Описание
Security update for chromium
This update for chromium fixes the following issues:
Changes in chromium:
Chromium 153.0.8010.36 (boo#1279840):
- CVE-2026-87464: Use after free in WebGL
- CVE-2026-87488: Use after free in WebGL
- CVE-2026-87438: Out of bounds write in WebGL
- CVE-2026-87527: Buffer overflow in WebGL
- CVE-2026-87628: Use after free in Cast
- CVE-2026-87512: Use after free in ANGLE
- CVE-2026-87585: Double free in PDFium
- CVE-2026-87444: Memory corruption in Codecs
- CVE-2026-87447: Incorrect authorization in Network
- CVE-2026-87440: Out of bounds read in Media
- CVE-2026-87633: Use after free in Views
- CVE-2026-87525: Out of bounds read in Chromoting
- CVE-2026-87578: Use after free in Receiver
- CVE-2026-87517: Race condition in Mobile
- CVE-2026-87524: Use after free in Core
- CVE-2026-87569: Missing authorization in Views
- CVE-2026-87554: Race condition in Chromoting
- CVE-2026-87467: Race condition in Updater
- CVE-2026-87492: Incorrect authorization in DevTools
- CVE-2026-87520: Use after free in Dawn
- CVE-2026-87514: Use after free in Views
- CVE-2026-87650: Out of bounds read in WebGL
- CVE-2026-87596: Out of bounds read in ANGLE
- CVE-2026-87654: Buffer overflow in ANGLE
- CVE-2026-87604: Out of bounds read in ANGLE
- CVE-2026-87621: Out of bounds write in ANGLE
- CVE-2026-87647: Uninitialized resource in GPU
- CVE-2026-87646: Use after free in Web Authentication
- CVE-2026-87500: Improper validation of array index in ANGLE
- CVE-2026-87572: Injection in DevTools
- CVE-2026-87460: Use after free in Platform
- CVE-2026-87542: Use after free in Input
- CVE-2026-87639: Use after free in WebPackaging
- CVE-2026-87552: Missing authorization in TrustedWebActivities
- CVE-2026-87651: Incorrect authorization in Paint
- CVE-2026-87587: Use after free in V8
- CVE-2026-87564: Type confusion in V8
- CVE-2026-87498: Missing authorization in WebUI
- CVE-2026-87499: Incorrect authorization in Network
- CVE-2026-87607: Use after free in Device
- CVE-2026-87558: Use after free in Payments
- CVE-2026-87581: Use after free in Payments
- CVE-2026-87480: Use after free in Printing
- CVE-2026-87612: Type confusion in V8
- CVE-2026-87536: Use after free in V8
- CVE-2026-87474: Use after free in Payments
- CVE-2026-87504: Use after free in Core
- CVE-2026-87640: Out of bounds read in WebView
- CVE-2026-87491: Out of bounds write in V8
- CVE-2026-87478: Observable discrepancy in Autofill
- CVE-2026-87446: Incomplete cleanup in Extensions
- CVE-2026-87657: Use after free in V8
- CVE-2026-87434: Missing authorization in CORS
- CVE-2026-87487: Missing authorization in FileSystem
- CVE-2026-87453: Confused deputy in BackgroundFetch
- CVE-2026-87588: Use after free in Chromecast
- CVE-2026-87636: Type confusion in XML
- CVE-2026-87611: Missing authorization in FileSystem
- CVE-2026-87606: Missing authorization in SiteIsolation
- CVE-2026-87456: Uninitialized resource in Media
- CVE-2026-87553: Improper input validation in SiteIsolation
- CVE-2026-87658: Information leak in Extensions
- CVE-2026-87465: Incorrect authorization in Downloads
- CVE-2026-87515: Incorrect authorization in FileAPI
- CVE-2026-87547: Incorrect reference resolution in FileSystem
- CVE-2026-87442: Confused deputy in Prerender
- CVE-2026-87506: Privilege elevation in WebUI
- CVE-2026-87433: Race condition in FileAPI
- CVE-2026-87557: Missing authorization in LocalNetworkAccess
- CVE-2026-87457: Race condition in Updater
- CVE-2026-87503: Inappropriate implementation in Downloads
- CVE-2026-87481: Incorrect authorization in WebView
- CVE-2026-87537: Missing authorization in Extensions
- CVE-2026-87471: Incorrect authorization in ServiceWorker
- CVE-2026-87485: Incorrect authorization in CORS
- CVE-2026-87652: Incorrect authorization in PushAPI
- CVE-2026-87582: Confused deputy in DataTransfer
- CVE-2026-87466: Incorrect authorization in Workers
- CVE-2026-87603: Missing authorization in FileSystem
- CVE-2026-87615: Race condition in Payments
- CVE-2026-87642: Uninitialized resource in WebGL
- CVE-2026-87577: Incorrect authorization in Isolated
- CVE-2026-87449: Cross-site request forgery in DeviceBoundSessionCredentials
- CVE-2026-87613: Incorrect reference resolution in Extensions
- CVE-2026-87645: Improper state validation in Safebrowsing
- CVE-2026-87443: Missing authorization in Actor
- CVE-2026-87630: Integer overflow in WebRTC
- CVE-2026-87590: Improper input validation in Passwords
- CVE-2026-87580: Incorrect authorization in WebAppInstalls
- CVE-2026-87482: Cleartext transmission of sensitive data in HttpsUpgrades
- CVE-2026-87497: Uninitialized resource in Codecs
- CVE-2026-87579: Buffer overflow in WebRTC
- CVE-2026-87576: Uninitialized resource in GPU
- CVE-2026-87476: Incorrect authorization in Loader
