PatchSiren

Google CVE debriefs · Page 10

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Google CVE published 2026-08-25

CVE-2026-78969

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T21:17:53.120Z and has not been modified since then. The CVE-2026-78969 vulnerability is caused by an uninitialized resource in the Video component of Google Chrome prior to version 152.0.7977.65. This issue allows a remote attacker to read memory inside the sandbox via a crafted HTML page. The vu [truncated]

MEDIUM Google CVE published 2026-08-25

CVE-2026-78967

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T21:17:52.847Z and has not been modified since then. The CVE-2026-78967 vulnerability is related to missing authorization in BFCache in Google Chrome prior to 152.0.7977.65. This allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted H [truncated]

MEDIUM Google CVE published 2026-08-25

CVE-2026-78965

The CVE-2026-78965 vulnerability, caused by an uninitialized resource in ANGLE within Google Chrome prior to version 152.0.7977.65, allows a remote attacker to obtain cross-origin data via a crafted HTML page. This issue has a CVSS score of 4.3, indicating a Medium severity level, and a High severity rating from Chromium. The vulnerability affects Google Chrome users, particularly those with high security [truncated]

LOW Google CVE published 2026-08-25

CVE-2026-78958

The CVE-2026-78958 vulnerability is related to an uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65. This vulnerability allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. The CVSS score is 3.1, and the severity is classified as LOW. Google Chrome users and administrators should be aware of this vulnerabil [truncated]

MEDIUM Google CVE published 2026-08-25

CVE-2026-78957

Information leak in Mobile in Google Chrome on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensitive information via a crafted file. This vulnerability, known as CVE-2026-78957, affects Google Chrome on iOS devices and has a CVSS score of 5.5, indicating a medium severity level. The vulnerability is caused by an information leak issue in Google Chrome on iOS, which can be exploited by a [truncated]

MEDIUM Google CVE published 2026-08-25

CVE-2026-78955

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T21:17:51.520Z and has not been modified since then. The vulnerability, CVE-2026-78955, involves an observable discrepancy in PerformanceAPIs in Google Chrome prior to version 152.0.7977.65. This issue allows a remote attacker to potentially obtain cross-origin data via a crafted HTML page. The CV [truncated]

LOW Google CVE published 2026-08-25

CVE-2026-78953

A CVE debrief for CVE-2026-78953, a missing authorization vulnerability in SiteIsolation in Google Chrome prior to 152.0.7977.65. This vulnerability allows a remote attacker who has compromised the renderer process to bypass site isolation via a crafted PDF file. Defenders responsible for managing Chrome deployments should assess and prioritize updating Chrome to version 152.0.7977.65 or later. The CVE re [truncated]

LOW Google CVE published 2026-08-25

CVE-2026-78941

Information leak in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. This vulnerability, tracked as CVE-2026-78941, poses a Low severity risk with a CVSS score of 3.1. The issue is confined to the Core component of Google Chrome, enabling an attacker to bypass site isolation through a specifica [truncated]

LOW Google CVE published 2026-08-25

CVE-2026-78936

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T21:17:49.383Z and has not been modified since then. CVE-2026-78936 is an observable discrepancy in CustomTabs in Google Chrome on Android prior to 152.0.7977.65. This vulnerability allows a local attacker to obtain cross-origin data via a co-installed app. The issue has a CVSS score of 2.9 and is [truncated]

HIGH Google CVE published 2026-08-25

CVE-2026-78910

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T21:17:48.473Z and has not been modified since then. The NVD entry is currently Received. The vulnerability is a buffer overflow in the V8 engine of Google Chrome prior to version 152.0.7977.65, allowing a remote attacker to execute arbitrary code within the sandbox. This Medium severity vulnerabi [truncated]

HIGH Google CVE published 2026-08-25

CVE-2026-78906

The CVE-2026-78906 record describes a race condition in ANGLE within Google Chrome, prior to version 152.0.7977.65. This vulnerability allows a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. The issue is classified as a Medium severity vulnerability by Chromium security. Google Chrome users, particularly those with automated browsing or high-risk browsin [truncated]

HIGH Google CVE published 2026-08-25

CVE-2026-78905

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T21:17:47.877Z and has not been modified since then. This type confusion vulnerability in ANGLE, affecting Google Chrome prior to version 152.0.7977.65, allows remote attackers to potentially execute arbitrary code outside the sandbox via a crafted HTML page. The vulnerability's technical impact i [truncated]

HIGH Google CVE published 2026-08-25

CVE-2026-78901

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T21:17:47.520Z and has not been modified since then. This vulnerability, CVE-2026-78901, is a race condition in V8 in Google Chrome prior to 152.0.7977.65, allowing a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. It is classified as a Medium severity issue b [truncated]

MEDIUM Google CVE published 2026-08-25

CVE-2026-78898

CVE-2026-78898 is a Medium severity vulnerability in Google Chrome prior to version 152.0.7977.65, related to incorrect authorization in Downloads. This allows a remote attacker to bypass system access restrictions via a crafted HTML page, leveraging social engineering tactics. The vulnerability has a CVSS score of 5.4. Users of Google Chrome prior to version 152.0.7977.65, IT administrators responsible f [truncated]

HIGH Google CVE published 2026-08-20

CVE-2026-76022

A high-severity buffer overflow vulnerability exists in the Network component of Google Chrome prior to version 151.0.7922.173. This vulnerability, CVE-2026-76022, allows a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. The vulnerability has been classified as High severity by the Chromium security team. The buffer overflow occurs when the browser processes a specia [truncated]

