PatchSiren

Google CVE debriefs · Page 15

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Google CVE published 2026-07-30

CVE-2026-17763

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:39.367Z and has not been modified since then. The CVE-2026-17763 vulnerability is caused by an inappropriate implementation in the GPU of Google Chrome, allowing a remote attacker who has compromised the renderer process to leak cross-origin data via a crafted HTML page. This issue affects [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17759

The CVE-2026-17759 vulnerability is caused by an uninitialized use in the Codecs component of Google Chrome prior to version 151.0.7922.72. This allows remote attackers to potentially obtain sensitive information from process memory via a crafted HTML page. The issue has a CVSS score of 6.5 and is categorized as Medium severity by Chromium. The vulnerability affects Google Chrome users and requires immedi [truncated]

CRITICAL Google CVE published 2026-07-30

CVE-2026-17758

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:38.777Z and has not been modified since then. The vulnerability is a heap buffer overflow in Dawn in Google Chrome prior to 151.0.7922.72, allowing a remote attacker to potentially perform a sandbox escape via a crafted HTML page. It has a CVSS score of 9.6 and is classified as CRITICAL. To [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17757

The CVE-2026-17757 vulnerability is an uninitialized use issue in Skia within Google Chrome prior to version 151.0.7922.72. This issue allows a remote attacker to leak cross-origin data via a crafted HTML page. The vulnerability has a CVSS score of 4.3 and is classified as Medium severity. Google Chrome users, particularly those who handle sensitive data or require high security standards, should be aware [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17756

The CVE-2026-17756 vulnerability, caused by insufficient policy enforcement in Presentation in Google Chrome prior to version 151.0.7922.72, allows a remote attacker to bypass navigation restrictions via a crafted HTML page. This issue has a CVSS score of 6.5 and a Medium security severity according to Chromium. Administrators and users of Google Chrome, especially those in environments where navigation r [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17755

CVE-2026-17755 is a Medium severity vulnerability in Google Chrome prior to 151.0.7922.72, allowing an attacker who convinces a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. This vulnerability requires user interaction to exploit and impacts browser security and extension management. The CVE record was published on 2026-07-30T01:16:38.443Z and has not been mo [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17754

CVE-2026-17754 is a medium-severity vulnerability in Google Chrome prior to version 151.0.7922.72, caused by an inappropriate implementation in Blink. This allows remote attackers to bypass the same-origin policy via crafted HTML pages. The CVSS score is 6.5, and the Chromium security severity is rated as Medium. The vulnerability affects Google Chrome users, particularly those in environments where secur [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17753

The CVE-2026-17753 vulnerability was reported in Google Chrome's Autofill feature, allowing a remote attacker to leak cross-origin data via a crafted HTML page. This issue has a CVSS score of 4.3 and is classified as Medium severity. The vulnerability was fixed in version 151.0.7922.72. Users of Google Chrome, particularly those who use Autofill, should apply the patch to update Google Chrome to version 1 [truncated]

HIGH Google CVE published 2026-07-30

CVE-2026-17752

CVE-2026-17752 is a use-after-free vulnerability in the Views component of Google Chrome on Mac systems, which could allow remote attackers to potentially exploit heap corruption via a crafted HTML page. The vulnerability has a CVSS score of 8.8, indicating high severity. It was addressed in Google Chrome version 151.0.7922.72. Administrators and users of Google Chrome on Mac systems should be aware of th [truncated]

HIGH Google CVE published 2026-07-30

CVE-2026-17750

The CVE-2026-17750 vulnerability is a use-after-free issue in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome, prior to version 151.0.7922.72. This vulnerability, classified as Medium severity by Chromium, could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The CVSS score for this vulnerability is 7.1, indicating a high severity level. [truncated]

CRITICAL Google CVE published 2026-07-30

CVE-2026-17749

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:37.803Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. This vulnerability, CVE-2026-17749, involves insufficient validation of untrusted input in Google Chrome Extensions prior to version 151.0.7922.72, which could allow an attacker to potentially perf [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17748

CVE-2026-17748 is a medium severity vulnerability in Google Chrome prior to version 151.0.7922.72, related to inappropriate implementation in Extensions. This allows a remote attacker who has compromised the renderer process to bypass site isolation via a crafted HTML page. The vulnerability has a CVSS score of 6.5 and is rated as Medium by the Chromium security team. To mitigate this vulnerability, it is [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17747

The CVE-2026-17747 vulnerability involves insufficient validation of untrusted input in Payments within Google Chrome on Android. This issue allows a remote attacker who has compromised the renderer process to perform UI spoofing via a crafted HTML page. The vulnerability has been addressed in Google Chrome version 151.0.7922.72. Organizations should review their current browser versions and update to the [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17746

CVE-2026-17746 is a use-after-free vulnerability in the GPU of Google Chrome on Mac systems prior to version 151.0.7922.72. This vulnerability could potentially allow a remote attacker who has compromised the renderer process to perform a sandbox escape via a crafted HTML page. The Chromium security severity is rated as Medium with a CVSS score of 5.8. Users of Google Chrome on Mac systems, particularly t [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17745

The CVE-2026-17745 vulnerability is a medium-severity issue in Google Chrome, caused by an out-of-bounds read in Skia. This vulnerability allows a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The vulnerability has a CVSS score of 5.8 and is classified as medium severity. Organizations and individuals using Google Chrome prior to [truncated]

HIGH Google CVE published 2026-07-30

CVE-2026-17744

The CVE-2026-17744 vulnerability is caused by inappropriate implementation in File Input in Google Chrome on Linux. This issue allows remote attackers to potentially perform sandbox escapes via crafted HTML pages. The vulnerability has a CVSS score of 7.1 and is classified as HIGH severity. It affects Linux users of Google Chrome prior to version 151.0.7922.72. To address this vulnerability, users should [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17742

The CVE-2026-17742 vulnerability, classified as insufficient policy enforcement in Payments in Google Chrome prior to 151.0.7922.72, allows a remote attacker to leak cross-origin data via a crafted HTML page. This issue, with a Chromium security severity of Medium, was published on 2026-07-30T01:16:37.050Z. The vulnerability affects Google Chrome users, particularly those handling sensitive cross-origin d [truncated]

HIGH Google CVE published 2026-07-30

CVE-2026-17741

The CVE-2026-17741 vulnerability is caused by insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72. This allows remote attackers to potentially perform a sandbox escape via a crafted HTML page. The vulnerability has a CVSS score of 7.1 and is rated as HIGH severity. Google Chrome users on Android should apply the patch to update Google Chrome to version [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17740

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:36.820Z and has not been modified since then. The vulnerability, CVE-2026-17740, is an uninitialized use issue in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome prior to version 151.0.7922.72. This issue allows a remote attacker to leak cross-origin data by providing a cra [truncated]

CRITICAL Google CVE published 2026-07-30

CVE-2026-17738

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:36.603Z and has not been modified since then. The CVE-2026-17738 vulnerability is caused by insufficient validation of untrusted input in the Payments feature of Google Chrome. This vulnerability can be exploited by a remote attacker who has compromised the renderer process to potentially p [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17736

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:36.377Z and has not been modified since then. CVE-2026-17736 is a Medium severity vulnerability in Google Chrome on Android, caused by insufficient validation of untrusted input in WebView, allowing potential sandbox escapes. Users should update to version 151.0.7922.72 or later. Evidence i [truncated]

HIGH Google CVE published 2026-07-30

CVE-2026-17735

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:36.257Z and has not been modified since then. CVE-2026-17735 is a Medium severity vulnerability in Google Chrome, affecting users of versions prior to 151.0.7922.72. This vulnerability involves insufficient validation of untrusted input in BFCache, potentially allowing a remote attacker who [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17734

The CVE-2026-17734 vulnerability is an inappropriate implementation in Google Chrome's Autofill feature, allowing a remote attacker to inject arbitrary scripts or HTML via a crafted HTML page, potentially leading to UXSS attacks. This issue has a CVSS score of 5.4 and is classified as Medium severity. The vulnerability affects Google Chrome installations prior to version 151.0.7922.72. IT administrators r [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17731

CVE-2026-17731 is an inappropriate implementation in Autofill in Google Chrome on Android prior to version 151.0.7922.72. This vulnerability allowed a remote attacker to leak cross-origin data via a crafted HTML page, classified as Medium severity with a CVSS score of 4.3. The issue was fixed in version 151.0.7922.72. Evidence is limited to publicly available sources and may not reflect the full scope or [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17730

The CVE-2026-17730 vulnerability is a side-channel information leakage in Autofill in Google Chrome prior to 151.0.7922.72. This allows a remote attacker to leak cross-origin data by convincing a user to engage in specific UI gestures via a crafted HTML page. The vulnerability has a CVSS score of 4.3 and is rated as Medium severity by Chromium. Affected product deployments should be reviewed for exposure, [truncated]

HIGH Google CVE published 2026-07-30

CVE-2026-17729

The CVE-2026-17729 vulnerability is a use after free issue in V8 in Google Chrome prior to 151.0.7922.72. This vulnerability allowed a remote attacker who had compromised the renderer process to potentially perform out of bounds memory access via a crafted HTML page. The Chromium security severity is Medium, with a CVSS score of 8.8. Limited information is available about the actual impact and exploitatio [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17728

The CVE-2026-17728 vulnerability is caused by inappropriate implementation in Extensions in Google Chrome prior to version 151.0.7922.72. This allows remote attackers to inject arbitrary scripts or HTML via a crafted HTML page, potentially leading to UXSS attacks. The vulnerability has a CVSS score of 5.4 and is classified as Medium severity. Users and administrators of Google Chrome, especially those in [truncated]

CRITICAL Google CVE published 2026-07-30

CVE-2026-17727

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:35.370Z and has not been modified since then. The vulnerability, CVE-2026-17727, is an out-of-bounds write issue in WebGL within Google Chrome on Android, affecting versions prior to 151.0.7922.72. This issue allows a remote attacker to potentially perform a sandbox escape via a crafted HTM [truncated]

HIGH Google CVE published 2026-07-30

CVE-2026-17723

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:34.903Z and has not been modified since then. The CVE-2026-17723 vulnerability is a use-after-free issue in the Media component of Google Chrome on Windows, prior to version 151.0.7922.72. This vulnerability could allow a remote attacker who has compromised the renderer process to potential [truncated]

HIGH Google CVE published 2026-07-30

CVE-2026-17722

Object lifecycle issue in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The issue is caused by an object lifecycle problem in the WebView component of Google Chrome on Android. This vulnerability can be exploited by a remote attacker who has compromised the rende [truncated]