- CVE-2026-87475: Missing authorization in Omnibox
- CVE-2026-87436: Incomplete cleanup in Browser
- CVE-2026-87479: Insufficient policy enforcement in Extensions
- CVE-2026-87513: Missing authorization in ControlledFrame
- CVE-2026-87432: Incorrect authorization in Navigation
- CVE-2026-87560: Missing authorization in Browser
- CVE-2026-87521: Information leak in WebMCP
- CVE-2026-87539: Observable discrepancy in Network
- CVE-2026-87648: Use after free in ANGLE
- CVE-2026-87534: Missing authorization in WebView
- CVE-2026-87562: Incorrect reference resolution in Accessibility
- CVE-2026-87556: Missing authorization in Browser
- CVE-2026-87508: Incorrect authorization in Loader
- CVE-2026-87643: Integer overflow in GPU
- CVE-2026-87573: Improper input validation in Network
- CVE-2026-87548: Improper state validation in Installer
- CVE-2026-87501: UI misrepresentation in Passwords
- CVE-2026-87452: Incorrect authorization in GPU
- CVE-2026-87516: Observable discrepancy in Navigation
- CVE-2026-87599: Improper input validation in Interstitials
- CVE-2026-87507: UI misrepresentation in Downloads
- CVE-2026-87559: UI misrepresentation in UI
- CVE-2026-87472: Improper input validation in FedCM
- CVE-2026-87486: Clickjacking in TrustedWebActivities
- CVE-2026-87655: Clickjacking in Downloads
- CVE-2026-87462: UI misrepresentation in FedCM
- CVE-2026-87649: UI misrepresentation in Downloads
- CVE-2026-87445: UI misrepresentation in Session
- CVE-2026-87567: UI misrepresentation in UrlFormatting
- CVE-2026-87496: UI misrepresentation in Browser
- CVE-2026-87441: Missing authorization in Downloads
- CVE-2026-87549: Incomplete cleanup in Downloads
- CVE-2026-87458: UI misrepresentation in Geometry
- CVE-2026-87574: Information leak in ServiceWorker
- CVE-2026-87495: Information leak in Scroll
- CVE-2026-87541: Information leak in Navigation
- CVE-2026-87451: Information leak in Downloads
- CVE-2026-87570: Incorrect authorization in SiteIsolation
- CVE-2026-87555: Uninitialized resource in GPU
- CVE-2026-87600: Improper input validation in Safebrowsing
- CVE-2026-87532: Improper state validation in Safebrowsing
- CVE-2026-87439: Information leak in ServiceWorker
- CVE-2026-87450: Incorrect authorization in Permissions
- CVE-2026-87505: Incorrect authorization in FileSystem
- CVE-2026-87622: Missing authorization in FedCM
- CVE-2026-87540: Incorrect authorization in Isolated
- CVE-2026-87594: Incorrect authorization in DataTransfer
- CVE-2026-87518: Observable discrepancy in Safebrowsing
- CVE-2026-87589: Incorrect authorization in SiteIsolation
- CVE-2026-87484: UI misrepresentation in Geometry
- CVE-2026-87530: Uncontrolled search path element in CredentialProvider
- CVE-2026-87550: Improper encoding or escaping of output in CSS
- CVE-2026-87494: Use after free in Browser
- CVE-2026-87483: Incorrect authorization in Browser
- CVE-2026-87454: Information leak in Enterprise
- CVE-2026-87616: Improper initialization in Views
- CVE-2026-87535: Information loss or omission in Safebrowsing
- CVE-2026-87644: Incorrect authorization in Views
- CVE-2026-87533: Use after free in DevTools
- CVE-2026-87635: UI misrepresentation in Payments
- CVE-2026-87641: Race condition in Browser
- CVE-2026-87431: Missing authorization in Extensions
- CVE-2026-87493: Missing authorization in FileSystem
- CVE-2026-87625: Use after free in V8
- CVE-2026-87468: Incorrect authorization in Isolated
- CVE-2026-87563: Origin validation error in Paint
- CVE-2026-87510: Improper input validation in FileAPI
- CVE-2026-87435: Information leak in ControlledFrame
- CVE-2026-87531: Information leak in CORS
- CVE-2026-87637: Use after free in Extensions
- CVE-2026-87529: Numeric truncation error in Media
- CVE-2026-87470: Improper quantity validation in Tint
- CVE-2026-87586: Out of bounds read in ANGLE
- CVE-2026-87584: Incorrect authorization in WebUI
- CVE-2026-87632: Cross-site scripting in SanitizerAPI
- CVE-2026-87528: Type confusion in Rust
- CVE-2026-87623: Observable discrepancy in DOM
- CVE-2026-87566: Observable discrepancy in Layout
- CVE-2026-87638: Out of bounds write in Media
- CVE-2026-87455: Use after free in Aura
- CVE-2026-87591: Incorrect authorization in Extensions
- CVE-2026-87526: Use after free in Passwords
- CVE-2026-87609: Use after free in Sharing
- CVE-2026-87610: Incorrect authorization in Omnibox
- CVE-2026-87626: Incorrect authorization in DeviceBoundSessionCredentials
- CVE-2026-87629: Incorrect authorization in Sources
- CVE-2026-87653: UI misrepresentation in FullScreen
- CVE-2026-87634: Use after free in WebPackaging
- CVE-2026-87429: Missing authorization in ServiceWorker
- CVE-2026-87618: Incorrect reference resolution in Storage
- CVE-2026-87614: Incorrect authorization in ServiceWorker