HIGH Google CVE published 2026-08-20

CVE-2026-76021

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-20T21:17:10.280Z and has not been modified since then. This use-after-free vulnerability in Google Chrome's DOM, prior to version 151.0.7922.173, allows remote attackers to execute arbitrary code inside the sandbox via a crafted HTML page. Organizations and individuals using Google Chrome for browsi [truncated]

HIGH Google CVE published 2026-08-20

CVE-2026-76020

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-20T21:17:10.167Z and has not been modified since then. CVE-2026-76020 indicates a race condition in V8 in Google Chrome prior to 151.0.7922.173. This High severity vulnerability, with a CVSS score of 7.5, allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. [truncated]

HIGH Google CVE published 2026-08-20

CVE-2026-76019

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-20T21:17:10.040Z and has not been modified since then. The vulnerability CVE-2026-76019 is related to incorrect authorization in Workers in Google Chrome prior to version 151.0.7922.173. This issue allowed a remote attacker who had compromised the renderer process and leveraged social engineering to [truncated]

HIGH Google CVE published 2026-08-20

CVE-2026-76017

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-20T21:17:09.800Z and has not been modified since then. This critical use-after-free vulnerability in Chromoting of Google Chrome versions prior to 151.0.7922.173 allows remote attackers to execute arbitrary code outside the sandbox via crafted network traffic. The vulnerability is caused by a use-af [truncated]

HIGH Google CVE published 2026-08-18

CVE-2026-76046

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:18:28.750Z and has not been modified since then. The CVE-2026-76046 vulnerability is a high severity buffer overflow issue in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome on Android platforms. This vulnerability occurs when a remote attacker compromises the render [truncated]

HIGH Google CVE published 2026-08-18

CVE-2026-76045

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:18:28.643Z and has not been modified since then. The CVE-2026-76045 vulnerability is a use-after-free issue in WebGL in Google Chrome prior to version 151.0.7922.169. This vulnerability could allow a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. The Chro [truncated]

HIGH Google CVE published 2026-08-18

CVE-2026-76044

The CVE-2026-76044 record indicates a high-severity vulnerability in Google Chrome, specifically a race condition in the USB component that could allow remote attackers to execute arbitrary code outside the sandbox. This vulnerability is particularly concerning as it involves the USB component, which could be exploited through specially designed USB devices or interactions. The vulnerability's impact is h [truncated]

LOW Google CVE published 2026-08-18

CVE-2026-76042

The CVE-2026-76042 vulnerability is a use of uninitialized resource issue in Google Chrome's GPU, which could allow a remote attacker to read memory outside the sandbox via a crafted HTML page. This type of vulnerability can have significant impacts on the security of Google Chrome users, particularly those who may be targeted by remote attackers. The vulnerability has a CVSS score of 3.1 and is considere [truncated]

MEDIUM Google CVE published 2026-08-18

CVE-2026-76041

An AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:18:28.173Z and has not been modified since then. CVE-2026-76041 is an information leak vulnerability in Skia, a component of Google Chrome. This vulnerability, with a CVSS score of 4.3, could allow a remote attacker to potentially bypass web origin policy via a crafted HTML page. The vulner [truncated]

HIGH Google CVE published 2026-08-18

CVE-2026-76040

The CVE-2026-76040 vulnerability is a use-after-free issue in the Browser component of Google Chrome on Mac systems, allowing remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page, leveraging social engineering tactics. This vulnerability has a high severity and requires immediate attention. The issue has been patched in Google Chrome version 151.0.7922.169. Users should a [truncated]

MEDIUM Google CVE published 2026-08-18

CVE-2026-76039

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:18:27.947Z and has not been modified since then. CVE-2026-76039 is a High severity vulnerability in Google Chrome on Android, allowing remote attackers to obtain sensitive information via crafted HTML pages. The vulnerability is due to incorrect reference resolution in Core. User interaction i [truncated]

CRITICAL Google CVE published 2026-08-18

CVE-2026-76035

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:18:27.500Z and has not been modified since then. This critical vulnerability, CVE-2026-76035, exists in Google Chrome on Mac systems prior to version 151.0.7922.169. It is caused by an inappropriate implementation in the Media component, allowing remote attackers to execute arbitrary code outs [truncated]

HIGH Google CVE published 2026-08-11

CVE-2026-67180

Google Turbinia is affected by a vulnerability that allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing request or influence an evidence path/name can obtain code execution on the worker fleet. This issue was fixed on 2026-07-10. The CVSS score is 7.5, indicating a high severity vulnerability. Organizations should review and apply patches to prevent pote [truncated]

HIGH Google CVE published 2026-08-06

CVE-2026-19177

The CVE-2026-19177 vulnerability is caused by insufficient validation of untrusted input in the UI of Google Chrome versions prior to 151.0.7922.109. This allows a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The Chromium security severity of this issue is High, with a CVSS score of 8.3. Affected product context indicates Google [truncated]

CRITICAL Google CVE published 2026-08-06

CVE-2026-19175

The CVE-2026-19175 vulnerability is a use-after-free issue in the Payments component of Google Chrome prior to version 151.0.7922.109. This vulnerability allows a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The CVSS score of 9.6 and critical severity highlight the importance of applying the patch. The vulnerability impacts Google Chrome users, particularly those in env [truncated]