affected Red Hat:openshift:4.4::el8 dracut-squash
dracut-tools affected Red Hat:openshift:4.4::el8 dracut-tools
dumb-init affected Red Hat:openshift:4.4::el7 dumb-init
dumb-init-debuginfo affected Red Hat:openshift:4.4::el7 dumb-init-debuginfo
elastic-curator affected Red Hat:openshift:4.4::el7 elastic-curator
faq affected Red Hat:openshift:4.4::el7 faq
faq-debuginfo affected Red Hat:openshift:4.4::el7 faq-debuginfo
fb303 affected Red Hat:openshift:4.4::el7 fb303
fb303-devel affected Red Hat:openshift:4.4::el7 fb303-devel
fb303-java affected Red Hat:openshift:4.4::el7 fb303-java
fuse-overlayfs affected Red Hat:openshift:4.4::el7 fuse-overlayfs
fuse-overlayfs-debuginfo affected Red Hat:openshift:4.4::el7 fuse-overlayfs-debuginfo
golang-github-prometheus-promu affected Red Hat:openshift:4.4::el7 golang-github-prometheus-promu
golang-scl-shim affected Red Hat:openshift:4.4::el7 golang-scl-shim
gperftools affected Red Hat:openshift:4.4::el8 gperftools
gperftools-debugsource affected Red Hat:openshift:4.4::el8 gperftools-debugsource
gperftools-devel affected Red Hat:openshift:4.4::el8 gperftools-devel
gperftools-libs affected Red Hat:openshift:4.4::el8 gperftools-libs
gperftools-libs-debuginfo affected Red Hat:openshift:4.4::el8 gperftools-libs-debuginfo
grpc affected Red Hat:openshift:4.4::el8 grpc
grpc-cli affected Red Hat:openshift:4.4::el8 grpc-cli
grpc-cli-debuginfo affected Red Hat:openshift:4.4::el8 grpc-cli-debuginfo
grpc-debuginfo affected Red Hat:openshift:4.4::el8 grpc-debuginfo
grpc-debugsource affected Red Hat:openshift:4.4::el8 grpc-debugsource
grpc-devel affected Red Hat:openshift:4.4::el8 grpc-devel
grpc-plugins affected Red Hat:openshift:4.4::el8 grpc-plugins
grpc-plugins-debuginfo affected Red Hat:openshift:4.4::el8 grpc-plugins-debuginfo
ignition affected Red Hat:openshift:4.4::el8 ignition
ignition-debuginfo affected Red Hat:openshift:4.4::el8 ignition-debuginfo
ignition-debugsource affected Red Hat:openshift:4.4::el8 ignition-debugsource
ignition-validate affected Red Hat:openshift:4.4::el8 ignition-validate
ignition-validate-debuginfo affected Red Hat:openshift:4.4::el8 ignition-validate-debuginfo
inotify-tools affected Red Hat:openshift:4.4::el7 inotify-tools
inotify-tools-debuginfo affected Red Hat:openshift:4.4::el7 inotify-tools-debuginfo
inotify-tools-devel affected Red Hat:openshift:4.4::el7 inotify-tools-devel
iptables affected Red Hat:openshift:4.4::el8 iptables
iptables-arptables affected Red Hat:openshift:4.4::el8 iptables-arptables
iptables-debuginfo affected Red Hat:openshift:4.4::el8 iptables-debuginfo
iptables-debugsource affected Red Hat:openshift:4.4::el8 iptables-debugsource
iptables-devel affected Red Hat:openshift:4.4::el8 iptables-devel
iptables-ebtables affected Red Hat:openshift:4.4::el8 iptables-ebtables
iptables-libs affected Red Hat:openshift:4.4::el8 iptables-libs
iptables-libs-debuginfo affected Red Hat:openshift:4.4::el8 iptables-libs-debuginfo
iptables-services affected Red Hat:openshift:4.4::el8 iptables-services
iptables-utils affected Red Hat:openshift:4.4::el8 iptables-utils
iptables-utils-debuginfo affected Red Hat:openshift:4.4::el8 iptables-utils-debuginfo
ipxe affected Red Hat:openshift:4.4::el8 ipxe
ipxe-bootimgs affected Red Hat:openshift:4.4::el8 ipxe-bootimgs
ipxe-rhcert affected Red Hat:openshift:4.4::el8 ipxe-rhcert
ipxe-roms affected Red Hat:openshift:4.4::el8 ipxe-roms
ipxe-roms-qemu affected Red Hat:openshift:4.4::el8 ipxe-roms-qemu
jenkins affected Red Hat:openshift:4.4::el7 jenkins
jenkins-2-plugins affected Red Hat:openshift:4.4::el7 jenkins-2-plugins
jq affected Red Hat:openshift:4.4::el7 jq
jq-debuginfo affected Red Hat:openshift:4.4::el7 jq-debuginfo
jq-devel affected Red Hat:openshift:4.4::el7 jq-devel
kibana affected Red Hat:openshift:4.4::el7 kibana
kibana-debuginfo affected Red Hat:openshift:4.4::el7 kibana-debuginfo
kuryr-binding-scripts affected Red Hat:openshift:4.4::el8 kuryr-binding-scripts
libnftnl affected Red Hat:openshift:4.4::el8 libnftnl
libnftnl-debuginfo affected Red Hat:openshift:4.4::el8 libnftnl-debuginfo
libnftnl-debugsource affected Red Hat:openshift:4.4::el8 libnftnl-debugsource
libnftnl-devel affected Red Hat:openshift:4.4::el8 libnftnl-devel
libthrift-java affected Red Hat:openshift:4.4::el7 libthrift-java
libthrift-javadoc affected Red Hat:openshift:4.4::el7 libthrift-javadoc
libunwind affected Red Hat:openshift:4.4::el8 libunwind
libunwind-debuginfo affected Red Hat:openshift:4.4::el8 libunwind-debuginfo
libunwind-debugsource affected Red Hat:openshift:4.4::el8 libunwind-debugsource
libunwind-devel affected Red Hat:openshift:4.4::el8 libunwind-devel
machine-config-daemon affected Red Hat:openshift:4.4::el8 machine-config-daemon
mariadb-apb-role affected Red Hat:openshift:4.4::el7 mariadb-apb-role
mysql-apb-role affected Red Hat:openshift:4.4::el7 mysql-apb-role
nss-altfiles affected Red Hat:openshift:4.4::el8 nss-altfiles
nss-altfiles-debuginfo affected Red Hat:openshift:4.4::el8 nss-altfiles-debuginfo
nss-altfiles-debugsource affected Red Hat:openshift:4.4::el8 nss-altfiles-debugsource
oniguruma affected Red Hat:openshift:4.4::el7 oniguruma
oniguruma-debuginfo affected Red Hat:openshift:4.4::el7 oniguruma-debuginfo
oniguruma-devel affected Red Hat:openshift:4.4::el7 oniguruma-devel
openshift affected Red Hat:openshift:4.4::el7 openshift
openshift affected Red Hat:openshift:4.4::el8 openshift
openshift-ansible affected Red Hat:openshift:4.4::el7 openshift-ansible
openshift-ansible-test affected Red Hat:openshift:4.4::el7 openshift-ansible-test
openshift-clients affected Red Hat:openshift:4.4::el8 openshift-clients
openshift-clients affected Red Hat:openshift:4.4::el7 openshift-clients
openshift-clients-redistributable affected Red Hat:openshift:4.4::el7 openshift-clients-redistributable
openshift-clients-redistributable affected Red Hat:openshift:4.4::el8 openshift-clients-redistributable
openshift-eventrouter affected Red Hat:openshift:4.4::el7 openshift-eventrouter
openshift-eventrouter-debuginfo affected Red Hat:openshift:4.4::el7 openshift-eventrouter-debuginfo
openshift-hyperkube affected Red Hat:openshift:4.4::el7 openshift-hyperkube
openshift-hyperkube affected Red Hat:openshift:4.4::el8 openshift-hyperkube
openshift-kuryr affected Red Hat:openshift:4.4::el8 openshift-kuryr
openshift-kuryr affected Red Hat:openshift:4.4::el7 openshift-kuryr
openshift-kuryr-cni affected Red Hat:openshift:4.4::el8 openshift-kuryr-cni
openshift-kuryr-cni affected Red Hat:openshift:4.4::el7 openshift-kuryr-cni
openshift-kuryr-common affected Red Hat:openshift:4.4::el8 openshift-kuryr-common
openshift-kuryr-common affected Red Hat:openshift:4.4::el7 openshift-kuryr-common
openshift-kuryr-controller affected Red Hat:openshift:4.4::el8 openshift-kuryr-controller
openshift-kuryr-controller affected Red Hat:openshift:4.4::el7 openshift-kuryr-controller
openstack-ironic affected Red Hat:openshift:4.4::el8 openstack-ironic
openstack-ironic-api affected Red Hat:openshift:4.4::el8 openstack-ironic-api
openstack-ironic-common affected Red Hat:openshift:4.4::el8 openstack-ironic-common
openstack-ironic-conductor affected Red Hat:openshift:4.4::el8 openstack-ironic-conductor
openstack-ironic-inspector affected Red Hat:openshift:4.4::el8 openstack-ironic-inspector
openstack-ironic-inspector-api affected Red Hat:openshift:4.4::el8 openstack-ironic-inspector-api
openstack-ironic-inspector-conductor affected Red Hat:openshift:4.4::el8 openstack-ironic-inspector-conductor
openstack-ironic-inspector-dnsmasq affected Red Hat:openshift:4.4::el8 openstack-ironic-inspector-dnsmasq
openstack-ironic-python-agent affected Red Hat:openshift:4.4::el8 openstack-ironic-python-agent
ostree affected Red Hat:openshift:4.4::el8 ostree
ostree-debuginfo affected Red Hat:openshift:4.4::el8 ostree-debuginfo
ostree-debugsource affected Red Hat:openshift:4.4::el8 ostree-debugsource
ostree-devel affected Red Hat:openshift:4.4::el8 ostree-devel
ostree-grub2 affected Red Hat:openshift:4.4::el8 ostree-grub2
ostree-libs affected Red Hat:openshift:4.4::el8 ostree-libs
ostree-libs-debuginfo affected Red Hat:openshift:4.4::el8 ostree-libs-debuginfo
ovn2.12 affected Red Hat:openshift:4.4::el7 ovn2.12
ovn2.12-central affected Red Hat:openshift:4.4::el7 ovn2.12-central
ovn2.12-debuginfo affected Red Hat:openshift:4.4::el7 ovn2.12-debuginfo
ovn2.12-host affected Red Hat:openshift:4.4::el7 ovn2.12-host
ovn2.12-vtep affected Red Hat:openshift:4.4::el7 ovn2.12-vtep
perl-thrift affected Red Hat:openshift:4.4::el7 perl-thrift
pivot affected Red Hat:openshift:4.4::el8 pivot
podman affected Red Hat:openshift:4.4::el8 podman
podman-debuginfo affected Red Hat:openshift:4.4::el8 podman-debuginfo
podman-debugsource affected Red Hat:openshift:4.4::el8 podman-debugsource
podman-docker affected Red Hat:openshift:4.4::el8 podman-docker
podman-manpages affected Red Hat:openshift:4.4::el8 podman-manpages
podman-remote affected Red Hat:openshift:4.4::el8 podman-remote
podman-remote-debuginfo affected Red Hat:openshift:4.4::el8 podman-remote-debuginfo
podman-tests affected Red Hat:openshift:4.4::el8 podman-tests
postgresql-apb-role affected Red Hat:openshift:4.4::el7 postgresql-apb-role
pprof affected Red Hat:openshift:4.4::el8 pprof
prometheus-promu affected Red Hat:openshift:4.4::el7 prometheus-promu
protobuf affected Red Hat:openshift:4.4::el8 protobuf
protobuf-compiler affected Red Hat:openshift:4.4::el8 protobuf-compiler
protobuf-compiler-debuginfo affected Red Hat:openshift:4.4::el8 protobuf-compiler-debuginfo