- CVE-2026-87619: Observable discrepancy in Prefetch
- CVE-2026-87561: Incorrect authorization in Web Authentication
- CVE-2026-87598: Incorrect authorization in ServiceWorker
- CVE-2026-87519: Incorrect authorization in Safebrowsing
- CVE-2026-87543: Missing authorization in Core
- CVE-2026-87522: Missing authorization in WebView
- CVE-2026-87568: Improper input validation in Chromium
- CVE-2026-87656: Improper state validation in Safebrowsing
- CVE-2026-87511: Missing authorization in DevTools
- CVE-2026-87627: Interpretation conflict in Safebrowsing
- CVE-2026-87595: Server-side request forgery in Mobile
- CVE-2026-87592: Out of bounds read in Tint
- CVE-2026-87620: Observable discrepancy in SVG
- CVE-2026-87502: Confused deputy in Fullscreen
- CVE-2026-87448: Use after free in DevTools
- CVE-2026-87459: Observable discrepancy in Select
- CVE-2026-87463: Incorrect authorization in Certificate
- CVE-2026-87546: Incorrect type conversion or cast in Safebrowsing
- CVE-2026-87538: Clickjacking in Input
- CVE-2026-87545: Information leak in Mobile
- CVE-2026-87617: Use after free in DevTools
- CVE-2026-87523: Race condition in DataTransfer
- CVE-2026-87565: Information leak in Passwords
- CVE-2026-87597: UI misrepresentation in CustomTabs
- CVE-2026-87624: UI misrepresentation in Passwords
- CVE-2026-87605: Missing authorization in Contacts
- CVE-2026-87490: Information leak in Transactions Platform
- CVE-2026-87583: UI misrepresentation in Passwords
- CVE-2026-87509: Incorrect authorization in Updater
- CVE-2026-87473: Incorrect authorization in FileHandling
- CVE-2026-87461: Information leak in Core
- CVE-2026-87631: Missing authorization in DOM
- CVE-2026-87469: Improper input validation in Extensions
- CVE-2026-87489: Memory corruption in V8
- CVE-2026-87575: Incorrect authorization in Loader
- CVE-2026-87571: Improper certificate validation in Loader
- CVE-2026-87477: Information leak in Core
- CVE-2026-87551: Improper certificate validation in CORS
- CVE-2026-87608: Improper certificate validation in FedCM
- CVE-2026-87437: Information leak in Frames
- CVE-2026-87602: Out of bounds read in ANGLE
- CVE-2026-87601: Race condition in V8
- CVE-2026-87544: Incorrect authorization in Extensions
- CVE-2026-87430: Buffer overflow in WebRTC
- CVE-2026-87593: Information leak in Editing
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1279840
- SUSE CVE CVE-2026-87429 page
- SUSE CVE CVE-2026-87430 page
- SUSE CVE CVE-2026-87431 page
- SUSE CVE CVE-2026-87432 page
- SUSE CVE CVE-2026-87433 page
- SUSE CVE CVE-2026-87434 page
- SUSE CVE CVE-2026-87435 page
- SUSE CVE CVE-2026-87436 page
- SUSE CVE CVE-2026-87437 page
- SUSE CVE CVE-2026-87438 page
- SUSE CVE CVE-2026-87439 page
- SUSE CVE CVE-2026-87440 page
- SUSE CVE CVE-2026-87441 page
- SUSE CVE CVE-2026-87442 page
- SUSE CVE CVE-2026-87443 page
- SUSE CVE CVE-2026-87444 page
- SUSE CVE CVE-2026-87445 page
- SUSE CVE CVE-2026-87446 page
Описание
Missing authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87429
- SUSE Bug 1279840
Описание
Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87430
- SUSE Bug 1279840
Описание
Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87431
- SUSE Bug 1279840
Описание
Incorrect authorization in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87432
- SUSE Bug 1279840
Описание
Race condition in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87433
- SUSE Bug 1279840
Описание
Missing authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87434
- SUSE Bug 1279840
Описание
Information leak in ControlledFrame in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87435
- SUSE Bug 1279840
Описание
Incomplete cleanup in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87436
- SUSE Bug 1279840
Описание
Information leak in Frames in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87437
- SUSE Bug 1279840
Описание
Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-87438
- SUSE Bug 1279840
Описание
Information leak in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87439
- SUSE Bug 1279840
Описание
Out of bounds read in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87440
- SUSE Bug 1279840
Описание
Missing authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87441
- SUSE Bug 1279840
Описание
Confused deputy in Prerender in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87442
- SUSE Bug 1279840
Описание
Missing authorization in Actor in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87443
- SUSE Bug 1279840
Описание
Memory corruption in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87444
- SUSE Bug 1279840
Описание
UI misrepresentation in Session in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87445
