PatchSiren

Google CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Google CVE published 2026-08-06

CVE-2026-19177

The CVE-2026-19177 vulnerability is caused by insufficient validation of untrusted input in the UI of Google Chrome versions prior to 151.0.7922.109. This allows a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The Chromium security severity of this issue is High, with a CVSS score of 8.3. Affected product context indicates Google [truncated]

CRITICAL Google CVE published 2026-08-06

CVE-2026-19175

The CVE-2026-19175 vulnerability is a use-after-free issue in the Payments component of Google Chrome prior to version 151.0.7922.109. This vulnerability allows a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The CVSS score of 9.6 and critical severity highlight the importance of applying the patch. The vulnerability impacts Google Chrome users, particularly those in env [truncated]

HIGH Google CVE published 2026-08-06

CVE-2026-19174

The CVE-2026-19174 vulnerability is an integer overflow in V8 in Google Chrome prior to 151.0.7922.109. This vulnerability, with a CVSS score of 8.8, could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The Chromium security severity is rated as High. The vulnerability affects Google Chrome users who have not upgraded to version 151.0.7922.109 or later. Evidenc [truncated]

HIGH Google CVE published 2026-08-06

CVE-2026-19173

The CVE-2026-19173 vulnerability is an out-of-bounds write issue in Skia in Google Chrome prior to 151.0.7922.109. This issue allows a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The vulnerability has a high CVSS score of 8.3 and is classified as High severity by Chromium. Users of Google Chrome should apply the patch to prevent [truncated]

HIGH Google CVE published 2026-08-06

CVE-2026-19172

The CVE-2026-19172 vulnerability is a use-after-free issue in the Views component of Google Chrome prior to version 151.0.7922.109. This vulnerability could allow a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. The Chromium security severity of this issue is Critical. The vulnerability affects Google Chrome users, particularly a [truncated]

CRITICAL Google CVE published 2026-08-06

CVE-2026-19171

The CVE-2026-19171 vulnerability is a use-after-free issue in the Media component of Google Chrome on Windows. This vulnerability can be exploited by a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability has a CVSS score of 9.6, indicating a high severity level. Affected product context includes Google Chrome on Windows prior to version 151.0.7922.109. The CV [truncated]

CRITICAL Google CVE published 2026-08-06

CVE-2026-19170

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:16:59.480Z and has not been modified since then. The NVD entry is currently Analyzed. This Critical use-after-free vulnerability in WebGL in Google Chrome on Android prior to 151.0.7922.109 allows a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerabil [truncated]

HIGH Google CVE published 2026-08-06

CVE-2026-19169

The CVE-2026-19169 vulnerability is caused by insufficient validation of untrusted input in Contextual Tasks in Google Chrome prior to 151.0.7922.109. This allows a remote attacker to perform privilege escalation via a crafted HTML page. The Chromium security severity is High, with a CVSS score of 8.8. Administrators and users of Google Chrome should be aware of this vulnerability and take immediate actio [truncated]

HIGH Google CVE published 2026-08-06

CVE-2026-19168

The CVE-2026-19168 vulnerability, caused by an inappropriate implementation in the V8 engine of Google Chrome, allows a remote attacker to execute arbitrary code inside a sandbox via a specially crafted HTML page. This High severity vulnerability has a CVSS score of 8.8. The affected product is Google Chrome, and users should ensure they are running the latest version of the browser to prevent potential e [truncated]

LOW Google CVE published 2026-08-06

CVE-2026-19167

The CVE-2026-19167 vulnerability is an integer overflow in the GPU of Google Chrome, which occurred prior to version 151.0.7922.109. This allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. The technical impact of this vulnerability is that an attacker could potentially access sensitive data from other origins, which could lead to further e [truncated]

CRITICAL Google CVE published 2026-08-06

CVE-2026-19166

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:16:59.037Z and has not been modified since then. The CVE-2026-19166 vulnerability is a use-after-free issue in Web Authentication in Google Chrome prior to 151.0.7922.109. This could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability has [truncated]

HIGH Google CVE published 2026-08-06

CVE-2026-19165

CVE-2026-19165 is a high severity use after free vulnerability in Google Chrome Extensions prior to version 151.0.7922.109. An attacker who convinces a user to install a malicious extension can execute arbitrary code inside a sandbox via a crafted Chrome Extension. This type of vulnerability can lead to code execution, data theft, or other malicious activities if exploited. The vulnerability affects Googl [truncated]

