[NEW] [high] Google Chrome: Multiple Vulnerabilities Enable Unspecified Attack
An attacker can exploit multiple vulnerabilities in Google Chrome to cause unspecified impacts, including potentially arbitrary code execution, bypass of security measures, disclosure of information, or a denial-of-service condition.
CSIRTS triage
- What
- Multiple vulnerabilities enable unspecified attacks including arbitrary code execution, security bypass, information disclosure, and denial of service.
- Who is affected
- Chrome users running vulnerable versions.
- Urgency
- High; multiple critical vulnerability classes identified.
- Action
- Update Chrome to the latest available version immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Chrome
Get an email when a new Chrome advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2790
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-195560.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-195570.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-195580.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-195590.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-195600.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-19556 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19557 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19558 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19559 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19560 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMicrosoft Edge Multiple Vulnerabilitieshkcert
- unknownDSA-6436-1 chromium - security updatedebian
- unknownGoogle Chrome Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Google Chrome (August 12, 2026)cert-fr-avis
- highCVE-2026-19560: Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to …nvd
- highCVE-2026-19559: Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to e…nvd
- highCVE-2026-19558: Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who …nvd
- highCVE-2026-19557: Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote at…nvd
- highCVE-2026-19556: Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to exe…nvd
- unknownCVE-2026-19560: Chromium: CVE-2026-19560 Use after free in Blinkmsrc
- unknownCVE-2026-19556: Chromium: CVE-2026-19556 Use after free in V8msrc
- unknownCVE-2026-19559: Chromium: CVE-2026-19559 Use after free in HTMLmsrc
More from CERT-Bund (BSI) Security Advisories
- medium[NEW] [medium] Red Hat Enterprise Linux (yelp, dracut): Multiple vulnerabilities2026-08-14
- medium[NEW] [medium] PJSIP: Vulnerability enables manipulation of files2026-08-14
- high[NEW] [high] Internet Systems Consortium BIND: Multiple vulnerabilities2026-08-14
- high[NEW] [high] Microsoft Developer Tools: Multiple Vulnerabilities2026-08-14
- high[NEW] [high] Golang Go: Multiple vulnerabilities2026-08-14