protobuf-debuginfo affected Red Hat:openshift:4.4::el8 protobuf-debuginfo
protobuf-debugsource affected Red Hat:openshift:4.4::el8 protobuf-debugsource
protobuf-devel affected Red Hat:openshift:4.4::el8 protobuf-devel
protobuf-lite affected Red Hat:openshift:4.4::el8 protobuf-lite
protobuf-lite-debuginfo affected Red Hat:openshift:4.4::el8 protobuf-lite-debuginfo
protobuf-lite-devel affected Red Hat:openshift:4.4::el8 protobuf-lite-devel
protobuf-lite-static affected Red Hat:openshift:4.4::el8 protobuf-lite-static
protobuf-static affected Red Hat:openshift:4.4::el8 protobuf-static
protobuf-vim affected Red Hat:openshift:4.4::el8 protobuf-vim
python2-ansible-runner affected Red Hat:openshift:4.4::el7 python2-ansible-runner
python2-boto3 affected Red Hat:openshift:4.4::el7 python2-boto3
python2-botocore affected Red Hat:openshift:4.4::el7 python2-botocore
python2-certifi affected Red Hat:openshift:4.4::el7 python2-certifi
python2-daemon affected Red Hat:openshift:4.4::el7 python2-daemon
python2-dictdiffer affected Red Hat:openshift:4.4::el7 python2-dictdiffer
python2-google-auth affected Red Hat:openshift:4.4::el7 python2-google-auth
python2-kubernetes affected Red Hat:openshift:4.4::el7 python2-kubernetes
python2-kubernetes-tests affected Red Hat:openshift:4.4::el7 python2-kubernetes-tests
python2-kuryr-kubernetes affected Red Hat:openshift:4.4::el7 python2-kuryr-kubernetes
python2-lockfile affected Red Hat:openshift:4.4::el7 python2-lockfile
python2-netaddr affected Red Hat:openshift:4.4::el8 python2-netaddr
python2-openshift affected Red Hat:openshift:4.4::el7 python2-openshift
python2-pexpect affected Red Hat:openshift:4.4::el7 python2-pexpect
python2-psutil affected Red Hat:openshift:4.4::el7 python2-psutil
python2-ptyprocess affected Red Hat:openshift:4.4::el7 python2-ptyprocess
python2-pysocks affected Red Hat:openshift:4.4::el7 python2-pysocks
python2-rsa affected Red Hat:openshift:4.4::el7 python2-rsa
python2-ruamel-ordereddict affected Red Hat:openshift:4.4::el7 python2-ruamel-ordereddict
python2-ruamel-yaml affected Red Hat:openshift:4.4::el7 python2-ruamel-yaml
python2-s3transfer affected Red Hat:openshift:4.4::el7 python2-s3transfer
python2-string_utils affected Red Hat:openshift:4.4::el7 python2-string_utils
python2-typing affected Red Hat:openshift:4.4::el7 python2-typing
python2-urllib3 affected Red Hat:openshift:4.4::el7 python2-urllib3
python2-voluptuous affected Red Hat:openshift:4.4::el7 python2-voluptuous
python3-grpcio affected Red Hat:openshift:4.4::el8 python3-grpcio
python3-grpcio-debuginfo affected Red Hat:openshift:4.4::el8 python3-grpcio-debuginfo
python3-ironic-inspector-tests affected Red Hat:openshift:4.4::el8 python3-ironic-inspector-tests
python3-ironic-python-agent affected Red Hat:openshift:4.4::el8 python3-ironic-python-agent
python3-ironic-tests affected Red Hat:openshift:4.4::el8 python3-ironic-tests
python3-kuryr-kubernetes affected Red Hat:openshift:4.4::el8 python3-kuryr-kubernetes
python3-kuryr-lib affected Red Hat:openshift:4.4::el8 python3-kuryr-lib
python3-kuryr-lib-tests affected Red Hat:openshift:4.4::el8 python3-kuryr-lib-tests
python3-netaddr affected Red Hat:openshift:4.4::el8 python3-netaddr
python3-openstacksdk affected Red Hat:openshift:4.4::el8 python3-openstacksdk
python3-openstacksdk-tests affected Red Hat:openshift:4.4::el8 python3-openstacksdk-tests
python3-protobuf affected Red Hat:openshift:4.4::el8 python3-protobuf
python3-pyroute2 affected Red Hat:openshift:4.4::el8 python3-pyroute2
python3-sushy affected Red Hat:openshift:4.4::el8 python3-sushy
python3-sushy-tests affected Red Hat:openshift:4.4::el8 python3-sushy-tests
python-boto3 affected Red Hat:openshift:4.4::el7 python-boto3
python-botocore affected Red Hat:openshift:4.4::el7 python-botocore
python-cachetools affected Red Hat:openshift:4.4::el7 python-cachetools
python-certifi affected Red Hat:openshift:4.4::el7 python-certifi
python-click affected Red Hat:openshift:4.4::el7 python-click
python-daemon affected Red Hat:openshift:4.4::el7 python-daemon
python-dictdiffer affected Red Hat:openshift:4.4::el7 python-dictdiffer
python-elasticsearch affected Red Hat:openshift:4.4::el7 python-elasticsearch
python-fb303 affected Red Hat:openshift:4.4::el7 python-fb303
python-google-auth affected Red Hat:openshift:4.4::el7 python-google-auth
python-kubernetes affected Red Hat:openshift:4.4::el7 python-kubernetes
python-kuryr-lib affected Red Hat:openshift:4.4::el8 python-kuryr-lib
python-lockfile affected Red Hat:openshift:4.4::el7 python-lockfile
python-netaddr affected Red Hat:openshift:4.4::el8 python-netaddr
python-openshift affected Red Hat:openshift:4.4::el7 python-openshift
python-openstacksdk affected Red Hat:openshift:4.4::el8 python-openstacksdk
python-pexpect affected Red Hat:openshift:4.4::el7 python-pexpect
python-psutil affected Red Hat:openshift:4.4::el7 python-psutil
python-psutil-debuginfo affected Red Hat:openshift:4.4::el7 python-psutil-debuginfo
python-ptyprocess affected Red Hat:openshift:4.4::el7 python-ptyprocess
python-pyroute2 affected Red Hat:openshift:4.4::el8 python-pyroute2
python-pysocks affected Red Hat:openshift:4.4::el7 python-pysocks
python-requests-unixsocket affected Red Hat:openshift:4.4::el7 python-requests-unixsocket
python-rsa affected Red Hat:openshift:4.4::el7 python-rsa
python-ruamel-ordereddict affected Red Hat:openshift:4.4::el7 python-ruamel-ordereddict
python-ruamel-ordereddict-debuginfo affected Red Hat:openshift:4.4::el7 python-ruamel-ordereddict-debuginfo
python-ruamel-yaml affected Red Hat:openshift:4.4::el7 python-ruamel-yaml
python-ruamel-yaml-debuginfo affected Red Hat:openshift:4.4::el7 python-ruamel-yaml-debuginfo
python-s3transfer affected Red Hat:openshift:4.4::el7 python-s3transfer
python-string_utils affected Red Hat:openshift:4.4::el7 python-string_utils
python-sushy affected Red Hat:openshift:4.4::el8 python-sushy
python-thrift affected Red Hat:openshift:4.4::el7 python-thrift
python-typing affected Red Hat:openshift:4.4::el7 python-typing
python-urllib3 affected Red Hat:openshift:4.4::el7 python-urllib3
python-voluptuous affected Red Hat:openshift:4.4::el7 python-voluptuous
redhat-release-coreos affected Red Hat:openshift:4.4::el8 redhat-release-coreos
rhcos-tools affected Red Hat:openshift:4.4::el8 rhcos-tools
rhosp-director-images-ipa-x86_64 affected Red Hat:openshift:4.4::el8 rhosp-director-images-ipa-x86_64
rhosp-director-images-ppc64le affected Red Hat:openshift:4.4::el8 rhosp-director-images-ppc64le
rpm-ostree affected Red Hat:openshift:4.4::el8 rpm-ostree
rpm-ostree-debuginfo affected Red Hat:openshift:4.4::el8 rpm-ostree-debuginfo
rpm-ostree-debugsource affected Red Hat:openshift:4.4::el8 rpm-ostree-debugsource
rpm-ostree-devel affected Red Hat:openshift:4.4::el8 rpm-ostree-devel
rpm-ostree-libs affected Red Hat:openshift:4.4::el8 rpm-ostree-libs
rpm-ostree-libs-debuginfo affected Red Hat:openshift:4.4::el8 rpm-ostree-libs-debuginfo
runc affected Red Hat:openshift:4.4::el8 runc
runc affected Red Hat:openshift:4.4::el7 runc
runc-debuginfo affected Red Hat:openshift:4.4::el7 runc-debuginfo
runc-debuginfo affected Red Hat:openshift:4.4::el8 runc-debuginfo
runc-debugsource affected Red Hat:openshift:4.4::el8 runc-debugsource
rust-afterburn affected Red Hat:openshift:4.4::el8 rust-afterburn
rust-afterburn-debugsource affected Red Hat:openshift:4.4::el8 rust-afterburn-debugsource
skopeo affected Red Hat:openshift:4.4::el8 skopeo
skopeo affected Red Hat:openshift:4.4::el7 skopeo
skopeo-debuginfo affected Red Hat:openshift:4.4::el7 skopeo-debuginfo
skopeo-debuginfo affected Red Hat:openshift:4.4::el8 skopeo-debuginfo
skopeo-debugsource affected Red Hat:openshift:4.4::el8 skopeo-debugsource
skopeo-tests affected Red Hat:openshift:4.4::el7 skopeo-tests
systemd affected Red Hat:openshift:4.4::el8 systemd
systemd-container affected Red Hat:openshift:4.4::el8 systemd-container
systemd-container-debuginfo affected Red Hat:openshift:4.4::el8 systemd-container-debuginfo
systemd-debuginfo affected Red Hat:openshift:4.4::el8 systemd-debuginfo
systemd-debugsource affected Red Hat:openshift:4.4::el8 systemd-debugsource
systemd-devel affected Red Hat:openshift:4.4::el8 systemd-devel
systemd-journal-remote affected Red Hat:openshift:4.4::el8 systemd-journal-remote
systemd-journal-remote-debuginfo affected Red Hat:openshift:4.4::el8 systemd-journal-remote-debuginfo
systemd-libs affected Red Hat:openshift:4.4::el8 systemd-libs
systemd-libs-debuginfo affected Red Hat:openshift:4.4::el8 systemd-libs-debuginfo
systemd-pam affected Red Hat:openshift:4.4::el8 systemd-pam
systemd-pam-debuginfo affected Red Hat:openshift:4.4::el8 systemd-pam-debuginfo
systemd-tests affected Red Hat:openshift:4.4::el8 systemd-tests
systemd-tests-debuginfo affected Red Hat:openshift:4.4::el8 systemd-tests-debuginfo
systemd-udev affected Red Hat:openshift:4.4::el8 systemd-udev
systemd-udev-debuginfo affected Red Hat:openshift:4.4::el8 systemd-udev-debuginfo
thrift affected Red Hat:openshift:4.4::el7 thrift
thrift-debuginfo affected Red Hat:openshift:4.4::el7 thrift-debuginfo
thrift-devel affected Red Hat:openshift:4.4::el7 thrift-devel
thrift-glib affected Red Hat:openshift:4.4::el7 thrift-glib
thrift-qt affected Red Hat:openshift:4.4::el7 thrift-qt
tini affected Red Hat:openshift:4.4::el7 tini
tini-debuginfo affected Red Hat:openshift:4.4::el7 tini-debuginfo
toolbox affected Red Hat:openshift:4.4::el8 toolbox
Upstream advisory