- SUSE Bug 1279840
Описание
Incomplete cleanup in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87446
- SUSE Bug 1279840
Описание
Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87447
- SUSE Bug 1279840
Описание
Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87448
- SUSE Bug 1279840
Описание
Cross-site request forgery in DeviceBoundSessionCredentials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87449
- SUSE Bug 1279840
Описание
Incorrect authorization in Permissions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87450
- SUSE Bug 1279840
Описание
Information leak in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87451
- SUSE Bug 1279840
Описание
Incorrect authorization in GPU in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87452
- SUSE Bug 1279840
Описание
Confused deputy in BackgroundFetch in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87453
- SUSE Bug 1279840
Описание
Information leak in Enterprise in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87454
- SUSE Bug 1279840
Описание
Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87455
- SUSE Bug 1279840
Описание
Uninitialized resource in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87456
- SUSE Bug 1279840
Описание
Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87457
- SUSE Bug 1279840
Описание
UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87458
- SUSE Bug 1279840
Описание
Observable discrepancy in Select in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87459
- SUSE Bug 1279840
Описание
Use after free in Platform in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87460
- SUSE Bug 1279840
Описание
Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted Chrome extension. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87461
- SUSE Bug 1279840
Описание
UI misrepresentation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87462
- SUSE Bug 1279840
Описание
Incorrect authorization in Certificate in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to potentially spoof address bar via crafted network traffic. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87463
- SUSE Bug 1279840
Описание
Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-87464
- SUSE Bug 1279840
Описание
Incorrect authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87465
- SUSE Bug 1279840
Описание
Incorrect authorization in Workers in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87466
- SUSE Bug 1279840
Описание
Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87467
- SUSE Bug 1279840
Описание
Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87468
- SUSE Bug 1279840
Описание
Improper input validation in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy into a privileged page via crafted network traffic. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87469
- SUSE Bug 1279840
Описание
Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87470
- SUSE Bug 1279840
Описание
Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87471
- SUSE Bug 1279840
Описание
Improper input validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87472
- SUSE Bug 1279840
Описание
Incorrect authorization in FileHandling in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87473
- SUSE Bug 1279840
Описание
Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87474
- SUSE Bug 1279840
Описание
Missing authorization in Omnibox in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87475
- SUSE Bug 1279840
Описание
Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87476
- SUSE Bug 1279840
Описание
Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87477
- SUSE Bug 1279840
Описание
Observable discrepancy in Autofill in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87478
- SUSE Bug 1279840
Описание
Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87479
- SUSE Bug 1279840
Описание
Use after free in Printing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87480
- SUSE Bug 1279840
Описание
Incorrect authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87481
- SUSE Bug 1279840
Описание
Cleartext transmission of sensitive data in HttpsUpgrades in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via crafted network traffic. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87482
- SUSE Bug 1279840
Описание
Incorrect authorization in Browser in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87483
- SUSE Bug 1279840
Описание
UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87484
- SUSE Bug 1279840
Описание
Incorrect authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87485
- SUSE Bug 1279840
Описание
Clickjacking in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to spoof address bar via a co-installed app. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87486
