[NEU] [hoch] Google Chrome: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff
Ein Angreifer kann mehrere Schwachstellen in Google Chrome ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Umgehung von Sicherheitsmaßnahmen, die Ausweitung von Berechtigungen, die Offenlegung sensibler Informationen, die Durchführung von XSS-Angriffen oder das Auslösen eines Denial-of-Service-Zustands.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3238
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-874290.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-874300.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-874310.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-874320.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-874330.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-874340.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-874350.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-874360.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-874370.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-874380.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownexploitedGoogle Chrome Multiple Vulnerabilitieshkcert
- criticalCVE-2026-87488: Use after free in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote…nvd
- highCVE-2026-87487: Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote a…nvd
- mediumCVE-2026-87486: Clickjacking in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 all…nvd
- lowCVE-2026-87485: Incorrect authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attac…nvd
- mediumCVE-2026-87484: UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allowed a remote atta…nvd
- unknownCVE-2026-87483: Incorrect authorization in Browser in Google Chrome on on Android prior to 153.0.8010.36 allow…nvd
- unknownCVE-2026-87482: Cleartext transmission of sensitive data in HttpsUpgrades in Google Chrome on on iOS prior to …nvd
- highCVE-2026-87481: Incorrect authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allow…nvd
- highCVE-2026-87480: Use after free in Printing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker w…nvd
- highCVE-2026-87479: Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed …nvd
- mediumCVE-2026-87478: Observable discrepancy in Autofill in Google Chrome prior to 153.0.8010.36 allowed a remote at…nvd
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [mittel] OpenSSH: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-10
- high[UPDATE] [hoch] OpenVPN: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] gzip: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-10