MINI-2jj3-9fx2-c62p

Open SourceCoalition ESS < 30%2026-09-02

MINI-2jj3-9fx2-c62p

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

CVE-2026-87464

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

CVEs:CVE-2026-87464

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-93031

GoogleCoalition ESS < 30%HIGH2026-09-18

The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This is due...

CVEs:CVE-2026-93031

Affected products

ProductStatusVendorPackageEcosystem
Use-your-Drive | Google Drive plugin for WordPress affected WP Cloud Plugins
Upstream advisory

MINI-2424-fjg7-ww67

Open SourceCoalition ESS < 30%2026-09-02

MINI-2424-fjg7-ww67

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

CVE-2026-87438

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

CVEs:CVE-2026-87438

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

MINI-3qfv-7jrv-v7g9

Open SourceCoalition ESS < 30%2026-09-02

MINI-3qfv-7jrv-v7g9

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

CVE-2026-87430

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87430

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87448

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87448

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87474

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-87474

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87512

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-87512

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87488

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Use after free in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

CVEs:CVE-2026-87488

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87527

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

CVEs:CVE-2026-87527

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

MINI-27vm-6cp6-xpff

Open SourceCoalition ESS < 30%2026-09-02

MINI-27vm-6cp6-xpff

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

CVE-2026-87529

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87529

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-21096

Open SourceCoalition ESS < 30%CRITICAL2026-09-09

Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.

CVEs:CVE-2026-21096

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Samsung Mobile Devices affected Samsung Mobile
Upstream advisory

CVE-2026-21095

Open SourceCoalition ESS < 30%CRITICAL2026-09-09

Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.

CVEs:CVE-2026-21095

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Samsung Mobile Devices affected Samsung Mobile
Upstream advisory

MINI-2g5v-gwhw-m3wp

Open SourceCoalition ESS < 30%2026-09-02

MINI-2g5v-gwhw-m3wp

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

CVE-2026-87440

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Out of bounds read in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-87440

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87444

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Memory corruption in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-87444

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

MINI-4fhx-cmh5-72g9

Open SourceCoalition ESS < 30%2026-09-02

MINI-4fhx-cmh5-72g9

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

MINI-37hw-rwxg-33c6

Open SourceCoalition ESS < 30%2026-09-02

MINI-37hw-rwxg-33c6

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

CVE-2026-87547

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity:...

CVEs:CVE-2026-87547

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87579

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87579

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87455

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87455

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87581

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-87581

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87607

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Use after free in Device in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-87607

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87487

GoogleCoalition ESS < 30%HIGH2026-09-09

Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML...

CVEs:CVE-2026-87487

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

MINI-33cf-8hwx-c4g6

Open SourceCoalition ESS < 30%2026-09-02

MINI-33cf-8hwx-c4g6

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

MINI-33r3-985h-r4hg

Open SourceCoalition ESS < 30%2026-09-02

MINI-33r3-985h-r4hg

Affected products

ProductStatusVendorPackageEcosystem
istio-cni-fips-1.26 affected MinimOS istio-cni-fips-1.26
istioctl-fips-1.26 affected MinimOS istioctl-fips-1.26
istio-install-cni-fips-1.26 affected MinimOS istio-install-cni-fips-1.26
istio-pilot-agent-fips-1.26 affected MinimOS istio-pilot-agent-fips-1.26
istio-pilot-discovery-fips-1.26 affected MinimOS istio-pilot-discovery-fips-1.26
Upstream advisory

MINI-2qmw-4xvp-c9gw

Open SourceCoalition ESS < 30%2026-09-02

MINI-2qmw-4xvp-c9gw

Affected products

ProductStatusVendorPackageEcosystem
istio-cni-1.25 affected MinimOS istio-cni-1.25
istioctl-1.25 affected MinimOS istioctl-1.25
istio-install-cni-1.25 affected MinimOS istio-install-cni-1.25
istio-pilot-agent-1.25 affected MinimOS istio-pilot-agent-1.25
istio-pilot-discovery-1.25 affected MinimOS istio-pilot-discovery-1.25
Upstream advisory

MINI-2vwh-rx7m-mfx6

Open SourceCoalition ESS < 30%2026-09-02

MINI-2vwh-rx7m-mfx6

Affected products

ProductStatusVendorPackageEcosystem
istio-cni-1.22 affected MinimOS istio-cni-1.22
istioctl-1.22 affected MinimOS istioctl-1.22
istio-install-cni-1.22 affected MinimOS istio-install-cni-1.22
istio-pilot-agent-1.22 affected MinimOS istio-pilot-agent-1.22
istio-pilot-discovery-1.22 affected MinimOS istio-pilot-discovery-1.22
Upstream advisory

CVE-2026-91709

GoogleCoalition ESS < 30%CRITICAL2026-09-15

Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-91709

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87634

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87634

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87470

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87470

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87643

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Integer overflow in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87643

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87558

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Use after free in Payments in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-87558

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87520

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-87520

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87609

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Use after free in Sharing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)

CVEs:CVE-2026-87609

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87504

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Use after free in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)

CVEs:CVE-2026-87504

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87616

GoogleCoalition ESS < 30%HIGH2026-09-09

Improper initialization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a c...

CVEs:CVE-2026-87616

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

MINI-39gj-qjpf-vr3v

Open SourceCoalition ESS < 30%2026-09-02

MINI-39gj-qjpf-vr3v

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

MINI-47w3-9462-2f6m

Open SourceCoalition ESS < 30%2026-09-02

MINI-47w3-9462-2f6m

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

CVE-2026-56855

GoogleCoalition ESS < 30%HIGH2026-09-02

Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messag...

CVEs:CVE-2026-56855

Affected products

ProductStatusVendorPackageEcosystem
crypto affected golang
Upstream advisory

MINI-2358-r23m-r9hj

Open SourceCoalition ESS < 30%2026-09-02

MINI-2358-r23m-r9hj

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

MINI-2hwm-c6mm-xr59

Open SourceCoalition ESS < 30%2026-09-02

MINI-2hwm-c6mm-xr59

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

CVE-2026-87510

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Improper input validation in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severi...

CVEs:CVE-2026-87510

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87553

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Improper input validation in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security ...

CVEs:CVE-2026-87553

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87639

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-87639

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87617

GoogleCoalition ESS < 30%HIGH2026-09-09

Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87617

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87526

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Use after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Medium)

CVEs:CVE-2026-87526

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-55366

Open SourceCoalition ESS < 30%CRITICAL2026-09-15

In IP Multimedia Subsystem, there is a possible authentication bypass due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-55366

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-87654

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-87654

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87431

GoogleCoalition ESS < 30%HIGH2026-09-09

Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium)

CVEs:CVE-2026-87431

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87646

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-87646

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87582

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: M...

CVEs:CVE-2026-87582

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87481

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Incorrect authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium sec...

CVEs:CVE-2026-87481

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87613

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)

CVEs:CVE-2026-87613

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87478

GoogleCoalition ESS < 30%HIGH2026-09-09

Observable discrepancy in Autofill in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87478

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87528

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Type confusion in Rust in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87528

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87479

GoogleCoalition ESS < 30%HIGH2026-09-09

Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a cr...

CVEs:CVE-2026-87479

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87480

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Use after free in Printing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-87480

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87524

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Use after free in Core in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severi...

CVEs:CVE-2026-87524

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87471

GoogleCoalition ESS < 30%HIGH2026-09-09

Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87471

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

MINI-3gv2-w59c-mv6c

Open SourceCoalition ESS < 30%2026-09-02

MINI-3gv2-w59c-mv6c

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

CVE-2026-87494

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Use after free in Browser in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87494

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87500

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Improper validation of array index in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-87500

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87443

GoogleCoalition ESS < 30%HIGH2026-09-09

Missing authorization in Actor in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87443

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87436

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Incomplete cleanup in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Medium)

CVEs:CVE-2026-87436

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87446

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Incomplete cleanup in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)

CVEs:CVE-2026-87446

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

MINI-2chc-rpqc-4vw9

Open SourceCoalition ESS < 30%2026-09-02

MINI-2chc-rpqc-4vw9

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

CVE-2026-85047

GoogleCoalition ESS < 30%CRITICAL2026-09-03

Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-85047

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-85042

GoogleCoalition ESS < 30%CRITICAL2026-09-03

Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-85042

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-85050

GoogleCoalition ESS < 30%CRITICAL2026-09-03

Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-85050

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-85043

GoogleCoalition ESS < 30%CRITICAL2026-09-03

Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: High)

CVEs:CVE-2026-85043

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

MINI-4h74-jwm9-vjwg

Open SourceCoalition ESS < 30%2026-09-01

MINI-4h74-jwm9-vjwg

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-1.37 affected MinimOS kube-apiserver-1.37
kube-controller-manager-1.37 affected MinimOS kube-controller-manager-1.37
kubelet-1.37 affected MinimOS kubelet-1.37
kube-proxy-1.37 affected MinimOS kube-proxy-1.37
kube-scheduler-1.37 affected MinimOS kube-scheduler-1.37
Upstream advisory

CVE-2026-87621

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Out of bounds write in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-87621

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87618

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Incorrect reference resolution in Storage in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chrom...

CVEs:CVE-2026-87618

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87549

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Incomplete cleanup in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87549

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-85051

GoogleCoalition ESS < 30%CRITICAL2026-09-03

Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-85051

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87612

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-87612

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87638

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Out of bounds write in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87638

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87637

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Use after free in Extensions in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87637

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87650

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-87650

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-21092

Open SourceCoalition ESS < 30%HIGH2026-09-09

Path traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attackers to create image files with system server privilege.

CVEs:CVE-2026-21092

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2026-78662

Open SourceCoalition ESS < 30%HIGH2026-09-02

Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel...