CRITICAL Google CVE published 2026-08-06

CVE-2026-19164

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:16:58.803Z and has not been modified since then. This vulnerability, CVE-2026-19164, is a critical issue in Google Chrome prior to version 151.0.7922.109, allowing potential sandbox escapes via crafted HTML pages due to insufficient validation of untrusted input in Codecs. The CVSS Score is 9. [truncated]

HIGH Google CVE published 2026-08-06

CVE-2026-19163

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:16:58.690Z and has not been modified since then. This vulnerability, CVE-2026-19163, is a use-after-free issue in the Media component of Google Chrome on Windows. It allows a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML pag [truncated]

HIGH Google CVE published 2026-08-06

CVE-2026-19162

The CVE-2026-19162 vulnerability is an out-of-bounds write issue in the V8 engine of Google Chrome versions prior to 151.0.7922.109. This vulnerability, with a CVSS score of 8.8, can be exploited by a remote attacker to execute arbitrary code within a sandbox environment by providing a crafted HTML page. The Chromium security severity is rated as High. Administrators and users of Google Chrome should prio [truncated]

LOW Google CVE published 2026-08-06

CVE-2026-19160

The CVE-2026-19160 vulnerability is an uninitialized use issue in the Skia library within Google Chrome, which allows a remote attacker who has compromised the renderer process to leak cross-origin data via a crafted HTML page. This vulnerability has a CVSS score of 3.1 and is rated as High severity by Chromium. Affected product deployments should be reviewed for exposure, and owners should be assigned fo [truncated]

HIGH Google CVE published 2026-08-06

CVE-2026-19159

The CVE-2026-19159 vulnerability is a use-after-free issue in the Views component of Google Chrome prior to version 151.0.7922.109. This vulnerability could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page, requiring the user to engage in specific UI gestures. The Chromium security severity is rated as High with a CVSS score of 7.5. Affected product deployments should [truncated]

HIGH Google CVE published 2026-08-06

CVE-2026-19158

The CVE-2026-19158 vulnerability is a use-after-free issue in the Views component of Google Chrome on Windows, prior to version 151.0.7922.109. This vulnerability could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page, requiring the user to engage in specific UI gestures. The Chromium security severity is rated as High with a CVSS score of 7.5. Affected product deploy [truncated]

CRITICAL Google CVE published 2026-08-06

CVE-2026-19157

CVE-2026-19157 is a critical out-of-bounds write vulnerability in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome on Android. This vulnerability, prior to version 151.0.7922.109, could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The Chromium security team classified this issue as Critical. Affected product deployments require immediate attentio [truncated]

HIGH Google CVE published 2026-08-06

CVE-2026-19156

The CVE-2026-19156 vulnerability is a heap buffer overflow in Google Chrome prior to version 151.0.7922.109. This vulnerability can be exploited by an attacker who convinces a user to install a malicious extension, potentially leading to heap corruption. The Chromium security severity is rated as High, with a CVSS score of 7.5. Users of Chrome should ensure they are updated to version 151.0.7922.109 or la [truncated]

HIGH Google CVE published 2026-08-06

CVE-2026-19155

The CVE-2026-19155 vulnerability is a use-after-free issue in the Payments component of Google Chrome prior to version 151.0.7922.109. This issue allows a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The vulnerability has been classified as High severity by Chromium, with a CVSS score of 8.3. Affected product deployments should b [truncated]

HIGH Google CVE published 2026-08-06

CVE-2026-19154

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:16:57.660Z and has not been modified since then. This use-after-free vulnerability in Skia affects Google Chrome on Android, allowing a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability has a CVSS score of 8.3 and is considered Critical. Defende [truncated]

HIGH Google CVE published 2026-08-06

CVE-2026-19151

CVE-2026-19151 is a high severity use-after-free vulnerability in the V8 engine of Google Chrome prior to version 151.0.7922.109. The vulnerability allows remote attackers to execute arbitrary code inside a sandbox via a crafted HTML page. This issue is caused by a use-after-free error in the V8 engine, which can lead to high impact attacks. Organizations and individuals using Google Chrome prior to versi [truncated]

HIGH Google CVE published 2026-08-06

CVE-2026-19150

The CVE-2026-19150 vulnerability is caused by an inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109. This allows remote attackers to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability has a high security severity according to Chromium and a CVSS score of 8.8. Organizations should review their Chrome installations and ensure they are updated to the l [truncated]

