CVE-2026-78937
Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to po
CVSS
9.6
Critical
EPSS
0.4%
p31
KEV
—
Exploit Today
9
0-100
Published: Aug 25, 2026 · Last modified: Aug 27, 2026 · CWE-416
0.3%EPSS · 30 days0.4%
2026-08-262026-09-19
Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-940553.7 LOW—
———Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.4hCVE-2026-880978.1 HIG12.7%
——4Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.13hCVE-2026-935862.9 LOW1.7%
——1ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, caused by a pointer that is not updated correctly. Exploitation may result in a limited availability impact (e.g., a crash of the affected process). The issue is fixed in versions 7.1.2-31 and 6.9.13-56.1dCVE-2026-933828.8 HIG31.2%
——9Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)23hCVE-2026-933749.6 CRI29.2%
——9Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)23hCVE-2026-933739.6 CRI23.4%
——7Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: High)23h