CVEs:CVE-2026-78662

Affected products

ProductStatusVendorPackageEcosystem
crypto affected golang
golang.org/x/crypto/ssh affected golang.org/x/crypto
Upstream advisory

MINI-3w83-893w-pqx5

Open SourceCoalition ESS < 30%2026-09-02

MINI-3w83-893w-pqx5

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

MINI-3rmp-75gw-jff6

Open SourceCoalition ESS < 30%2026-09-02

MINI-3rmp-75gw-jff6

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

MINI-462v-9mwr-jww9

Open SourceCoalition ESS < 30%2026-09-02

MINI-462v-9mwr-jww9

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

CVE-2026-87595

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Server-side request forgery in Mobile in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87595

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87435

GoogleCoalition ESS < 30%HIGH2026-09-09

Information leak in ControlledFrame in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87435

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87439

GoogleCoalition ESS < 30%HIGH2026-09-09

Information leak in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87439

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

MINI-3ggf-hfhv-rr5w

Open SourceCoalition ESS < 30%2026-09-02

MINI-3ggf-hfhv-rr5w

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

CVE-2026-91711

GoogleCoalition ESS < 30%CRITICAL2026-09-15

Out of bounds write in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-91711

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-91710

GoogleCoalition ESS < 30%CRITICAL2026-09-15

Use after free in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-91710

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87555

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Uninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87555

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87636

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Type confusion in XML in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87636

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87572

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Injection in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-87572

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87450

GoogleCoalition ESS < 30%HIGH2026-09-09

Incorrect authorization in Permissions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium)

CVEs:CVE-2026-87450

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87429

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Missing authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87429

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

MINI-4mrj-qc9m-2958

Open SourceCoalition ESS < 30%2026-09-02

MINI-4mrj-qc9m-2958

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

CVE-2026-87590

GoogleCoalition ESS < 30%HIGH2026-09-09

Improper input validation in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially leak sensitive information via crafted network traffic. (Chromium security severity: Medium)

CVEs:CVE-2026-87590

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87588

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Use after free in Chromecast in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87588

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87536

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-87536

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87587

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-87587

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87460

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Use after free in Platform in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-87460

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87542

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Use after free in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-87542

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

MINI-2rcx-x3cw-8fm4

Open SourceCoalition ESS < 30%2026-09-02

MINI-2rcx-x3cw-8fm4

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

MINI-44jp-39jh-2x59

Open SourceCoalition ESS < 30%2026-09-02

MINI-44jp-39jh-2x59

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

MINI-48rr-qx9q-c47h

Open SourceCoalition ESS < 30%2026-09-02

MINI-48rr-qx9q-c47h

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

MINI-4p33-m7jg-wm58

Open SourceCoalition ESS < 30%2026-09-02

MINI-4p33-m7jg-wm58

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

CVE-2026-87537

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security sev...

CVEs:CVE-2026-87537

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

MINI-4gxw-vx62-cxf9

Open SourceCoalition ESS < 30%2026-09-02

MINI-4gxw-vx62-cxf9

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

CVE-2026-87565

GoogleCoalition ESS < 30%HIGH2026-09-09

Information leak in Passwords in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87565

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87522

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially bypass system access restrictions via crafted network traffic. (Chromium security severity: Low)

CVEs:CVE-2026-87522

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87433

GoogleCoalition ESS < 30%HIGH2026-09-09

Race condition in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87433

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87506

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Privilege elevation in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87506

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87604

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-87604

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-85049

GoogleCoalition ESS < 30%CRITICAL2026-09-03

Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-85049

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-28666

Open SourceCoalition ESS < 30%HIGH2026-09-08

In multiple functions of LocalImageResolver.java, there is a possible Remote Persistent Denial of Service due to a DNG image rendering check bypass. This could lead to remote escalation of privilege with no additional execution privileges needed. User ...

CVEs:CVE-2026-28666

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-85053

GoogleCoalition ESS < 30%CRITICAL2026-09-03

Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-85053

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87437

GoogleCoalition ESS < 30%HIGH2026-09-09

Information leak in Frames in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87437

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87477

GoogleCoalition ESS < 30%HIGH2026-09-09

Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87477

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

MINI-2jw2-g998-8xm3

Open SourceCoalition ESS < 30%2026-09-02

MINI-2jw2-g998-8xm3

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

CVE-2026-28606

Open SourceCoalition ESS < 30%CRITICAL2026-09-08

In handleBondStateChanged of AdapterService.java, there is a possible way to skip pairing due to a logic error in the code. This could lead to remote escalation of privilege without user consent with no additional execution privileges needed. User inte...

CVEs:CVE-2026-28606

Affected products

ProductStatusVendorPackageEcosystem
android affected google
android affected google
Android affected Google
Upstream advisory

MINI-497j-gjmp-q66w

Open SourceCoalition ESS < 30%2026-09-02

MINI-497j-gjmp-q66w

Affected products

ProductStatusVendorPackageEcosystem
google-cloud-sdk-core affected MinimOS google-cloud-sdk-core
Upstream advisory

CVE-2026-87513

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Missing authorization in ControlledFrame in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87513

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-56920

Open SourceCoalition ESS < 30%HIGH2026-09-15

In s_decode_vui_param of fw_hevc_dec_header.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2026-56920

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-56882

Open SourceCoalition ESS < 30%HIGH2026-09-15

In Cellular Modem, there is a possible information disclosure due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-56882

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-87556

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Missing authorization in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87556

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-0200

Open SourceCoalition ESS < 30%HIGH2026-09-15

In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-0200

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-87585

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)

CVEs:CVE-2026-87585

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-14989

GoogleCoalition ESS < 30%HIGH2026-09-09

The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpl_user_preference' parameter in all versions up to, and including, 4.4.1 due to insufficient input sanitization and o...

CVEs:CVE-2026-14989

Affected products

ProductStatusVendorPackageEcosystem
WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode (WordPress plugin gdpr-cookie-consent) affected wplegalpages
Upstream advisory

CVE-2026-87476

GoogleCoalition ESS < 30%HIGH2026-09-09

Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87476

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87447

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: High)

CVEs:CVE-2026-87447

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-58710

Open SourceCoalition ESS < 30%HIGH2026-09-15

In DecodeFilmGrainParams of film_grain_dec.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-58710

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-58683

Open SourceCoalition ESS < 30%HIGH2026-09-15

In IP Multimedia Subsystem, there is a possible out-of-bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-58683

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-56997

Open SourceCoalition ESS < 30%HIGH2026-09-15

In Av1DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2026-56997

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-56974

Open SourceCoalition ESS < 30%HIGH2026-09-15

In Start of AudioRtpPayloadEncoderNode.cpp, there is a possible out-of-bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.

CVEs:CVE-2026-56974

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-87548

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Improper state validation in Installer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87548

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-28609

Open SourceCoalition ESS < 30%HIGH2026-09-08

In read of MatroskaExtractor.cpp, there is a possible out-of-bounds write due to improper casting. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-28609

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-87648

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security sever...

CVEs:CVE-2026-87648

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

MINI-2v89-w5ff-r5q7

Open SourceCoalition ESS < 30%2026-09-02

MINI-2v89-w5ff-r5q7

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

CVE-2026-87600

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Improper input validation in Safebrowsing in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87600

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-56942

Open SourceCoalition ESS < 30%HIGH2026-09-15

In ReadTileInfo of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-56942

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-55331

Open SourceCoalition ESS < 30%HIGH2026-09-15

In IP Multimedia Subsystem, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-55331

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-0170

Open SourceCoalition ESS < 30%HIGH2026-09-15

In Vp9DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2026-0170

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

MINI-277g-26v9-89h6

Open SourceCoalition ESS < 30%2026-09-02

MINI-277g-26v9-89h6

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

CVE-2026-19778

GoogleCoalition ESS < 30%HIGH2026-09-09

The WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & Shopping plugin for WordPress is vulnerable to time-based SQL Injection via the 'feed' parameter in all versions up to, and including, 2.23.7 due to insufficient escaping...

CVEs:CVE-2026-19778

Affected products

ProductStatusVendorPackageEcosystem
WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & Shopping affected aukejomm
Upstream advisory

CVE-2026-87442

GoogleCoalition ESS < 30%LOW2026-09-09

Confused deputy in Prerender in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87442

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87434

GoogleCoalition ESS < 30%LOW2026-09-09

Missing authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87434

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-55306

Open SourceCoalition ESS < 30%HIGH2026-09-15

In Cellular Modem, there is a possible denial of service due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-55306

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-87625

GoogleCoalition ESS < 30%HIGH2026-09-09

Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)

CVEs:CVE-2026-87625

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

MINI-34gm-3qp3-rwmp

Open SourceCoalition ESS < 30%2026-09-02

MINI-34gm-3qp3-rwmp

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

CVE-2026-87644

GoogleCoalition ESS < 30%HIGH2026-09-09

Incorrect authorization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a c...

CVEs:CVE-2026-87644

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87564

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-87564

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

MINI-4hww-g47f-4hgw

Open SourceCoalition ESS < 30%2026-09-02

MINI-4hww-g47f-4hgw

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

CVE-2026-87441

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Missing authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)

CVEs:CVE-2026-87441

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87472

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Improper input validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87472

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87445

GoogleCoalition ESS < 30%MEDIUM2026-09-09

UI misrepresentation in Session in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87445

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87473

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Incorrect authorization in FileHandling in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87473

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-57008

Open SourceCoalition ESS < 30%HIGH2026-09-15

In Modem, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-57008

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-87535

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Information loss or omission in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87535

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87518

GoogleCoalition ESS < 30%HIGH2026-09-09

Observable discrepancy in Safebrowsing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially obtain sensitive information via a crafted HTML page. (Chromium security severity...

CVEs:CVE-2026-87518

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87466

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Incorrect authorization in Workers in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87466

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87453

GoogleCoalition ESS < 30%HIGH2026-09-09

Confused deputy in BackgroundFetch in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87453

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

MINI-3ghc-c3m8-8hxg

Open SourceCoalition ESS < 30%2026-09-02

MINI-3ghc-c3m8-8hxg

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

CVE-2026-87503

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Inappropriate implementation in Downloads in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87503

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87519

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Incorrect authorization in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87519

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87642

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Uninitialized resource in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87642

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-45527

Open SourceCoalition ESS < 30%HIGH2026-09-08

In convertCleanApertureToRect of HeifCleanAperture.cpp, there is a possible way to cause a temporary denial of service due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interact...

CVEs:CVE-2026-45527

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-87483

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Incorrect authorization in Browser in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87483

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87541

GoogleCoalition ESS < 30%HIGH2026-09-09

Information leak in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87541

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87629

GoogleCoalition ESS < 30%HIGH2026-09-09

Incorrect authorization in Sources in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87629

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87545

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Information leak in Mobile in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87545

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87459

GoogleCoalition ESS < 30%HIGH2026-09-09

Observable discrepancy in Select in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87459

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87454

GoogleCoalition ESS < 30%HIGH2026-09-09

Information leak in Enterprise in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87454

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87508

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87508

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87626

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Incorrect authorization in DeviceBoundSessionCredentials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via crafted network traffic. (Chromium security severity: Medium)

CVEs:CVE-2026-87626

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87569

GoogleCoalition ESS < 30%HIGH2026-09-09

Missing authorization in Views in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-87569

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87574

GoogleCoalition ESS < 30%HIGH2026-09-09

Information leak in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87574

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87591

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)

CVEs:CVE-2026-87591

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87550

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Improper encoding or escaping of output in CSS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87550

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-4657

GoogleCoalition ESS < 30%HIGH2026-09-10

The Easy Google Fonts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the control_selectors meta field in all versions up to, and including, 2.0.4. This is due to the plugin registering the control_selectors meta field with show_i...

