PatchSiren

Google CVE debriefs · Page 14

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Google CVE published 2026-07-30

CVE-2026-17821

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:45.663Z and has not been modified since then. This vulnerability, CVE-2026-17821, involves insufficient policy enforcement in Google Chrome Extensions prior to version 151.0.7922.72. An attacker can exploit this by convincing a user to install a malicious extension, which could then bypass [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17819

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-17819 was published on 2026-07-30T01:16:45.460Z. This medium severity vulnerability, classified as CWE-451, affects Google Chrome prior to version 151.0.7922.72 and allows remote attackers to perform UI spoofing via crafted HTML pages. The vulnerability has a CVSS score of 6.5. Organizations and individuals usi [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17818

The CVE-2026-17818 vulnerability is caused by an inappropriate implementation in the Network component of Google Chrome prior to version 151.0.7922.72. This allows remote attackers to inject arbitrary scripts or HTML via a crafted HTML page, potentially leading to UXSS attacks. The vulnerability has a CVSS score of 6.1 and is classified as Medium severity. Administrators and users of Google Chrome should [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17817

The CVE-2026-17817 vulnerability is caused by an inappropriate implementation in Google Chrome's ReportingAndNEL feature. This allows remote attackers to leak cross-origin data via a crafted HTML page. The issue was addressed in Google Chrome version 151.0.7922.72. Organizations and individuals using Google Chrome prior to version 151.0.7922.72 should apply the update to prevent potential data leaks. Addi [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17814

The CVE-2026-17814 vulnerability, classified as Medium severity with a CVSS score of 6.5, affects Google Chrome for iOS prior to version 151.0.7922.72. Insufficient validation of untrusted input allows a remote attacker to bypass navigation restrictions via a crafted HTML page. This issue requires immediate attention from administrators and users of Google Chrome for iOS, as well as security teams respons [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17810

The CVE-2026-17810 vulnerability, caused by an uninitialized use in Dawn in Google Chrome prior to 151.0.7922.72, allows a remote attacker to leak cross-origin data via a crafted HTML page. This Medium severity vulnerability has a CVSS score of 4.3. The vulnerability affects Google Chrome users, particularly those who handle sensitive data or require high security standards. To address this issue, users s [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17809

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:44.380Z and has not been modified since then. This vulnerability, CVE-2026-17809, is related to insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72. It allowed a remote attacker who had compromised the renderer process to potentially perform a sa [truncated]

HIGH Google CVE published 2026-07-30

CVE-2026-17807

The CVE-2026-17807 vulnerability is a use-after-free issue in the V8 engine of Google Chrome, which could allow remote attackers to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability has a CVSS score of 8.8 and is classified as HIGH severity. The issue was addressed in Google Chrome version 151.0.7922.72. Affected product deployments should be reviewed for potential exposu [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17806

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. This CVE record was published on 2026-07-30T01:16:44.053Z and has not been modified since then. The vulnerability has a CVSS score of 5.8 and is classified as Medium severity. Adm [truncated]

CRITICAL Google CVE published 2026-07-30

CVE-2026-17804

A use-after-free vulnerability exists in the Media component of Google Chrome prior to version 151.0.7922.72. This vulnerability allows a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The vulnerability has a CVSS score of 9.6 and is rated as Medium severity by Chromium. It is crucial for organizations to prioritize patching this v [truncated]

CRITICAL Google CVE published 2026-07-30

CVE-2026-17803

CVE-2026-17803 is a critical vulnerability in Google Chrome prior to version 151.0.7922.72. The vulnerability is caused by insufficient validation of untrusted input in the Save to Drive feature, which allows a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. This vulnerability has a CVSS score of 9.6 and is classified as CRITICAL. Us [truncated]

CRITICAL Google CVE published 2026-07-30

CVE-2026-17801

The CVE-2026-17801 vulnerability is an out-of-bounds read and write issue in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome versions prior to 151.0.7922.72. This vulnerability could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The Chromium security team has rated this vulnerability as Medium severity. Organizations should review their Chrome in [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17799

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:43.307Z and has not been modified since then. This vulnerability, CVE-2026-17799, is related to insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to version 151.0.7922.72. It allows a remote attacker to bypass discretionary access control via a malicious fil [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17797

A Medium severity UXSS vulnerability, CVE-2026-17797, was discovered in Google Chrome prior to version 151.0.7922.72. This vulnerability allows remote attackers to inject arbitrary scripts or HTML via a crafted HTML page, potentially leading to script injection attacks. The vulnerability's technical details are based on official sources, but additional context is needed to fully understand the issue. Limi [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17794

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:42.783Z and has not been modified since then. This vulnerability affects Google Chrome on Android prior to version 151.0.7922.72, allowing a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. Insufficient validati [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17793

