PatchSiren

Google CVE debriefs · Page 16

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Google CVE published 2026-07-30

CVE-2026-17721

The CVE-2026-17721 vulnerability is a critical out-of-bounds write issue in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome, prior to version 151.0.7922.72. This vulnerability could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The issue was addressed in Google Chrome version 151.0.7922.72. Organizations and individuals using Google Chrome prior [truncated]

LOW Google CVE published 2026-07-30

CVE-2026-17720

The CVE-2026-17720 vulnerability is related to insufficient policy enforcement in Passwords in Google Chrome prior to version 151.0.7922.72. This allows a remote attacker who has compromised the renderer process to leak cross-origin data via a crafted HTML page. The vulnerability has a High Chromium security severity but a Low CVSS score of 3.1. Google Chrome users, particularly those with sensitive cross [truncated]

HIGH Google CVE published 2026-07-30

CVE-2026-17719

CVE-2026-17719 is a high-severity use-after-free vulnerability in the Input component of Google Chrome prior to version 151.0.7922.72. This vulnerability allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The CVSS score for this vulnerability is 8.8, indicating a high level of severity. The vulnerability affects Google Chrome users and requires immediate attention [truncated]

CRITICAL Google CVE published 2026-07-30

CVE-2026-17718

The CVE-2026-17718 vulnerability is a use-after-free issue in ANGLE within Google Chrome prior to version 151.0.7922.72. This vulnerability could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The CVSS score is 9.6, indicating critical severity. The vulnerability was published on 2026-07-30T01:16:34.353Z and has not been modified since then. Defenders should verif [truncated]

CRITICAL Google CVE published 2026-07-30

CVE-2026-17717

The CVE-2026-17717 vulnerability is an integer overflow in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome, which could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. This issue occurs in versions prior to 151.0.7922.72 and has a CVSS score of 9.6, indicating critical severity. The vulnerability is categorized under CWE-190 (Integer Overflow or Wr [truncated]

HIGH Google CVE published 2026-07-30

CVE-2026-17716

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:34.137Z and has not been modified since then. The vulnerability CVE-2026-17716 is a use-after-free issue in the Updater component of Google Chrome on Mac systems, allowing a local attacker to perform privilege escalation via malicious network traffic. The issue was addressed in Google Chrom [truncated]

LOW Google CVE published 2026-07-30

CVE-2026-17715

The CVE-2026-17715 vulnerability involves an inappropriate implementation in Passwords within Google Chrome versions prior to 151.0.7922.72. This issue allows a remote attacker to leak cross-origin data by convincing a user to engage in specific UI gestures via a crafted HTML page. The vulnerability has a CVSS score of 3.1 and is considered High severity by Chromium, despite its LOW severity rating. Affec [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17714

The CVE-2026-17714 vulnerability is an uninitialized use issue in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome, affecting versions prior to 151.0.7922.72. This vulnerability allows a remote attacker to potentially obtain sensitive information from process memory by providing a crafted HTML page. The issue is rated with a CVSS score of 6.5, indicating a Medium severity level, but the Ch [truncated]

CRITICAL Google CVE published 2026-07-30

CVE-2026-17713

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:33.820Z and has not been modified since then. This vulnerability affects Google Chrome on Android, specifically versions prior to 151.0.7922.72. It is caused by insufficient validation of untrusted input in the Accessibility feature. A remote attacker who has compromised the renderer proces [truncated]

CRITICAL Google CVE published 2026-07-30

CVE-2026-17710

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:33.500Z and has not been modified since then. This critical vulnerability, CVE-2026-17710, affects Google Chrome on Mac systems prior to version 151.0.7922.72. It is caused by an inappropriate implementation in MHTML, allowing a remote attacker who has compromised the renderer process to po [truncated]

CRITICAL Google CVE published 2026-07-30

CVE-2026-17708

The CVE-2026-17708 vulnerability is a use-after-free issue in the Audio component of Google Chrome prior to version 151.0.7922.72. This vulnerability could allow a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. The Chromium security severity of this issue is High. Organizations and individuals using Google Chrome prior to version [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17707

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:33.170Z and has not been modified since then. The CVE-2026-17707 vulnerability is caused by an uninitialized use in the Media component of Google Chrome on Windows. This issue allows a remote attacker who has compromised the renderer process to obtain potentially sensitive information from [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17706

The CVE-2026-17706 vulnerability is caused by insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 151.0.7922.72. This allows a remote attacker who has compromised the renderer process to leak cross-origin data via a crafted HTML page. The issue is particularly concerning for environments with high-risk exposure to untrusted input, such as public-facing web applications [truncated]

HIGH Google CVE published 2026-07-30

CVE-2026-17705

The CVE-2026-17705 vulnerability is an integer overflow in libxml in Google Chrome prior to version 151.0.7922.72. This vulnerability, with a CVSS score of 8.8, could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The Chromium security severity is rated as High. Evidence is limited to public sources and may not reflect the full scope or impact of this vulnerabi [truncated]

CRITICAL Google CVE published 2026-07-30

CVE-2026-17704

CVE-2026-17704 is a use-after-free vulnerability in ANGLE within Google Chrome versions prior to 151.0.7922.72. This issue allows a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The vulnerability has a high CVSS score of 9.6 and is classified as CRITICAL. Users of Google Chrome prior to version 151.0.7922.72 should apply the patch [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17703