CVEs:CVE-2026-4657

Affected products

ProductStatusVendorPackageEcosystem
Easy Google Fonts affected sunny_johal
Upstream advisory

CVE-2026-87458

GoogleCoalition ESS < 30%MEDIUM2026-09-09

UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87458

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87499

GoogleCoalition ESS < 30%HIGH2026-09-09

Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-87499

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87620

GoogleCoalition ESS < 30%HIGH2026-09-09

Observable discrepancy in SVG in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87620

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87623

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Observable discrepancy in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87623

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87432

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Incorrect authorization in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87432

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87475

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Missing authorization in Omnibox in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87475

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87456

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Uninitialized resource in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87456

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87515

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Incorrect authorization in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87515

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87516

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Observable discrepancy in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87516

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

MINI-2mw3-rwhq-xxj2

Open SourceCoalition ESS < 30%2026-09-02

MINI-2mw3-rwhq-xxj2

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

CVE-2026-87489

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Memory corruption in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)

CVEs:CVE-2026-87489

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87632

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Cross-site scripting in SanitizerAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87632

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87507

GoogleCoalition ESS < 30%MEDIUM2026-09-09

UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87507

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

MINI-24x2-qpgw-pr73

Open SourceCoalition ESS < 30%2026-09-02

MINI-24x2-qpgw-pr73

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

CVE-2026-85044

GoogleCoalition ESS < 30%HIGH2026-09-03

Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-85044

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87570

GoogleCoalition ESS < 30%HIGH2026-09-09

Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted file. (Chromium security severit...

CVEs:CVE-2026-87570

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87630

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Integer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87630

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87635

GoogleCoalition ESS < 30%MEDIUM2026-09-09

UI misrepresentation in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87635

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87496

GoogleCoalition ESS < 30%MEDIUM2026-09-09

UI misrepresentation in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87496

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87631

GoogleCoalition ESS < 30%HIGH2026-09-09

Missing authorization in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87631

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87485

GoogleCoalition ESS < 30%LOW2026-09-09

Incorrect authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87485

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87557

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Missing authorization in LocalNetworkAccess in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87557

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87566

GoogleCoalition ESS < 30%HIGH2026-09-09

Observable discrepancy in Layout in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87566

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87652

GoogleCoalition ESS < 30%LOW2026-09-09

Incorrect authorization in PushAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87652

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87610

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Incorrect authorization in Omnibox in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87610

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87451

GoogleCoalition ESS < 30%HIGH2026-09-09

Information leak in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87451

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87603

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87603

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87523

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Race condition in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87523

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87484

GoogleCoalition ESS < 30%MEDIUM2026-09-09

UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87484

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87539

GoogleCoalition ESS < 30%LOW2026-09-09

Observable discrepancy in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87539

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87534

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)

CVEs:CVE-2026-87534

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87584

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87584

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87580

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Incorrect authorization in WebAppInstalls in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. (Chromium security s...

CVEs:CVE-2026-87580

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-55343

Open SourceCoalition ESS < 30%HIGH2026-09-15

In decodeAmr of ImsMediaAudioPlayer.cpp, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.

CVEs:CVE-2026-55343

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-87594

GoogleCoalition ESS < 30%HIGH2026-09-09

Incorrect authorization in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87594

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87598

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87598

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87532

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87532

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-28627

Open SourceCoalition ESS < 30%HIGH2026-09-08

In btm_sec_encrypt_change of btm_sec.cc, there is a possible downgrade attack due to a logic error in the code. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2026-28627

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-87511

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Missing authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Low)

CVEs:CVE-2026-87511

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87452

GoogleCoalition ESS < 30%LOW2026-09-09

Incorrect authorization in GPU in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87452

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87521

GoogleCoalition ESS < 30%HIGH2026-09-09

Information leak in WebMCP in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87521

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87597

GoogleCoalition ESS < 30%MEDIUM2026-09-09

UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to spoof address bar via a co-installed app. (Chromium security severity: Low)

CVEs:CVE-2026-87597

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87573

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Improper input validation in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87573

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87449

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Cross-site request forgery in DeviceBoundSessionCredentials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87449

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87593

GoogleCoalition ESS < 30%HIGH2026-09-09

Information leak in Editing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87593

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87608

GoogleCoalition ESS < 30%HIGH2026-09-09

Improper certificate validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)

CVEs:CVE-2026-87608

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87490

GoogleCoalition ESS < 30%HIGH2026-09-09

Information leak in Transactions Platform in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87490

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87505

GoogleCoalition ESS < 30%HIGH2026-09-09

Incorrect authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: Medium)

CVEs:CVE-2026-87505

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-28604

Open SourceCoalition ESS < 30%HIGH2026-09-08

In multiple locations, there is a possible use after free due to a race condition. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-28604

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2026-87561

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Incorrect authorization in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Low)

CVEs:CVE-2026-87561

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87640

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Out of bounds read in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87640

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87544

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87544

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87546

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Incorrect type conversion or cast in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted file. (Chromium security severity: Low)

CVEs:CVE-2026-87546

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87497

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Uninitialized resource in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87497

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87538

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Clickjacking in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87538

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87622

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Missing authorization in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87622

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87559

GoogleCoalition ESS < 30%MEDIUM2026-09-09

UI misrepresentation in UI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87559

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87468

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87468

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87493

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87493

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87589

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87589

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87592

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Out of bounds read in Tint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87592

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87495

GoogleCoalition ESS < 30%HIGH2026-09-09

Information leak in Scroll in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87495

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87627

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Interpretation conflict in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted file. (Chromium security severity: Low)

CVEs:CVE-2026-87627

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87560

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Missing authorization in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87560

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87462

GoogleCoalition ESS < 30%MEDIUM2026-09-09

UI misrepresentation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87462

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87577

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87577

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87576

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Uninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87576

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87619

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Observable discrepancy in Prefetch in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87619

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87614

GoogleCoalition ESS < 30%LOW2026-09-09

Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87614

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87498

GoogleCoalition ESS < 30%LOW2026-09-09

Missing authorization in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-87498

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87543

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Missing authorization in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87543

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87586

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87586

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87596

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-87596

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87653

GoogleCoalition ESS < 30%MEDIUM2026-09-09

UI misrepresentation in FullScreen in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87653

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87562

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Incorrect reference resolution in Accessibility in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87562

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87647

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Uninitialized resource in GPU in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-87647

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87501

GoogleCoalition ESS < 30%MEDIUM2026-09-09

UI misrepresentation in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87501

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87599

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Improper input validation in Interstitials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87599

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87651

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Incorrect authorization in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-87651

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87601

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Race condition in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87601

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87655

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Clickjacking in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87655

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-85052

GoogleCoalition ESS < 30%HIGH2026-09-03

Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-85052

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87658

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Information leak in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)

CVEs:CVE-2026-87658

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87469

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Improper input validation in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy into a privileged page via crafted network traffic. (Chromium security severity: Low)

CVEs:CVE-2026-87469

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87531

GoogleCoalition ESS < 30%HIGH2026-09-09

Information leak in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87531

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

MINI-364r-896p-9p4m

Open SourceCoalition ESS < 30%2026-09-02

MINI-364r-896p-9p4m

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

CVE-2026-21103

Open SourceCoalition ESS < 30%HIGH2026-09-09

Path traversal in GalaxyDiagnostics prior to SMR Sep-2026 Release 1 allows physical attackers to access files with system privilege.

CVEs:CVE-2026-21103

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2026-87540

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87540

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87482

GoogleCoalition ESS < 30%HIGH2026-09-09

Cleartext transmission of sensitive data in HttpsUpgrades in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via crafted network traffic. (Chromium security severity: Medium)

CVEs:CVE-2026-87482

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87605

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Missing authorization in Contacts in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially obtain sensitive information via a crafted HTML page. (Chromium...

CVEs:CVE-2026-87605

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87517

GoogleCoalition ESS < 30%LOW2026-09-09

Race condition in Mobile in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-87517

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87657

GoogleCoalition ESS < 30%CRITICAL2026-09-09

Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87657

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87611

GoogleCoalition ESS < 30%LOW2026-09-09

Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87611

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87656

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87656

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87602

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Out of bounds read in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87602

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87502

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Confused deputy in Fullscreen in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87502

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87465

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Incorrect authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87465

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87628

GoogleCoalition ESS < 30%HIGH2026-09-09

Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Critical)

CVEs:CVE-2026-87628

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87649

GoogleCoalition ESS < 30%MEDIUM2026-09-09

UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87649

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87645

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87645

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87583

GoogleCoalition ESS < 30%MEDIUM2026-09-09

UI misrepresentation in Passwords in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87583

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-21094

Open SourceCoalition ESS < 30%HIGH2026-09-09

Improper input validation in wpa_supplicant prior to SMR Sep-2026 Release 1 allows adjacent attackers to write out-of-bounds memory.

CVEs:CVE-2026-21094

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2026-87563

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Origin validation error in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87563

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-91708

GoogleCoalition ESS < 30%LOW2026-09-15

Race condition in Network in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-91708

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87633

GoogleCoalition ESS < 30%HIGH2026-09-09

Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)

CVEs:CVE-2026-87633

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87463

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Incorrect authorization in Certificate in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to potentially spoof address bar via crafted network traffic. (Chromium security severity: Low)

CVEs:CVE-2026-87463

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87461

GoogleCoalition ESS < 30%HIGH2026-09-09

Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted Chrome extension. (Chromium security severity: Low)

CVEs:CVE-2026-87461

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87568

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Improper input validation in Chromium in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via crafted network traffic. (Chromium security severity: Low)

CVEs:CVE-2026-87568

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87567

GoogleCoalition ESS < 30%MEDIUM2026-09-09

UI misrepresentation in UrlFormatting in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof address bar via a crafted domain name. (Chromium security severity: Medium)

CVEs:CVE-2026-87567

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-84127

Open SourceCoalition ESS < 30%HIGH2026-09-01

Information disclosure in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 155.

CVEs:CVE-2026-84127

Affected products

ProductStatusVendorPackageEcosystem
Firefox for Android affected Mozilla
firefox_mobile affected mozilla
Upstream advisory

CVE-2026-87551

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Improper certificate validation in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)

CVEs:CVE-2026-87551

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87615

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Race condition in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87615

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87624

GoogleCoalition ESS < 30%MEDIUM2026-09-09

UI misrepresentation in Passwords in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-87624

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87641

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Race condition in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-87641

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87530

GoogleCoalition ESS < 30%HIGH2026-09-09

Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)

CVEs:CVE-2026-87530

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-28659

Open SourceCoalition ESS < 30%CRITICAL2026-09-08

In MicroXR Blobstore, there is a possible way to access other app's files due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-28659

Affected products

ProductStatusVendorPackageEcosystem
android_xr affected google
Upstream advisory

CVE-2026-87578

GoogleCoalition ESS < 30%HIGH2026-09-09

Use after free in Receiver in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)

CVEs:CVE-2026-87578

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-21097

Open SourceCoalition ESS < 30%MEDIUM2026-09-09

Improper authentication in ActivityTaskManagerService prior to SMR Sep-2026 Release 1 allows local privileged attackers to launch arbitrary activity.

CVEs:CVE-2026-21097

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2026-87486

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Clickjacking in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to spoof address bar via a co-installed app. (Chromium security severity: Medium)

CVEs:CVE-2026-87486

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87514

GoogleCoalition ESS < 30%HIGH2026-09-09

Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)

CVEs:CVE-2026-87514

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-49883

Open SourceCoalition ESS < 30%CRITICAL2026-09-08

In checkReadPermission of PermissionsManager.java, there is a possible way to monitor sensitive device state data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User in...

