Threat Brief — 2026-09-15 — Chromium Patch Batch Floods 20 CVEs
Microsoft Edge has published advisories for 20 Chromium-origin vulnerabilities spanning the browser's core engine, graphics stack, and security-critical subsystems. The highest-impact class is use-after-free in V8 (CVE-2026-87657), which typically enables remote code execution through a malicious web page. No public exploits or KEV listings are indicated for any of these CVEs. The Sandworm/Cyclops Blink story covered yesterday has no new development.
Top items
- Chromium V8 use-after-free (CVE-2026-87657) — A use-after-free in the V8 JavaScript engine is the most serious of the batch; V8 UAF flaws are routinely weaponised for full browser compromise via a crafted web page. Affects all Chromium-based browsers including Google Chrome and Microsoft Edge. (src: MSRC)
- Chromium Media out-of-bounds write (CVE-2026-87638) — An out-of-bounds write in the Media subsystem; memory-corruption flaws in media parsing are a common attack vector via embedded video or audio on a webpage. Affects Chrome and Edge. (src: MSRC)
- Chromium ANGLE buffer overflow (CVE-2026-87654) — A buffer overflow in ANGLE (the OpenGL-to-Direct3D translation layer) could corrupt memory through WebGL rendering operations. Affects Chrome and Edge. (src: MSRC)
- Chromium use-after-free cluster (CVE-2026-87637, -87639, -87646, -87648) — Four additional UAF vulnerabilities in Extensions, WebPackaging, Web Authentication, and ANGLE. Each represents a memory-safety defect exploitable for code execution or sandbox escape depending on the affected component. (src: MSRC — CVE-2026-87637, CVE-2026-87639, CVE-2026-87646, CVE-2026-87648)
- Chromium authorisation and state-validation flaws (CVE-2026-87644, -87645, -87651, -87652, -87656) — Five issues involving incorrect authorisation (Views, Paint, PushAPI) and improper state validation (Safebrowsing ×2). These could allow bypass of browser security boundaries or silent failure of protective controls. (src: MSRC — CVE-2026-87644, CVE-2026-87645, CVE-2026-87651, CVE-2026-87652, CVE-2026-87656)
- Chromium UI deception and clickjacking (CVE-2026-87649, -87653, -87655) — UI misrepresentation in Downloads and FullScreen plus a clickjacking flaw in Downloads could trick users into approving malicious downloads or granting permissions. (src: MSRC — CVE-2026-87649, CVE-2026-87653, CVE-2026-87655)
- Chromium memory-read and info-leak flaws (CVE-2026-87642, -87647, -87650, -87658) — Uninitialised-resource issues in WebGL and GPU, an out-of-bounds read in WebGL, and an information leak in Extensions could expose sensitive browser-state data to attackers. (src: MSRC — CVE-2026-87642, CVE-2026-87647, CVE-2026-87650, CVE-2026-87658)
- Chromium browser race condition (CVE-2026-87641) — A race condition in the Browser component could lead to inconsistent state handling exploitable for privilege escalation within the browser process. (src: MSRC)
Themes
Broad Chromium surface area: The 20 CVEs touch virtually every major browser subsystem — V8, WebGL/ANGLE, Media, Extensions, Safebrowsing, Downloads, Web Authentication, PushAPI, and the core Browser process. This breadth is consistent with a major Chromium stable-channel update; the MSRC advisories are mirroring Google Chrome release notes, and Edge inherits all fixes. The absence of any exploit or KEV tagging suggests these are pre-disclosure or coordinated patches rather than in-the-wild emergencies, but the V8 and ANGLE memory-corruption flaws warrant priority attention as they are the most likely to be reverse-engineered.