CRITICAL Google CVE published 2026-08-06

CVE-2026-19149

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:16:57.113Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability, CVE-2026-19149, is a use-after-free issue in Aura within Google Chrome on Linux systems, which could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page [truncated]

HIGH Google CVE published 2026-08-06

CVE-2026-19147

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:16:56.887Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. This high severity use after free vulnerability exists in Google Chrome on Linux, prior to version 151.0.7922.109, in the Aura component. It could allow a remote attacker who has compromised the re [truncated]

HIGH Google CVE published 2026-08-06

CVE-2026-19145

CVE-2026-19145 is a high-severity use-after-free vulnerability in Google Chrome's Translate feature, prior to version 151.0.7922.109. This issue allows remote attackers to execute arbitrary code within a sandbox environment via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and is classified as High severity by the Chromium security team. Organizations and individuals using Google Chrome, [truncated]

HIGH Google CVE published 2026-08-06

CVE-2026-19144

The CVE-2026-19144 vulnerability is a use-after-free issue in the HTML component of Google Chrome prior to version 151.0.7922.109. This vulnerability can be exploited by a remote attacker to potentially corrupt heap memory by providing a specially crafted HTML page. The vulnerability has been assigned a high CVSS score of 8.8 and a High severity rating by Chromium. The affected product is Google Chrome, a [truncated]

HIGH Google CVE published 2026-08-06

CVE-2026-19143

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:16:56.423Z and has not been modified since then. The NVD entry is currently Analyzed. Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a local attacker to potentially perform a sandbox escape via a malicious file. This is a High [truncated]

HIGH Google CVE published 2026-08-06

CVE-2026-19142

The CVE-2026-19142 vulnerability is a use-after-free issue in the Views component of Google Chrome prior to version 151.0.7922.109. This vulnerability allows a remote attacker who can convince a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. The vulnerability has a CVSS score of 7.5 and is rated as High severity by the Chromium security team. Affecte [truncated]

HIGH Google CVE published 2026-08-06

CVE-2026-19141

A use-after-free vulnerability exists in the Resources component of Google Chrome on Android versions prior to 151.0.7922.109. This vulnerability, CVE-2026-19141, allows a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The vulnerability has been classified as High severity by the Chromium security team. The affected product is Goog [truncated]

HIGH Google CVE published 2026-08-06

CVE-2026-19140

The CVE-2026-19140 vulnerability is a use-after-free issue in the GPU of Google Chrome prior to version 151.0.7922.109. This vulnerability could allow a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. The Chromium security severity is rated as High. The CVSS score is 8.3 with AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H. Google Chrome user [truncated]

HIGH Google CVE published 2026-08-06

CVE-2026-19138

The CVE-2026-19138 vulnerability is a high-severity heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.109. This vulnerability allows a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The vulnerability's CVSS score is 8.3, indicating a high level of severity. Organizations and individuals using Google Chrome [truncated]

CRITICAL Google CVE published 2026-08-04

CVE-2026-0163

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T19:16:39.213Z and has not been modified since then. The CVE-2026-0163 vulnerability is a possible use after free in multiple functions of vpu_ioctl.c, leading to remote escalation of privilege with no additional execution privileges needed. This vulnerability has a CVSS score of 9.8, indicating a [truncated]

MEDIUM Google CVE published 2026-08-04

CVE-2026-10032

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T16:16:20.983Z and has not been modified since then. The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme, allowing for a stored/reflected XSS with Critical severity. Developers and administrators using @a2ui/web_core, es [truncated]

HIGH Google CVE published 2026-07-31

CVE-2026-14541

An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When a Google authService is initialized with mcpEnabled: true but lacks an explicitly defined audience or clientId, the ValidateMCPAuth pipeline for opaque tokens skips audience validation entirely. As a result, the toolbox will accept any valid Google OAuth acc [truncated]

HIGH Google CVE published 2026-07-31

CVE-2026-14540

A Server-Side Request Forgery (SSRF) vulnerability exists in Google mcp-toolbox versions 0.3.0 through 1.4.0. The underlying HTTP client fails to safely regulate request redirection boundaries due to a lack of restrictive CheckRedirect policy hook and target IP validation. This allows an attacker to supply a crafted path parameter that triggers an open redirect or direct destination swap, coercing the mcp [truncated]