CVEs:CVE-2026-49883

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android Wear affected Google
Upstream advisory

CVE-2026-56967

Open SourceCoalition ESS < 30%HIGH2026-09-15

In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-56967

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-21102

Open SourceCoalition ESS < 30%CRITICAL2026-09-09

Use after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code with root privilege.

CVEs:CVE-2026-21102

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Samsung Mobile Devices affected Samsung Mobile
Upstream advisory

CVE-2026-21101

Open SourceCoalition ESS < 30%HIGH2026-09-09

Improper input validation in DualDAR driver prior to SMR Sep-2026 Release 1 allows local privileged attackers to potentially execute arbitrary code with root privilege.

CVEs:CVE-2026-21101

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2026-21087

Open SourceCoalition ESS < 30%HIGH2026-09-09

Out-of-bounds write in libmdnie.so prior to SMR Sep-2026 Release 1 allows local attackers to execute arbitrary code with system server privilege.

CVEs:CVE-2026-21087

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Samsung Mobile Devices affected Samsung Mobile
Upstream advisory

CVE-2026-87552

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Missing authorization in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: High)

CVEs:CVE-2026-87552

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-21088

Open SourceCoalition ESS < 30%HIGH2026-09-09

Improper input validation in loading a subtitle frame in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

CVEs:CVE-2026-21088

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

MINI-2ffg-q5pj-p6j3

Open SourceCoalition ESS < 30%2026-09-02

MINI-2ffg-q5pj-p6j3

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

CVE-2026-87571

GoogleCoalition ESS < 30%MEDIUM2026-09-09

Improper certificate validation in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)

CVEs:CVE-2026-87571

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-87533

GoogleCoalition ESS < 30%HIGH2026-09-09

Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)

CVEs:CVE-2026-87533

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-21085

Open SourceCoalition ESS < 30%HIGH2026-09-09

Out-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.

CVEs:CVE-2026-21085

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Samsung Mobile Devices affected Samsung
Upstream advisory

CVE-2026-21089

Open SourceCoalition ESS < 30%HIGH2026-09-09

Improper input validation in removing style tag in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

CVEs:CVE-2026-21089

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2026-21091

Open SourceCoalition ESS < 30%HIGH2026-09-09

Out-of-bounds write in libcodec2secevrcdec.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

CVEs:CVE-2026-21091

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2026-21090

Open SourceCoalition ESS < 30%HIGH2026-09-09

Out-of-bounds write in libsaviextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

CVEs:CVE-2026-21090

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2026-87509

GoogleCoalition ESS < 30%HIGH2026-09-09

Incorrect authorization in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Low)

CVEs:CVE-2026-87509

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-56975

Open SourceCoalition ESS < 30%MEDIUM2026-09-15

In Cellular Modem, there is a possible denial of service due to improper input validation. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-56975

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-87525

GoogleCoalition ESS < 30%LOW2026-09-09

Out of bounds read in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to read memory outside the sandbox via a local program. (Chromium security severity: High)

CVEs:CVE-2026-87525

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-57012

Open SourceCoalition ESS < 30%HIGH2026-09-15

In the Setup Wizard, there is a possible remote package install due to a missing permission check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-57012

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-58767

Open SourceCoalition ESS < 30%MEDIUM2026-09-15

In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2026-58767

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2026-21104

Open SourceCoalition ESS < 30%HIGH2026-09-09

Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code.

CVEs:CVE-2026-21104

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Samsung Mobile Devices affected Samsung Mobile
Upstream advisory

CVE-2026-49919

Open SourceCoalition ESS < 30%HIGH2026-09-08

In tt_face_colr_blend_layer of ttcolr.c, there is a possible remote code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2026-49919

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-21093

Open SourceCoalition ESS < 30%HIGH2026-09-09

Stack-based buffer overflow in PROCA trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.

CVEs:CVE-2026-21093

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2026-21100

Open SourceCoalition ESS < 30%HIGH2026-09-09

Improper access control in SystemUI prior to SMR Sep-2026 Release 1 allows local attackers to launch arbitrary activity.

CVEs:CVE-2026-21100

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2026-21099

Open SourceCoalition ESS < 30%MEDIUM2026-09-09

Improper access control in SettingsProvider prior to SMR Sep-2026 Release 1 allows local attackers to access sensitive information.

CVEs:CVE-2026-21099

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2026-87554

GoogleCoalition ESS < 30%HIGH2026-09-09

Race condition in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)

CVEs:CVE-2026-87554

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-49895

Open SourceCoalition ESS < 30%MEDIUM2026-09-08

In get_eht_operation_channel_width of ieee802_11_common.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. Use...

CVEs:CVE-2026-49895

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-56881

Open SourceCoalition ESS < 30%HIGH2026-09-15

In enable_segment of remap.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-56881

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-58679

Open SourceCoalition ESS < 30%HIGH2026-09-15

In gf_ta_test_set_config of gf_ta_test.c, there is a possible heap buffer overflow due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2026-58679

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-28664

Open SourceCoalition ESS < 30%HIGH2026-09-08

In WriteImageToDisk of runtime_image.cc, there is a possible file tampering due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-28664

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-28650

Open SourceCoalition ESS < 30%HIGH2026-09-08

In setHiddenWhileSuspended of WindowState.java, there is a possible overlay bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2026-28650

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-28599

Open SourceCoalition ESS < 30%HIGH2026-09-08

In addCreatorToken of ActivityManagerService.java, there is a possible Intent Redirection Bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ...

CVEs:CVE-2026-28599

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-56941

Open SourceCoalition ESS < 30%HIGH2026-09-15

In multiple functions of fpc_tee_hal.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-56941

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-45531

Open SourceCoalition ESS < 30%HIGH2026-09-08

In read_boot_region of fsck.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-45531

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-58726

Open SourceCoalition ESS < 30%MEDIUM2026-09-15

In FsmReleaseKey of fsm.c, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-58726

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-56979

Open SourceCoalition ESS < 30%MEDIUM2026-09-15

In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-56979

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2026-87457

GoogleCoalition ESS < 30%HIGH2026-09-09

Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)

CVEs:CVE-2026-87457

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-87467

GoogleCoalition ESS < 30%HIGH2026-09-09

Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)

CVEs:CVE-2026-87467

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-58755

Open SourceCoalition ESS < 30%MEDIUM2026-09-15

In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2026-58755

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-58751

Open SourceCoalition ESS < 30%HIGH2026-09-15

In multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-58751

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-58691

Open SourceCoalition ESS < 30%HIGH2026-09-15

In FsmReleaseKey of fsm.c, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-58691

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-56982

Open SourceCoalition ESS < 30%HIGH2026-09-15

In VPU, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-56982

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-56973

Open SourceCoalition ESS < 30%MEDIUM2026-09-15

In multiple locations, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-56973

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2026-56970

Open SourceCoalition ESS < 30%HIGH2026-09-15

In multiple locations, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-56970

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2026-55304

Open SourceCoalition ESS < 30%MEDIUM2026-09-15

In addr_remap_address_map of remap.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-55304

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-28612

Open SourceCoalition ESS < 30%HIGH2026-09-08

In resolveActivity of ActivityStarter.java, there is a possible way to perform Intent Redirection attacks due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...

CVEs:CVE-2026-28612

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-28593

Open SourceCoalition ESS < 30%HIGH2026-09-08

In getItemList of SettingsFragment.java, there is a possible user interaction bypass due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed f...

CVEs:CVE-2026-28593

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-58765

Open SourceCoalition ESS < 30%MEDIUM2026-09-15

In GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-58765

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2026-58747

Open SourceCoalition ESS < 30%MEDIUM2026-09-15

In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-58747

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-58699

Open SourceCoalition ESS < 30%HIGH2026-09-15

In Vp9DecEndOfStream of vp9hwd_output.cc, there is a possible out-of-bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2026-58699

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-58678

Open SourceCoalition ESS < 30%HIGH2026-09-15

In Bootloader, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-58678

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-57006

Open SourceCoalition ESS < 30%MEDIUM2026-09-15

In acfw_ffa.c, there is a possible secret read due to a logic error in the code. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-57006

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-56978

Open SourceCoalition ESS < 30%HIGH2026-09-15

In get_global_config_item_addr of gc.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-56978

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-28642

Open SourceCoalition ESS < 30%HIGH2026-09-08

In executeRequest of ActivityStarter.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed ...

CVEs:CVE-2026-28642

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-28634

Open SourceCoalition ESS < 30%HIGH2026-09-08

In handleUssdRequest of PhoneInterfaceManager.java, there is a possible way to send a USSD request without permission due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. Use...

CVEs:CVE-2026-28634

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-58698

Open SourceCoalition ESS < 30%MEDIUM2026-09-15

In ap_pmic_poll_msg_handler of ap_pmic_ipc.c, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-58698

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-57042

Open SourceCoalition ESS < 30%MEDIUM2026-09-15

In multiple functions of DreamPickerReceiver.kt, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-57042

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-56992

Open SourceCoalition ESS < 30%MEDIUM2026-09-15

In multiple files, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-56992

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2026-56922

Open SourceCoalition ESS < 30%MEDIUM2026-09-15

In CPM, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-56922

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-49887

Open SourceCoalition ESS < 30%HIGH2026-09-08

In maybeRemoveInvalidInstallerPackageName of InstallRepository.kt, there is a possible unauthorized app update due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...

CVEs:CVE-2026-49887

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-58718

Open SourceCoalition ESS < 30%MEDIUM2026-09-15

In smmu_detach_dev_nested of arm-smmu-v3.c, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2026-58718

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-57035

Open SourceCoalition ESS < 30%HIGH2026-09-15

In multiple locations, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-57035

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2026-56989

Open SourceCoalition ESS < 30%HIGH2026-09-15

In multiple locations, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-56989

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2026-56972

Open SourceCoalition ESS < 30%HIGH2026-09-15

In multiple locations, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-56972

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2026-56907

Open SourceCoalition ESS < 30%MEDIUM2026-09-15

In VPU, there is a possible shared memory overwrite due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-56907

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-55365

Open SourceCoalition ESS < 30%HIGH2026-09-15

In multiple functions of remap.c, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-55365

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-55317

Open SourceCoalition ESS < 30%HIGH2026-09-15

In printf of printf.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-55317

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-56986

Open SourceCoalition ESS < 30%HIGH2026-09-15

In multiple files, there is a possible out-of-bounds read due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-56986

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2026-56985

Open SourceCoalition ESS < 30%HIGH2026-09-15

In multiple files, there is a possible way to obtain signatures due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-56985

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2026-55323

Open SourceCoalition ESS < 30%HIGH2026-09-15

In gf_base_update_finger_base of gf_base.c, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2026-55323

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-58721

Open SourceCoalition ESS < 30%MEDIUM2026-09-15

In multiple locations, there is a possible information disclosure due to uninitialized memory use. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-58721

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2026-58695

Open SourceCoalition ESS < 30%HIGH2026-09-15

In gmc_phy_lp3_exit_restore_registers of phy_power.c, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed fo...

CVEs:CVE-2026-58695

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-57014

Open SourceCoalition ESS < 30%HIGH2026-09-15

In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is n...