- SUSE Bug 1279840
Описание
Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87487
- SUSE Bug 1279840
Описание
Use after free in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-87488
- SUSE Bug 1279840
Описание
Memory corruption in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87489
- SUSE Bug 1279840
Описание
Information leak in Transactions Platform in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87490
- SUSE Bug 1279840
Описание
Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87491
- SUSE Bug 1279840
Описание
Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87492
- SUSE Bug 1279840
Описание
Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87493
- SUSE Bug 1279840
Описание
Use after free in Browser in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87494
- SUSE Bug 1279840
Описание
Information leak in Scroll in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87495
- SUSE Bug 1279840
Описание
UI misrepresentation in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87496
- SUSE Bug 1279840
Описание
Uninitialized resource in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87497
- SUSE Bug 1279840
Описание
Missing authorization in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87498
- SUSE Bug 1279840
Описание
Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87499
- SUSE Bug 1279840
Описание
Improper validation of array index in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87500
- SUSE Bug 1279840
Описание
UI misrepresentation in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87501
- SUSE Bug 1279840
Описание
Confused deputy in Fullscreen in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87502
- SUSE Bug 1279840
Описание
Inappropriate implementation in Downloads in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87503
- SUSE Bug 1279840
Описание
Use after free in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87504
- SUSE Bug 1279840
Описание
Incorrect authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87505
- SUSE Bug 1279840
Описание
Privilege elevation in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87506
- SUSE Bug 1279840
Описание
UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87507
- SUSE Bug 1279840
Описание
Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87508
- SUSE Bug 1279840
Описание
Incorrect authorization in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87509
- SUSE Bug 1279840
Описание
Improper input validation in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87510
- SUSE Bug 1279840
Описание
Missing authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87511
- SUSE Bug 1279840
Описание
Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87512
- SUSE Bug 1279840
Описание
Missing authorization in ControlledFrame in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87513
- SUSE Bug 1279840
Описание
Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87514
- SUSE Bug 1279840
Описание
Incorrect authorization in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87515
- SUSE Bug 1279840
Описание
Observable discrepancy in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87516
- SUSE Bug 1279840
Описание
Race condition in Mobile in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87517
- SUSE Bug 1279840
Описание
Observable discrepancy in Safebrowsing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87518
- SUSE Bug 1279840
Описание
Incorrect authorization in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87519
- SUSE Bug 1279840
Описание
Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87520
- SUSE Bug 1279840
Описание
Information leak in WebMCP in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87521
- SUSE Bug 1279840
Описание
Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially bypass system access restrictions via crafted network traffic. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87522
- SUSE Bug 1279840
Описание
Race condition in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87523
- SUSE Bug 1279840
Описание
Use after free in Core in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87524
- SUSE Bug 1279840
Описание
Out of bounds read in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to read memory outside the sandbox via a local program. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87525
- SUSE Bug 1279840
Описание
Use after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87526
- SUSE Bug 1279840
Описание
Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-87527
- SUSE Bug 1279840
Описание
Type confusion in Rust in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87528
- SUSE Bug 1279840
Описание
Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87529
- SUSE Bug 1279840
Описание
Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87530
- SUSE Bug 1279840
Описание
Information leak in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87531
- SUSE Bug 1279840
Описание
Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87532
- SUSE Bug 1279840
Описание
Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87533
- SUSE Bug 1279840
Описание
Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87534
- SUSE Bug 1279840
Описание
Information loss or omission in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87535
- SUSE Bug 1279840
Описание
Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87536
- SUSE Bug 1279840
Описание
Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87537
- SUSE Bug 1279840
Описание
Clickjacking in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87538
- SUSE Bug 1279840
Описание
Observable discrepancy in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87539
- SUSE Bug 1279840
Описание
Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87540
- SUSE Bug 1279840
Описание
Information leak in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87541
- SUSE Bug 1279840
Описание
Use after free in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87542
- SUSE Bug 1279840
Описание
Missing authorization in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87543
- SUSE Bug 1279840
Описание
Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87544
- SUSE Bug 1279840
Описание
Information leak in Mobile in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87545
- SUSE Bug 1279840
Описание
Incorrect type conversion or cast in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted file. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87546
- SUSE Bug 1279840
Описание
Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87547
- SUSE Bug 1279840
Описание
Improper state validation in Installer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87548
- SUSE Bug 1279840
Описание
Incomplete cleanup in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87549
- SUSE Bug 1279840
Описание
Improper encoding or escaping of output in CSS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87550
- SUSE Bug 1279840
Описание
Improper certificate validation in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87551
- SUSE Bug 1279840
Описание
Missing authorization in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87552
- SUSE Bug 1279840
Описание
Improper input validation in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87553
- SUSE Bug 1279840
Описание
Race condition in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87554
- SUSE Bug 1279840
Описание
Uninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87555
- SUSE Bug 1279840
Описание
Missing authorization in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87556
- SUSE Bug 1279840
Описание
Missing authorization in LocalNetworkAccess in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87557
- SUSE Bug 1279840
Описание
Use after free in Payments in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87558
- SUSE Bug 1279840
Описание
UI misrepresentation in UI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87559
- SUSE Bug 1279840
Описание
Missing authorization in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87560
- SUSE Bug 1279840
Описание
Incorrect authorization in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87561
- SUSE Bug 1279840
Описание
Incorrect reference resolution in Accessibility in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87562
- SUSE Bug 1279840
Описание
Origin validation error in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87563
- SUSE Bug 1279840
Описание
Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87564
- SUSE Bug 1279840
Описание
Information leak in Passwords in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87565
- SUSE Bug 1279840
Описание
Observable discrepancy in Layout in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87566
- SUSE Bug 1279840
Описание
UI misrepresentation in UrlFormatting in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof address bar via a crafted domain name. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87567
- SUSE Bug 1279840
Описание
Improper input validation in Chromium in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via crafted network traffic. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87568
- SUSE Bug 1279840
Описание
Missing authorization in Views in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87569
- SUSE Bug 1279840
Описание
Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted file. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87570