The CVE-2026-17703 record details an insufficient policy enforcement vulnerability in Google Chrome for iOS, allowing remote attackers to bypass navigation restrictions via crafted HTML pages. This issue, rated as High severity by Chromium and MEDIUM with a CVSS score of 6.5, affects Google Chrome on iOS prior to version 151.0.7922.72. Organizations and individuals using Google Chrome for iOS should be aw [truncated]

CRITICAL Google CVE published 2026-07-30

CVE-2026-17701

The CVE-2026-17701 vulnerability involves insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 151.0.7922.72. This could allow a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The vulnerability has a CVSS score of 9.6 and is considered CRITICAL. Affected product deployments should be reviewed for exp [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17700

CVE-2026-17700: Insufficient validation of untrusted input in Actor in Google Chrome prior to 151.0.7922.72 allows a remote attacker who has compromised the renderer process to leak cross-origin data via a crafted HTML page. This vulnerability has a high severity rating according to Chromium, with a CVSS score of 4.3 and a severity of MEDIUM. The issue is related to the Actor component in Google Chrome, w [truncated]

HIGH Google CVE published 2026-07-30

CVE-2026-17699

A high severity use-after-free vulnerability exists in the Views component of Google Chrome prior to version 151.0.7922.72. This vulnerability, tracked as CVE-2026-17699, could potentially allow a local attacker to escape the sandbox via a malicious file, impacting defensive operations and necessitating immediate attention. The CVE record, published on 2026-07-30T01:16:32.310Z, indicates a CVSS score of 8 [truncated]

HIGH Google CVE published 2026-07-30

CVE-2026-17698

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:32.200Z and has not been modified since then. This CVE-2026-17698 vulnerability involves insufficient validation of untrusted input in UI in Google Chrome on Android prior to 151.0.7922.72, allowing a local attacker to leak cross-origin data via a crafted HTML page. The issue has a High sev [truncated]

CRITICAL Google CVE published 2026-07-30

CVE-2026-17697

The CVE-2026-17697 vulnerability is a Type Confusion issue in ANGLE within Google Chrome prior to version 151.0.7922.72. This vulnerability allows a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The issue has a CVSS score of 9.6 and is classified as CRITICAL. The vulnerability was addressed by updating Chrome to version 151.0.7922.72 or later. Security teams should revie [truncated]

CRITICAL Google CVE published 2026-07-30

CVE-2026-17695

The CVE-2026-17695 vulnerability is caused by an inappropriate implementation in ANGLE (Almost Native Graphics Layer Engine) in Google Chrome on Mac prior to version 151.0.7922.72. This critical vulnerability allows a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability has a high impact on Google Chrome users on Mac, particularly those with high-risk exposure [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17693

Insufficient policy enforcement in FileSystem in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. This vulnerability impacts Google Chrome users, particularly those handling sensitive data or systems. The issue is caused by inadequate policy enforcement in the FileSystem component, which can be exploited through a specially crafted HTML page [truncated]

CRITICAL Google CVE published 2026-07-30

CVE-2026-17692

The CVE-2026-17692 vulnerability is a use-after-free issue in the DataTransfer component of Google Chrome on Windows. This vulnerability allows a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The issue is resolved in Google Chrome version 151.0.7922.72 or later. Organizations and individuals using Google Chrome on Windows should p [truncated]

MEDIUM Google CVE published 2026-07-30

CVE-2026-17690

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:31.333Z and has not been modified since then. This vulnerability affects Google Chrome users on Android, particularly those with high-risk exposure or handling sensitive data. Insufficient validation of untrusted input in PDF in Google Chrome on Android prior to 151.0.7922.72 allows a local [truncated]

CRITICAL Google CVE published 2026-07-30

CVE-2026-17688

The CVE-2026-17688 vulnerability is a use-after-free issue in the Input component of Google Chrome prior to version 151.0.7922.72. This vulnerability has a CVSS score of 9.6 and is rated as High severity by Chromium. An attacker who has compromised the renderer process could potentially exploit this vulnerability to perform a sandbox escape via a specially crafted HTML page. The vulnerability affects Goog [truncated]

CRITICAL Google CVE published 2026-07-30

CVE-2026-17687

CVE-2026-17687 is a High severity vulnerability in Google Chrome's ANGLE, potentially allowing remote attackers to escape the sandbox via crafted HTML pages. The issue was patched in version 151.0.7922.72. This vulnerability affects Google Chrome prior to version 151.0.7922.72. Organizations should apply the patch immediately to prevent potential sandbox escapes and exploitation. The CVE record was publis [truncated]

HIGH Google CVE published 2026-07-30

CVE-2026-17686

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:30.880Z and has not been modified since then. This High severity vulnerability in Google Chrome prior to 151.0.7922.72 allows a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. The vulnerability affects Google Chrome users, administr [truncated]

HIGH Google CVE published 2026-07-30

CVE-2026-17685

The CVE-2026-17685 vulnerability is a high-severity use-after-free issue in Google Chrome's Autofill feature. This vulnerability allows remote attackers to execute arbitrary code inside a sandbox via a crafted HTML page. The CVE record was published on 2026-07-30T01:16:30.770Z and has not been modified since then. The affected product is Google Chrome prior to version 151.0.7922.72. Users should ensure th [truncated]

CRITICAL Google CVE published 2026-07-30

CVE-2026-17684

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:30.660Z and has not been modified since then. This critical vulnerability affects Google Chrome for iOS versions prior to 151.0.7922.72, allowing a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability has been publicly disclosed and patched by t [truncated]