ZeroHour
Organization

Debian

1 mentions in 7 days · 3 in 30 days · 3 total · first seen · last

Timeline

CVE-2026-87464: RCE outside sandbox in Chromium prior to 153.0.8010.36

CVE-2026-87464 is a critical use-after-free in Chrome's WebGL allowing sandbox-escaping RCE via crafted HTML pages, fixed in 153.0.8010.36.

Google Chrome prior to 153.0.8010.36 contains a use-after-free in WebGL that allows a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. Google rates it as Chromium security severity Critical, though tracker details are restricted. Debian indicates all current Chromium packages are affected, and the flaw likely impacts Chromium-derived browsers. No active exploitation is mentioned in the disclosure.

oss-security · 5d agoVulnerabilityCVE-2026-87464

Re: Vulnerabilities fixed in libxml2-2.15.4

libxml2 2.15.4 patches two flaws including a heap buffer overflow in xmlDictAddQString tracked as CVE-2026-86137 and CVE-2026-86138.

libxml2 releases before 2.15.4 are affected by an integer overflow in xmlDictAddQString in dict.c that leads to a heap-based buffer overflow, tracked as CVE-2026-86137 and CVE-2026-86138. The oss-security post from Debian's Salvatore Bonaccorso flags the fixed release for downstream tracking. No exploitation is mentioned in the disclosure.

Debian developers rejected an LLM ban and left disclosure voluntary

Debian developers voted to encourage voluntary disclosure of AI assistance in contributions rather than banning or mandating labeling of LLM-generated code.

Debian's vote concluded August 28, with project secretary Kurt Roeckx announcing that the winning option encourages contributors to disclose generative AI assistance and stops there, adding no new mandatory review gates. The adopted resolution bars sending confidential material, embargoed security bugs, cryptographic keys and credentials to third-party AI services without explicit authorization, requires prior discussion for bulk automated work, and takes no position on whether model output is copyrightable. The project neither endorses nor prohibits generative AI and retains existing human review and licensing requirements.

Help Net Security · 15d agoAI policy

Related CVEs

  • Use-After-Free in WebGL in Google Chrome Allows Code Execution Outside the Sandbox
    CVE-2026-87464 is a use-after-free (CWE-416) in the WebGL component of Google Chrome affecting versions prior to 153.0.8010.36. A remote attacker can trigger it by luring a user to open a crafted HTML page, which corrupts memory in the browser's WebGL rendering path. Successful exploitation allows arbitrary code execution outside the browser sandbox, meaning the attacker escapes Chrome's process isolation and runs code with the privileges of the browser on the host. All Chrome users running an unpatched version before 153.0.8010.36 are affected. As of now there is no public proof-of-concept and this specific flaw is not in CISA KEV, although the Chrome 153 release headlines reference a separate V8 zero-day that was exploited in the wild.
    · google chrome all versions prior to 153.0.8010.36mass
  • Heap Buffer Overflow via Integer Overflow in libxml2 before 2.15.4
    CVE-2026-86138 is an integer overflow (CWE-190) in xmlDictAddQString in dict.c of libxml2, the widely used XML parsing library; the miscalculated size calculation leads to a heap-based buffer overflow. It is triggered when an application built on an affected libxml2 processes crafted XML (or other structured input) that exercises the library's qualified-string dictionary handling in a way that makes a computed length wrap around, producing an undersized allocation and an out-of-bounds heap write; the CVSS vector (AV:L/AC:H) indicates the attack path requires local access or locally processed crafted input and that exploitation conditions are narrow. An attacker who triggers the bug gains heap memory corruption with the privileges of the affected process, with high confidentiality and integrity impact and low availability impact per the CVSS score, ranging from crashes to potentially limited code execution. Anyone deploying or embedding libxml2 versions before 2.15.4 is affected, which spans a very large share of Linux/Unix systems, language runtimes, and applications that parse XML. There is currently no public proof-of-concept, no CISA KEV listing, and a 0.1% EPSS score, indicating no known exploitation.
    · libxml2 (upstream project) libxml2 all versions prior to 2.15.4 (fixed in 2.15.4)mass
  • Out-of-bounds read in libxml2 XML regexp parser fixed in 2.15.4
    CVE-2026-86137 is an out-of-bounds read (CWE-125) in libxml2's xmlFAParsePosCharGroup function, in the NXT macro of the xmlregexp regular-expression engine, fixed in libxml2 2.15.4. It is triggered when an application uses libxml2 to parse a regular-expression pattern that reaches the character-group parsing code path; the high-complexity CVSS component indicates a carefully formed input is needed to reach the faulty read. The practical impact is minimal: the vector is local (AV:L) with no confidentiality or integrity impact and only limited availability loss, so the realistic worst case is a crash or partial disruption of the parsing process rather than code execution or data disclosure. Any software that ships, links, or bundles a version of libxml2 prior to 2.15.4 is affected, which includes a very large installed base given how widely the library is embedded. Exploitation status is quiet: there is no public proof of concept, the flaw is not in CISA's KEV, and EPSS puts exploitation probability at 0.1% over the next 30 days.
    · GNOME (libxml2 project) libxml2 all versions prior to 2.15.4 PoC mass

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.