MEDIUM Google CVE published 2026-07-31

CVE-2026-14539

An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up to and including 1.4.0 allows an unauthenticated attacker to cause a denial of service (DoS). The /mcp endpoint handler reads incoming payloads directly into system memory using an unrestricted buffer loop (io.ReadAll) without applying defensive constraints such as http.MaxBytesReader or [truncated]

MEDIUM Google CVE published 2026-07-31

CVE-2026-14538

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T02:16:28.757Z and has not been modified since then. The bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 through 1.4.0 has an improper authorization and security-boundary bypass vulnerability; an authenticated attacker can bypass allowedDatasets validation checks due to a [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17912

The CVE-2026-17912 vulnerability is related to an inappropriate implementation in Chrome for iOS prior to version 151.0.7922.72. This issue allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. The vulnerability has a Chromium security severity of Low and a CVSS score of 4.3, classified as MEDIUM. Defenders and administrators responsible for Chrome for iOS installations shou [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17900

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:54.053Z and has not been modified since then. This vulnerability, CVE-2026-17900, is related to an inappropriate implementation in Enterprise in Google Chrome on Windows prior to 151.0.7922.72. It allowed a remote attacker to leak cross-origin data via a malicious file, with a CVSS score of [truncated]

HIGH Google CVE published 2026-07-30

CVE-2026-17898

CVE-2026-17898 is a use after free vulnerability in DevTools in Google Chrome prior to 151.0.7922.72. This issue allows an attacker who convinces a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. The Chromium security severity is rated as Low, but the CVSS score is 7.5, indicating HIGH severity. The vulnerability affects Google Chrome users [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17897

The CVE-2026-17897 vulnerability, caused by an inappropriate implementation in ORB in Google Chrome prior to version 151.0.7922.72, allows a remote attacker to leak cross-origin data via a crafted HTML page. This medium-severity vulnerability, with a CVSS score of 4.3, requires immediate attention to prevent potential data leaks. Organizations and individuals using Google Chrome for browsing, especially t [truncated]

HIGH Google CVE published 2026-07-30

CVE-2026-17896

CVE-2026-17896 is a use-after-free vulnerability in Google Chrome's DevTools, affecting versions prior to 151.0.7922.72. This Medium-severity issue, with a CVSS score of 7.5, allows remote attackers to execute arbitrary code inside a sandbox via crafted HTML pages. Users of Google Chrome, particularly those utilizing DevTools in development, testing, and production environments, should be aware and take i [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17895

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:53.533Z and has not been modified since then. The CVE-2026-17895 vulnerability in Google Chrome's DataTransfer implementation allows a remote attacker to leak cross-origin data via a crafted HTML page, requiring user interaction. The vulnerability has a CVSS score of 4.3 and is classified a [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17893

Insufficient validation of untrusted input in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects Google Chrome on Mac, particularly versions prior to 151.0.7922.72. The CVE record was published on 2026-07-30T01:16:53.313Z and has not been modifi [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17892

The CVE-2026-17892 vulnerability is caused by an inappropriate implementation in WebXR in Google Chrome prior to 151.0.7922.72. This allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. The vulnerability has a CVSS score of 6.5 and a Chromium security severity of Medium. Affected product context indicates Google Chrome users are impacted, requir [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17890

A PatchSiren debrief based on CVE-2026-17890. Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. This vulnerability, classified as CWE-20, has a CVSS score of 5.8 and a severity of Medium. It affects Google Chrome prior to version 1 [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17889

CVE-2026-17889 is an uninitialized use vulnerability in WebXR within Google Chrome prior to version 151.0.7922.72. This vulnerability allows a remote attacker to leak cross-origin data via a crafted HTML page. The issue has been rated as Medium severity by the Chromium security team, with a CVSS score of 4.3. Affected product deployments exist in managed environments and require immediate attention to pre [truncated]

HIGH Google CVE published 2026-07-30

CVE-2026-17888

The CVE-2026-17888 vulnerability is caused by insufficient validation of untrusted input in WebUI in Google Chrome prior to 151.0.7922.72. This allows a remote attacker to potentially perform a sandbox escape via malicious network traffic. The Chromium security severity is Medium, with a CVSS score of 7.1. Users and administrators of Google Chrome should be aware of this vulnerability and take immediate a [truncated]