← nejvýznamnější zprávy

SPOJENO AI KEV ✓ EPSS 0.01

Google warns of new Chrome zero-day bug exploited in attacks

Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year. [...]

10 zpráv z 9 zdrojů · první 9. 9. 02:00 · poslední 14. 9. 02:00 CZ · EN/orig

Microsoft Google Chrome FR HR US FI CA NL IT

tg: zneužíváno tg: zranitelnost tg: novinka v produktu

CVE v události 1

CVEhodnoceníKEVEPSS
CVE-2026-87491 8.8 3.1 · CISA-ADP KEV ✓ 0.01

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.6.

Dalších 5 CVE zmiňuje jen text zpravodajského článku (CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, CVE-2026-85046). Nejsou to identifikátory téhle události, proto nejsou v tabulce ani v odznacích.

Jak se o tom psalo 10

  1. · CERT-FR – avis FR

    Multiples vulnérabilités dans Microsoft Edge (14 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer un contournement de la politique de sécurité et un problème de sécurité non spécifié par l'éditeur. Microsoft indique que la vulnérabilité CVE-2026-87491 est activement exploitée.

  2. · CERT.hr HR

    Google je izdao zakrpe za 230 ranjivosti. Ažurirajte Chrome preglednik.

    Google je objavio sigurnosno ažuriranje kojim se otklanja ukupno 230 ranjivosti, među kojima se nalazi i ranjivost nultog dana Chrome preglednika koja se aktivno iskorištava u napadima. Google je počeo distribuirati zakrpane verzije za Windows (153.0.8010.36), Mac (153.0.8010.37) i Linux (153.0.8010.36), dva dana nakon što je ranjivost prijavljena. Ažuriranje bi do svih korisnika moglo stići za nekoliko dana ili tjedana, no korisnici ga mogu preuzeti i ranije putem automatske provjere…

  3. · Malwarebytes Labs US

    Update Chrome now to protect against an actively exploited vulnerability

    Chrome is rolling out an update for its desktop browser. The update includes 230 security fixes, one of which is known to be actively exploited. The stable channel has been updated to 153.0.8010.36/.37 for Windows and Mac, and 153.0.8010.36 for Linux. How to update Chrome If you don’t want to wait for the rollout to reach you, manually updating is easy. The easiest option is to allow Chrome to update automatically. But you can end up lagging behind on updates if you never close your browser or…

  4. · NCSC-FI FI

    Google Chrome Stable Channel Update

    Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: 9.6, CVEs: CVE-2026-87464, CVE-2026-87488, CVE-2026-87438, CVE-2026-87527, CVE-2026-87628, CVE-2026-87512, CVE-2026-87585, CVE-2026-87444, CVE-2026-87447, CVE-2026-87440, CVE-2026-87633, CVE-2026-87525, CVE-2026-87578, CVE-2026-87517, CVE-2026-87524, CVE-2026-87569, CVE-2026-87554, CVE-2026-87467, CVE-2026-87492, CVE-2026-87520 (+210 other associated CVEs), Summary: The Chrome team is delighted to announce the…

  5. · Cyber Centre Kanada CA

    Google security advisory (AV26-904)

    Serial Number: AV26-904Date: September 9, 2026 As of September 8, 2026, Google is affected by vulnerabilities in the following product: Chrome Prior to 153.0.8010.37 Google is aware that an exploit for CVE-2026-87491 exists in the wild. On September 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-87491 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any…

  6. · NCSC-NL NL

    NCSC-2026-0354 [1.00] [M/H] Kwetsbaarheid verholpen in Google Chrome

    Google heeft een zeroday-kwetsbaarheid verholpen in de V8 JavaScript engine van Google Chrome. Google meldt dat de kwetsbaarheid met kenmerk CVE-2026-87491 actief wordt misbruikt. Het betreft een out-of-bounds write in de V8-engine van Google Chrome, die voorkomt in versies vóór 153.0.8010.36. Een kwaadwillende kan een speciaal vervaardigde HTML-pagina gebruiken om de kwetsbaarheid te activeren en binnen de sandbox willekeurige code uit te voeren. De kwetsbaarheid wordt veroorzaakt door…

  7. · CSIRT Itálie (ACN) IT

    Risolte vulnerabilità in Google Chrome

    Google ha rilasciato un aggiornamento per il browser Chrome al fine di correggere 230 nuove vulnerabilità di sicurezza, di cui 5 con gravità “critica” e 41 con gravità “alta”.

  8. · BleepingComputer US nadpis události

    Google warns of new Chrome zero-day bug exploited in attacks

    Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year. [...]

  9. · CISA KEV US

    Google Chromium V8 Out of Bounds Write Vulnerability (CVE-2026-87491)

    CISA added CVE-2026-87491 to the Known Exploited Vulnerabilities catalog. Affected product: Google Chromium V8. Remediation due date: 2026-09-23.

  10. · CERT-FR – avis FR

    Multiples vulnérabilités dans Google Chrome (09 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur. Google indique que la vulnérabilité CVE-2026-87491 est activement exploitée.