The CVE-2026-17793 vulnerability, caused by an inappropriate implementation in Messages in Google Chrome on Android prior to version 151.0.7922.72, allows a remote attacker to perform UI spoofing via a crafted HTML page. This issue has a CVSS score of 6.5 and is classified as Medium severity by Chromium. The vulnerability was published on 2026-07-30T01:16:42.683Z and has not been modified since then. IT a [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17790

The CVE-2026-17790 vulnerability is caused by an uninitialized use in ANGLE in Google Chrome on Windows. This allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. The vulnerability has a CVSS score of 4.3 and a severity of Medium. Users of Google Chrome on Windows should be aware of this vulnerability and take immediate action to update their br [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17789

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:42.257Z and has not been modified since then. This vulnerability, CVE-2026-17789, affects Google Chrome on iOS prior to version 151.0.7922.72, allowing remote attackers to bypass navigation restrictions via malicious network traffic due to insufficient validation of untrusted input. The CVS [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17787

The CVE-2026-17787 vulnerability is related to an inappropriate implementation in DevTools in Google Chrome prior to version 151.0.7922.72. This vulnerability could allow a remote attacker to bypass same origin policy via a crafted HTML page. The CVSS score is 6.5, and the severity is rated as MEDIUM. The Chromium security severity is also rated as Medium. Organizations should review their deployments and [truncated]

HIGH Google CVE published 2026-07-30

CVE-2026-17784

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:41.723Z and has not been modified since then. This vulnerability affects Google Chrome on Mac prior to version 151.0.7922.72, allowing a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The technical impact is signific [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17782

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:41.510Z and has not been modified since then. This vulnerability, CVE-2026-17782, affects Google Chrome for iOS versions prior to 151.0.7922.72. It allows a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. The issue has a Medium severity and can lead t [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17781

The CVE-2026-17781 vulnerability, caused by inappropriate implementation in Extensions in Google Chrome prior to version 151.0.7922.72, allows an attacker to leak cross-origin data via a crafted Chrome Extension if a user installs it. This medium severity vulnerability requires user interaction and impacts Chrome users with outdated versions. Evidence is limited to CVE and NVD details. Defenders should ve [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17780

A Medium severity vulnerability, CVE-2026-17780, was discovered in Google Chrome prior to version 151.0.7922.72. This vulnerability, related to an inappropriate implementation in Isolated Web Apps, allows remote attackers to bypass navigation restrictions via crafted HTML pages. Organizations and individuals using Google Chrome prior to version 151.0.7922.72 should apply the latest update to prevent poten [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17779

The CVE-2026-17779 vulnerability is related to an inappropriate implementation in Google Chrome's Site Isolation feature. This issue allows remote attackers to bypass site isolation via a crafted HTML page. The vulnerability has a CVSS score of 5.4 and is classified as Medium severity. Google Chrome versions prior to 151.0.7922.72 are affected. Organizations should review their Chrome deployments and ensu [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17772

The CVE-2026-17772 vulnerability is an out-of-bounds read issue in WebGL in Google Chrome prior to version 151.0.7922.72. This vulnerability allowed a remote attacker to perform an out-of-bounds memory read via a crafted HTML page. The issue has a CVSS score of 4.3 and is rated as Medium severity by Chromium. Users of Google Chrome, especially those who handle sensitive data or require high security stand [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17770

CVE-2026-17770 is an out-of-bounds read vulnerability in the Media component of Google Chrome on Mac systems, classified as Medium severity with a CVSS score of 5.8. This issue, addressed in Google Chrome version 151.0.7922.72, could allow a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The vulnerability was published on 2026-07-3 [truncated]

CRITICAL Google CVE published 2026-07-30

CVE-2026-17768

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:39.990Z and has not been modified since then. CVE-2026-17768 is a Medium severity vulnerability in Google Chrome prior to version 151.0.7922.72, affecting WebSockets and potentially allowing a remote attacker to perform a sandbox escape via a crafted HTML page if the renderer process is com [truncated]

LOW Google CVE published 2026-07-30

CVE-2026-17766

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:39.767Z and has not been modified since then. The vulnerability CVE-2026-17766 is caused by insufficient validation of untrusted input in Clipboard in Google Chrome on Android prior to 151.0.7922.72. This allows a local attacker to leak cross-origin data via a crafted HTML page. The vulnera [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17765

The CVE-2026-17765 vulnerability is an inappropriate implementation in Google Chrome's WebProtect feature, allowing a remote attacker who has compromised the renderer process to leak cross-origin data via a crafted HTML page. This issue has a CVSS score of 4.3 and is classified as Medium severity. The vulnerability affects Google Chrome deployments prior to version 151.0.7922.72. IT administrators and sec [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17764

The CVE-2026-17764 vulnerability is caused by an inappropriate implementation in FedCM in Google Chrome prior to version 151.0.7922.72. This vulnerability allows a remote attacker to bypass same origin policy via a crafted HTML page, with a CVSS score of 6.5 and a severity rating of Medium. The issue relates to FedCM's handling of same-origin policy, potentially allowing attackers to access sensitive data [truncated]