CVEs:CVE-2026-57014

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-56950

Open SourceCoalition ESS < 30%MEDIUM2026-09-15

In validate_ns_buf of mbu_class.rs, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-56950

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-55351

Open SourceCoalition ESS < 30%HIGH2026-09-15

In VPU, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-55351

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-0199

Open SourceCoalition ESS < 30%HIGH2026-09-15

In gf_ta_test_set_config of gf_ta_test.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2026-0199

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-0177

Open SourceCoalition ESS < 30%MEDIUM2026-09-15

In do_sss_aes_gcm_256_op of crypto-aes.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-0177

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-58766

Open SourceCoalition ESS < 30%HIGH2026-09-15

In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ex...

CVEs:CVE-2026-58766

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-58739

Open SourceCoalition ESS < 30%MEDIUM2026-09-15

In platform_msg_handler_init of default_msg_handlers.c, there is a possible confused deputy due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2026-58739

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-56879

Open SourceCoalition ESS < 30%HIGH2026-09-15

In gmc_mb_msg_handler of gmc_mba.c, there is a possible memory corruption due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-56879

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-28638

Open SourceCoalition ESS < 30%MEDIUM2026-09-08

In multiple functions of XmpDataParser.java, there is a possible improper data sanitization due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed...

CVEs:CVE-2026-28638

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-28613

Open SourceCoalition ESS < 30%HIGH2026-09-08

In initAppLinkTypeAndIntent of ChannelImpl.java, there is a possible launch an arbitrary intent due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is neede...

CVEs:CVE-2026-28613

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-0183

Open SourceCoalition ESS < 30%MEDIUM2026-09-15

In CPM, there is a possible information disclosure due to a confused deputy. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-0183

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-28656

Open SourceCoalition ESS < 30%HIGH2026-09-08

In multiple functions of DeviceAdminAdd.java, there is a possible way to an overlay due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for expl...

CVEs:CVE-2026-28656

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-28644

Open SourceCoalition ESS < 30%HIGH2026-09-08

In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ne...

CVEs:CVE-2026-28644

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-28636

Open SourceCoalition ESS < 30%HIGH2026-09-08

In setupLayout of PickActivity.java, there is a possible bypass of the "Install unknown apps" security restriction due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti...

CVEs:CVE-2026-28636

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-28631

Open SourceCoalition ESS < 30%HIGH2026-09-08

In buildMiniResolver of IntentForwarderActivity.java, there is a possible consent bypass due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed...

CVEs:CVE-2026-28631

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-28614

Open SourceCoalition ESS < 30%HIGH2026-09-08

In onCreate of SlicePermissionActivity.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-28614

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-28607

Open SourceCoalition ESS < 30%HIGH2026-09-08

In multiple functions in multiple locations, there is a possible background activity launch bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed...

CVEs:CVE-2026-28607

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2026-58731

Open SourceCoalition ESS < 30%MEDIUM2026-09-15

In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploi...

CVEs:CVE-2026-58731

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-56958

Open SourceCoalition ESS < 30%MEDIUM2026-09-15

In gf_algo_get_cached_dump_data of gf_algo.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2026-56958

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-56892

Open SourceCoalition ESS < 30%MEDIUM2026-09-15

In ReadDataElement of common.c, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-56892

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-28602

Open SourceCoalition ESS < 30%HIGH2026-09-08

In setClipboardAccessNotificationsEnabledForUser of ClipboardService.java, there is a possible mult-iuser isolation due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User ...

CVEs:CVE-2026-28602

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-58773

Open SourceCoalition ESS < 30%HIGH2026-09-15

In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-58773

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2026-28622

Open SourceCoalition ESS < 30%MEDIUM2026-09-08

In getQueryBuilderInternal of MediaProvider.java, there is a possible way to retrieve location metadata due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not...

CVEs:CVE-2026-28622

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-58744

Open SourceCoalition ESS < 30%HIGH2026-09-15

In multiple locations, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-58744

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2026-28633

Open SourceCoalition ESS < 30%HIGH2026-09-08

In initForUserNoTracing of VoiceInteractionManagerService.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is ...

CVEs:CVE-2026-28633

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-28617

Open SourceCoalition ESS < 30%HIGH2026-09-08

In add of WifiNetworkSuggestionsManager.java, there is a possible persistent DOS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-28617

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-28596

Open SourceCoalition ESS < 30%HIGH2026-09-08

In parseInterventionFromXml of GameManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not neede...

CVEs:CVE-2026-28596

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-56945

Open SourceCoalition ESS < 30%HIGH2026-09-15

In VPU, there is a possible out-of-bounds write due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-56945

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-28624

Open SourceCoalition ESS < 30%HIGH2026-09-08

In multiple locations, there is a possible read/write access to files without the proper permissions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need...

CVEs:CVE-2026-28624

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2026-28616

Open SourceCoalition ESS < 30%HIGH2026-09-08

In Setup Wizard, there is a possible way to force connection to a malicious network due to confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-28616

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-28603

Open SourceCoalition ESS < 30%HIGH2026-09-08

In assertSafeToStartCustomActivity of AppRestrictionsFragment.java, there is a possible read/write access to private files due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User i...

CVEs:CVE-2026-28603

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-28600

Open SourceCoalition ESS < 30%HIGH2026-09-08

In onCreate of PaymentDefaultDialog.java, there is a possible way to change default payment app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed fo...

CVEs:CVE-2026-28600

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-28572

Open SourceCoalition ESS < 30%HIGH2026-09-08

In onCreate of InstallLaunch.kt, there is a possible misleading UI due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-28572

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-28626

Open SourceCoalition ESS < 30%HIGH2026-09-08

In onCreate of SetupPassthroughActivity.java, there is a possible way to launch arbitrary activity due to Intent redirection . This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed f...

CVEs:CVE-2026-28626

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-28630

Open SourceCoalition ESS < 30%MEDIUM2026-09-08

In onCreate of ContactsPickerActivity.kt, there is a possible misleading UI due to a tapjacking/overlay attack. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2026-28630

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-28623

Open SourceCoalition ESS < 30%HIGH2026-09-08

In writeToParcel of BleRssiRangingCapabilities.java, there is a possible way to obtain the Bluetooth MAC address due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User int...

CVEs:CVE-2026-28623

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-58716

Open SourceCoalition ESS < 30%MEDIUM2026-09-15

In multiple locations, there is a possible time-of-check to time-of-use due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-58716

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2026-28671

Open SourceCoalition ESS < 30%MEDIUM2026-09-08

In updateInternal of MediaProvider.java, there is a possible expose contents of files due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-28671

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-58734

Open SourceCoalition ESS < 30%HIGH2026-09-15

In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-58734

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-58728

Open SourceCoalition ESS < 30%HIGH2026-09-15

In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-58728

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-58724

Open SourceCoalition ESS < 30%HIGH2026-09-15

In multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-58724

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2026-58701

Open SourceCoalition ESS < 30%HIGH2026-09-15

In trusty_dputc of generic-arm64-smcall.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-58701

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-56988

Open SourceCoalition ESS < 30%HIGH2026-09-15

In multiple functions of bluetooth_cco.cc, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-56988

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-56923

Open SourceCoalition ESS < 30%HIGH2026-09-15

In handle_unmap_req of tipc_virtio_dev.c, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-56923

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-56915

Open SourceCoalition ESS < 30%MEDIUM2026-09-15

In bigo_worker_thread of bigo.c, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-56915

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-91741

GoogleEPSS <= 49%CRITICAL2026-09-15

Type confusion in CacheStorage in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-91741

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-91731

GoogleEPSS <= 49%CRITICAL2026-09-15

Type confusion in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-91731

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

MINI-3h2j-229p-mmw6

Open SourceEPSS <= 49%2026-09-02

MINI-3h2j-229p-mmw6

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

CVE-2026-91728

GoogleEPSS <= 49%CRITICAL2026-09-15

Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-91728

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-93372

GoogleEPSS <= 49%CRITICAL2026-09-17

Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

CVEs:CVE-2026-93372

Affected products

ProductStatusVendorPackageEcosystem
Chrome affected Google
Upstream advisory

CVE-2026-93377

GoogleEPSS <= 49%HIGH2026-09-17

Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-93377

Affected products

ProductStatusVendorPackageEcosystem
Chrome affected Google
Upstream advisory

CVE-2026-91721

GoogleEPSS <= 49%CRITICAL2026-09-15

Use after free in Internals in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

CVEs:CVE-2026-91721

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-93382

GoogleEPSS <= 49%CRITICAL2026-09-17

Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-93382

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-93374

GoogleEPSS <= 49%CRITICAL2026-09-17

Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

CVEs:CVE-2026-93374

Affected products

ProductStatusVendorPackageEcosystem
Chrome affected Google
Upstream advisory

CVE-2026-28618

Open SourceEPSS <= 49%HIGH2026-09-08

In dec_frm_prepare of oapv.c, there is a possible OOB write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-28618

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-93381

GoogleEPSS <= 49%HIGH2026-09-17

Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)

CVEs:CVE-2026-93381

Affected products

ProductStatusVendorPackageEcosystem
Chrome affected Google
Upstream advisory

CVE-2026-91738

GoogleEPSS <= 49%CRITICAL2026-09-15

Improper input validation in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-91738

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-91729

GoogleEPSS <= 49%CRITICAL2026-09-15

Use after free in DigitalCredentials in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-91729

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-91737

GoogleEPSS <= 49%CRITICAL2026-09-15

Use after free in PDF in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-91737

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-91745

GoogleEPSS <= 49%CRITICAL2026-09-15

Use after free in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-91745

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-91736

GoogleEPSS <= 49%CRITICAL2026-09-15

Use after free in DOM in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-91736

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-91724

GoogleEPSS <= 49%CRITICAL2026-09-15

Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-91724

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-91749

GoogleEPSS <= 49%CRITICAL2026-09-15

Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

CVEs:CVE-2026-91749

Affected products

ProductStatusVendorPackageEcosystem
Chrome affected Google
Upstream advisory

CVE-2026-91718

GoogleEPSS <= 49%CRITICAL2026-09-15

Use after free in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-91718

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-91715

GoogleEPSS <= 49%CRITICAL2026-09-15

Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-91715

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-84347

GoogleEPSS <= 49%CRITICAL2026-09-01

Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-84347

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-91733

GoogleEPSS <= 49%HIGH2026-09-15

Improper state validation in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-91733

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-84352

GoogleEPSS <= 49%CRITICAL2026-09-01

Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

CVEs:CVE-2026-84352

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-84353

GoogleEPSS <= 49%CRITICAL2026-09-01

Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

CVEs:CVE-2026-84353

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-93385

GoogleEPSS <= 49%HIGH2026-09-17

Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-93385

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

MINI-3fv6-48cc-q346

Open SourceEPSS <= 49%2026-09-02

MINI-3fv6-48cc-q346

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

CVE-2026-91735

GoogleEPSS <= 49%CRITICAL2026-09-15

Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: ...

