CVE-2026-87472
Improper input validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Scoring
- CVSS base score
- 1.5
- CWE
- CWE-20
- Published
- 2026-09-09
- Last modified
- 2026-09-09
Affected products
- Google Chrome
Weakness type
Related vulnerabilities
- CVE-2026-74761 — Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of RemoveSubscription clientId
- CVE-2026-73334 — Apache Parquet Hadoop: File-controlled KMS URL is forwarded to pluggable KmsClient that skips host validation
- CVE-2025-7062 — Stored Cross-Site Scripting via file upload in H5P module (h5p-nodejs-library) of Lumi Education
- CVE-2026-12855 — H19WMIHandlerSmm: unvalidated memory boundary could result in arbitrary code execution.
- CVE-2026-87083 — tile-ai tilelang Kernel Cache kernel_cache.py KernelCache._load_kernel_from_disk deserialization
- CVE-2026-87469 — Improper input validation in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote...
- CVE-2026-87568 — Improper input validation in Chromium in Google Chrome prior to 153.0.8010.36 allowed a remote...
- CVE-2026-87510 — Improper input validation in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote...