CVE-2026-25278
Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.
CVSS
7.8
High
EPSS
0.1%
p0
KEV
—
Exploit Today
0
0-100
Published: Sep 17, 2026 · Last modified: Sep 17, 2026 · CWE-367
Not enough EPSS history yet.
Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-112226.4 MED20.7%
——6GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed a developer user to perform actions in the context of another user's merge request commit due to a race condition issue in pipeline creation.20hCVE-2026-917488.3 HIG11.8%
——4Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)20hCVE-2026-917445.3 MED13.4%
——4Race condition in PlatformIntegration in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)1dCVE-2026-917438.3 HIG14.7%
——4Race condition in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)20hCVE-2026-917128.3 HIG16.6%
——5Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)20hCVE-2026-917083.1 LOW4.6%
——1Race condition in Network in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)1d