CVEs:CVE-2026-91735

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-91722

GoogleEPSS <= 49%CRITICAL2026-09-15

Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-91722

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-91716

GoogleEPSS <= 49%CRITICAL2026-09-15

Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-91716

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-93373

GoogleEPSS <= 49%CRITICAL2026-09-17

Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: High)

CVEs:CVE-2026-93373

Affected products

ProductStatusVendorPackageEcosystem
Chrome affected Google
Upstream advisory

CVE-2026-84326

GoogleEPSS <= 49%CRITICAL2026-09-01

Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-84326

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-49882

Open SourceEPSS <= 49%HIGH2026-09-08

In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-49882

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-84324

GoogleEPSS <= 49%CRITICAL2026-09-01

Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)

CVEs:CVE-2026-84324

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-49879

Open SourceEPSS <= 49%HIGH2026-09-08

In multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-49879

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-84333

GoogleEPSS <= 49%CRITICAL2026-09-01

Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-84333

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-91720

GoogleEPSS <= 49%CRITICAL2026-09-15

Uninitialized resource in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-91720

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-84351

GoogleEPSS <= 49%CRITICAL2026-09-01

Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-84351

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-84354

GoogleEPSS <= 49%CRITICAL2026-09-01

Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-84354

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-91726

GoogleEPSS <= 49%MEDIUM2026-09-15

Out of bounds read in WebGL in Google Chrome on on Android prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

CVEs:CVE-2026-91726

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-91712

GoogleEPSS <= 49%CRITICAL2026-09-15

Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security seve...

CVEs:CVE-2026-91712

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-93383

GoogleEPSS <= 49%HIGH2026-09-17

Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-93383

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-93387

GoogleEPSS <= 49%MEDIUM2026-09-17

Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-93387

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

MINI-2cv6-mqj5-2vxr

Open SourceEPSS <= 49%2026-09-02

MINI-2cv6-mqj5-2vxr

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

CVE-2026-91743

GoogleEPSS <= 49%CRITICAL2026-09-15

Race condition in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-91743

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-93386

GoogleEPSS <= 49%MEDIUM2026-09-17

UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-93386

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-84325

GoogleEPSS <= 49%CRITICAL2026-09-01

Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High)

CVEs:CVE-2026-84325

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-91740

GoogleEPSS <= 49%CRITICAL2026-09-15

Uninitialized resource in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-91740

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-91747

GoogleEPSS <= 49%CRITICAL2026-09-15

Use after free in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-91747

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

MINI-3857-f297-9594

Open SourceEPSS <= 49%2026-09-02

MINI-3857-f297-9594

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

CVE-2026-84349

GoogleEPSS <= 49%CRITICAL2026-09-01

Use after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-84349

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-93384

GoogleEPSS <= 49%MEDIUM2026-09-17

Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)

CVEs:CVE-2026-93384

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-91732

GoogleEPSS <= 49%HIGH2026-09-15

Missing authorization in AppManifest in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security sev...

CVEs:CVE-2026-91732

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-91725

GoogleEPSS <= 49%HIGH2026-09-15

Observable discrepancy in CSS in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-91725

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-91714

GoogleEPSS <= 49%MEDIUM2026-09-15

Observable discrepancy in Fonts in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-91714

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-91719

GoogleEPSS <= 49%HIGH2026-09-15

Code injection in XML in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-91719

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-91744

GoogleEPSS <= 49%MEDIUM2026-09-15

Race condition in PlatformIntegration in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromi...

CVEs:CVE-2026-91744

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-91746

GoogleEPSS <= 49%CRITICAL2026-09-15

Integer overflow in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-91746

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-91748

GoogleEPSS <= 49%HIGH2026-09-15

Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via UI Interact...

CVEs:CVE-2026-91748

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-84335

GoogleEPSS <= 49%HIGH2026-09-01

Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML...

CVEs:CVE-2026-84335

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-91730

GoogleEPSS <= 49%LOW2026-09-15

Incomplete cleanup in GetUserMedia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security sever...

CVEs:CVE-2026-91730

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-84350

GoogleEPSS <= 49%HIGH2026-09-01

Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Low)

CVEs:CVE-2026-84350

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

MINI-3vqr-whwf-5rw5

Open SourceEPSS <= 49%2026-09-02

MINI-3vqr-whwf-5rw5

Affected products

ProductStatusVendorPackageEcosystem
chromium affected MinimOS chromium
chromium-docker-selenium-compat affected MinimOS chromium-docker-selenium-compat
chromium-lang affected MinimOS chromium-lang
Upstream advisory

CVE-2026-84348

GoogleEPSS <= 49%HIGH2026-09-01

Information leak in MediaCapture in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-84348

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-91739

GoogleEPSS <= 49%MEDIUM2026-09-15

Missing authorization in Transactions Platform in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-91739

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-91713

GoogleEPSS <= 49%MEDIUM2026-09-15

Missing authorization in Browser in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-91713

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-84327

GoogleEPSS <= 49%MEDIUM2026-09-01

Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-84327

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-78600

Open SourceEPSS <= 49%HIGH2026-09-02

Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after a cross-namespace association has been denied by RBAC enforcement, allowing a lo...

CVEs:CVE-2026-78600

Affected products

ProductStatusVendorPackageEcosystem
elastic_cloud_on_kubernetes affected elastic
Upstream advisory

CVE-2026-84332

GoogleEPSS <= 49%MEDIUM2026-09-01

Incorrect authorization in SiteSettings in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-84332

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-84357

GoogleEPSS <= 49%MEDIUM2026-09-01

Improper input validation in Omnibox in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: High)

CVEs:CVE-2026-84357

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-84329

GoogleEPSS <= 49%HIGH2026-09-01

Confused deputy in CredentialProvider in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-84329

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-84323

GoogleEPSS <= 49%MEDIUM2026-09-01

Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security ...

CVEs:CVE-2026-84323

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-91723

GoogleEPSS <= 49%MEDIUM2026-09-15

Race condition in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-91723

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-28652

Open SourceEPSS <= 49%MEDIUM2026-09-08

In multiple functions of RangingServiceImpl.java, there is a possible MITM due to a missing permission check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-28652

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-84330

GoogleEPSS <= 49%MEDIUM2026-09-01

UI misrepresentation in FullScreen in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-84330

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-84331

GoogleEPSS <= 49%LOW2026-09-01

Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-84331

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-84356

GoogleEPSS <= 49%MEDIUM2026-09-01

UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2026-84356

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-84355

GoogleEPSS <= 49%LOW2026-09-01

Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-84355

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-84328

GoogleEPSS <= 49%LOW2026-09-01

Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-84328

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-84359

GoogleEPSS <= 49%HIGH2026-09-01

Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2026-84359

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-84358

GoogleEPSS <= 49%MEDIUM2026-09-01

Improper privilege management in Downloads in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2026-84358

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-28662

Open SourceEPSS <= 49%HIGH2026-09-08

In p2p_process_prov_disc_bootstrap_req of p2p_pd.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is ...

CVEs:CVE-2026-28662

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-20506

Open SourceEPSS <= 49%HIGH2026-09-07

In Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID:...

CVEs:CVE-2026-20506

Affected products

ProductStatusVendorPackageEcosystem
Android affected MediaTek
MediaTek chipset affected MediaTek, Inc.
Upstream advisory

CVE-2026-91727

GoogleEPSS <= 49%HIGH2026-09-15

Incorrect reference resolution in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a local attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a local program. (Chromium security sever...

CVEs:CVE-2026-91727

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-91734

GoogleEPSS <= 49%HIGH2026-09-15

Incorrect authorization in Core in Google Chrome on on Windows prior to 153.0.8010.47 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)

CVEs:CVE-2026-91734

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-45515

Open SourceEPSS <= 49%HIGH2026-09-08

In a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User inter...

CVEs:CVE-2026-45515

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-91717

GoogleEPSS <= 49%MEDIUM2026-09-15

Missing authorization in Android in Google Chrome on on Android prior to 153.0.8010.47 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: High)

CVEs:CVE-2026-91717

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2026-78609

Open SourceEPSS <= 49%MEDIUM2026-09-02

Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized modification of data via Metadata Spoofing (CAPEC-690). An actor holding limited Kubernetes permissions confined to a single namespace could cause attacker-...

CVEs:CVE-2026-78609

Affected products

ProductStatusVendorPackageEcosystem
elastic_cloud_on_kubernetes affected elastic
Upstream advisory

CVE-2026-28639

Open SourceEPSS <= 49%HIGH2026-09-08

In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2026-28639

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-45520

Open SourceEPSS <= 49%HIGH2026-09-08

In onAttach of BiometricsSettingsBase.java, there is a possible authentication bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2026-45520

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-93375

GoogleEPSS <= 49%HIGH2026-09-17

Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)

CVEs:CVE-2026-93375

Affected products

ProductStatusVendorPackageEcosystem
Chrome affected Google
Upstream advisory

CVE-2026-84334

GoogleEPSS <= 49%HIGH2026-09-01

Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)

CVEs:CVE-2026-84334

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
Upstream advisory

CVE-2026-28658

Open SourceEPSS <= 49%HIGH2026-09-08

In findMetaAuthUid of AccountsDb.java, there is a possible frp bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-28658

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-28655

Open SourceEPSS <= 49%HIGH2026-09-08

In multiple functions of RemoteViews.java, there is a possible background activity launch bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ...

CVEs:CVE-2026-28655

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-49884

Open SourceEPSS <= 49%HIGH2026-09-08

In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2026-49884

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-28594

Open SourceEPSS <= 49%HIGH2026-09-08

In multiple locations, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-28594

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2026-28583

Open SourceEPSS <= 49%HIGH2026-09-08

In validate_camera_metadata_structure of camera_metadata.c, there is a possible out of bounds write due to a logical error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is...

CVEs:CVE-2026-28583

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-28663

Open SourceEPSS <= 49%HIGH2026-09-08

In buildIntentSenderForUser of LauncherAppsService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interact...

CVEs:CVE-2026-28663

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-28660

Open SourceEPSS <= 49%MEDIUM2026-09-08

In getAllSessions of multiple files, there is a possible confused deputy due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-28660

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-28653

Open SourceEPSS <= 49%HIGH2026-09-08

In multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-28653

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-28657

Open SourceEPSS <= 49%HIGH2026-09-08

In onActivityResult of AppWidgetConfigActivityProxy.java, there is a possible unauthorized URI permission grant due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction ...

CVEs:CVE-2026-28657

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-45528

Open SourceEPSS <= 49%HIGH2026-09-08

In getManageSpaceActivityIntent of StorageManagerService.java, there is a possible LaunchAnyWhere chain due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is...

CVEs:CVE-2026-45528

Affected products

ProductStatusVendorPackageEcosystem
Android affected Google
Upstream advisory

CVE-2026-28620

Open SourceEPSS <= 49%HIGH2026-09-08

In multiple locations, there is a possible unauthorized URI access due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2026-28620

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2026-28584

Open SourceEPSS <= 49%MEDIUM2026-09-08

In createSessionInternal of PackageInstallerService.java, there is a possible way to permanently DoS the device due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interactio...

CVEs:CVE-2026-28584

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-28611

Open SourceEPSS <= 49%HIGH2026-09-08

In multiple functions of NfcService.java, there is a possible silent payment session hijacking enablement due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti...

CVEs:CVE-2026-28611

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-28582

Open SourceEPSS <= 49%MEDIUM2026-09-08

In onCreate of ConfirmDeviceCredentialActivity.java, there is a possible unauthorized access to and modification of device credentials due to a missing permission check. This could lead to local information disclosure with no additional execution privi...

CVEs:CVE-2026-28582

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

CVE-2026-28590

Open SourceEPSS <= 49%HIGH2026-09-08

In multiple locations, there is a possible improper encryption key validation due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2026-28590

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.