- SUSE Bug 1279840
Описание
Improper certificate validation in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87571
- SUSE Bug 1279840
Описание
Injection in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87572
- SUSE Bug 1279840
Описание
Improper input validation in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87573
- SUSE Bug 1279840
Описание
Information leak in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87574
- SUSE Bug 1279840
Описание
Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87575
- SUSE Bug 1279840
Описание
Uninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87576
- SUSE Bug 1279840
Описание
Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87577
- SUSE Bug 1279840
Описание
Use after free in Receiver in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87578
- SUSE Bug 1279840
Описание
Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87579
- SUSE Bug 1279840
Описание
Incorrect authorization in WebAppInstalls in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87580
- SUSE Bug 1279840
Описание
Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87581
- SUSE Bug 1279840
Описание
Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87582
- SUSE Bug 1279840
Описание
UI misrepresentation in Passwords in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87583
- SUSE Bug 1279840
Описание
Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87584
- SUSE Bug 1279840
Описание
Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87585
- SUSE Bug 1279840
Описание
Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87586
- SUSE Bug 1279840
Описание
Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87587
- SUSE Bug 1279840
Описание
Use after free in Chromecast in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87588
- SUSE Bug 1279840
Описание
Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87589
- SUSE Bug 1279840
Описание
Improper input validation in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially leak sensitive information via crafted network traffic. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87590
- SUSE Bug 1279840
Описание
Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87591
- SUSE Bug 1279840
Описание
Out of bounds read in Tint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87592
- SUSE Bug 1279840
Описание
Information leak in Editing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87593
- SUSE Bug 1279840
Описание
Incorrect authorization in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87594
- SUSE Bug 1279840
Описание
Server-side request forgery in Mobile in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87595
- SUSE Bug 1279840
Описание
Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87596
- SUSE Bug 1279840
Описание
UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to spoof address bar via a co-installed app. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87597
- SUSE Bug 1279840
Описание
Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87598
- SUSE Bug 1279840
Описание
Improper input validation in Interstitials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87599
- SUSE Bug 1279840
Описание
Improper input validation in Safebrowsing in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87600
- SUSE Bug 1279840
Описание
Race condition in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87601
- SUSE Bug 1279840
Описание
Out of bounds read in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87602
- SUSE Bug 1279840
Описание
Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87603
- SUSE Bug 1279840
Описание
Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87604
- SUSE Bug 1279840
Описание
Missing authorization in Contacts in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87605
- SUSE Bug 1279840
Описание
Missing authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87606
- SUSE Bug 1279840
Описание
Use after free in Device in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87607
- SUSE Bug 1279840
Описание
Improper certificate validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87608
- SUSE Bug 1279840
Описание
Use after free in Sharing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87609
- SUSE Bug 1279840
Описание
Incorrect authorization in Omnibox in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87610
- SUSE Bug 1279840
Описание
Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87611
- SUSE Bug 1279840
Описание
Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87612
- SUSE Bug 1279840
Описание
Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87613
- SUSE Bug 1279840
Описание
Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87614
- SUSE Bug 1279840
Описание
