Google Chrome Multiple Vulnerabilities
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Details
Original advisory: https://www.hkcert.org/security-bulletin/google-chrome-multiple-vulnerabilities_20260910
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-87491Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-874290.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-874300.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-874310.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-874320.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-874330.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-874340.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-874350.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-874360.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-874370.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownexploitedGoogle security advisory (AV26-904)cccs
- highexploitedCISA Adds Four Known Exploited Vulnerabilities to Catalogcisa
- unknownexploitedNCSC-2026-0354 [1.00] [M/H] Kwetsbaarheid verholpen in Google Chromencsc-nl
- high[NEU] [hoch] Google Chrome: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriffcert-bund
- highexploitedCVE-2026-87491: Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to…nvd
- highCVE-2026-87487: Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote a…nvd
- mediumCVE-2026-87486: Clickjacking in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 all…nvd
- lowCVE-2026-87485: Incorrect authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attac…nvd
- mediumCVE-2026-87484: UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allowed a remote atta…nvd
- unknownCVE-2026-87483: Incorrect authorization in Browser in Google Chrome on on Android prior to 153.0.8010.36 allow…nvd
- unknownCVE-2026-87482: Cleartext transmission of sensitive data in HttpsUpgrades in Google Chrome on on iOS prior to …nvd
- highCVE-2026-87481: Incorrect authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allow…nvd
More from HKCERT Security Bulletins
- unknownPalo Alto Products Multiple Vulnerabilities2026-09-10
- unknownMongoDB Multiple Vulnerabilities2026-09-10
- unknownCitrix Products Multiple Vulnerabilities2026-09-10
- unknownAdobe Monthly Security Update (September 2026)2026-09-09
- unknownMozilla Firefox Denial of Service Vulnerability2026-09-09