Race condition in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87615
- SUSE Bug 1279840
Описание
Improper initialization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87616
- SUSE Bug 1279840
Описание
Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87617
- SUSE Bug 1279840
Описание
Incorrect reference resolution in Storage in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87618
- SUSE Bug 1279840
Описание
Observable discrepancy in Prefetch in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87619
- SUSE Bug 1279840
Описание
Observable discrepancy in SVG in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87620
- SUSE Bug 1279840
Описание
Out of bounds write in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87621
- SUSE Bug 1279840
Описание
Missing authorization in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87622
- SUSE Bug 1279840
Описание
Observable discrepancy in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87623
- SUSE Bug 1279840
Описание
UI misrepresentation in Passwords in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87624
- SUSE Bug 1279840
Описание
Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87625
- SUSE Bug 1279840
Описание
Incorrect authorization in DeviceBoundSessionCredentials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via crafted network traffic. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87626
- SUSE Bug 1279840
Описание
Interpretation conflict in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted file. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87627
- SUSE Bug 1279840
Описание
Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-87628
- SUSE Bug 1279840
Описание
Incorrect authorization in Sources in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87629
- SUSE Bug 1279840
Описание
Integer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87630
- SUSE Bug 1279840
Описание
Missing authorization in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87631
- SUSE Bug 1279840
Описание
Cross-site scripting in SanitizerAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87632
- SUSE Bug 1279840
Описание
Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87633
- SUSE Bug 1279840
Описание
Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87634
- SUSE Bug 1279840
Описание
UI misrepresentation in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87635
- SUSE Bug 1279840
Описание
Type confusion in XML in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87636
- SUSE Bug 1279840
Описание
Use after free in Extensions in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87637
- SUSE Bug 1279840
Описание
Out of bounds write in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87638
- SUSE Bug 1279840
Описание
Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87639
- SUSE Bug 1279840
Описание
Out of bounds read in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87640
- SUSE Bug 1279840
Описание
Race condition in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87641
- SUSE Bug 1279840
Описание
Uninitialized resource in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87642
- SUSE Bug 1279840
Описание
Integer overflow in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87643
- SUSE Bug 1279840
Описание
Incorrect authorization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87644
- SUSE Bug 1279840
Описание
Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87645
- SUSE Bug 1279840
Описание
Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87646
- SUSE Bug 1279840
Описание
Uninitialized resource in GPU in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87647
- SUSE Bug 1279840
Описание
Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87648
- SUSE Bug 1279840
Описание
UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87649
- SUSE Bug 1279840
Описание
Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87650
- SUSE Bug 1279840
Описание
Incorrect authorization in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87651
- SUSE Bug 1279840
Описание
Incorrect authorization in PushAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87652
- SUSE Bug 1279840
Описание
UI misrepresentation in FullScreen in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87653
- SUSE Bug 1279840
Описание
Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-87654
- SUSE Bug 1279840
Описание
Clickjacking in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87655
- SUSE Bug 1279840
Описание
Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-87656
- SUSE Bug 1279840
Описание
Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87657
- SUSE Bug 1279840
Описание
Information leak in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-87658
- SUSE Bug 1279840