These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-15904 is a high-severity vulnerability in Google Chrome on Linux, allowing remote attackers to potentially exploit heap corruption via a crafted HTML page. This vulnerability is caused by a use-after-free issue in the Ozone component. The vulnerability can be exploited by convincing a user to engage in specific UI gestures. Users of Google Chrome on Linux should apply the update to prevent potent [truncated]
CVE-2026-15903 is a vulnerability in Google Chrome prior to version 150.0.7871.128, which allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability is an out of bounds read and write in V8, with a CVSS score of 8.8 and a severity of HIGH. This vulnerability has a significant impact on users of Google Chrome, particularly those who browse the internet a [truncated]
A use after free vulnerability was reported in Google Chrome's Cast feature prior to version 150.0.7871.128. This vulnerability could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The Chromium security severity of this issue is High, with a CVSS score of 9.6, indicating a Critical severity level. The vulnerability affects users of Google Chrome, particularly t [truncated]
A critical use after free vulnerability was discovered in Google Chrome prior to version 150.0.7871.128. The vulnerability, tracked as CVE-2026-15901, exists in the Network component of Google Chrome. An attacker could potentially exploit this vulnerability by providing a crafted HTML page, which could lead to heap corruption. This type of vulnerability occurs when a program attempts to access memory that [truncated]
A critical use after free vulnerability was discovered in the GPU component of Google Chrome on Android versions prior to 150.0.7871.128. This vulnerability, tracked as CVE-2026-15900, could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability is rated as Critical by the Chromium security team, with a CVSS score of 9.6. Successful exploitation could le [truncated]
A critical vulnerability, CVE-2026-15899, was found in Google Chrome's CameraCapture feature on Mac systems. This use-after-free vulnerability could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability has a CVSS score of 9.6, indicating a high severity level. Google has released a patch for this issue in version 150.0.7871.128 of Google Chrome.
The CVE-2026-15777 vulnerability is a use-after-free issue in the UI of Google Chrome on Linux, prior to version 150.0.7871.125. This could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page, requiring specific UI gestures from the user. The vulnerability has a CVSS score of 7.5 and is classified as High severity. Linux users of Google Chrome should review and apply the [truncated]
CVE-2026-11998 is a high-severity flaw in AngularJS' Strict Contextual Escaping (SCE) logic. This vulnerability allows bypassing certain SCE policies for resource URLs, which can lead to arbitrary JavaScript execution within the context of the victim's browser session. The SCE's purpose is to ensure that only trusted or safe values are used in certain security-sensitive contexts, such as resource URLs. A [truncated]
CVE-2026-11719 is a high-severity vulnerability in MCP Toolbox for Databases that allows authenticated users to bypass authorization restrictions. The vulnerability exists because older protocol versions (2025-06-18, 2025-03-26, and 2024-11-05) do not enforce scope checks, unlike the 2025-11-25 protocol version. An attacker with a low-privilege token can exploit this by specifying an older protocol versio [truncated]
A critical authentication bypass vulnerability exists in googleapis/mcp-toolbox. The vulnerability occurs in the generic opaque token validation path, allowing unauthorized third-party identity providers to issue accepted tokens. This happens when an external OAuth provider's introspection response omits the optional issuer (iss) field, causing the application to skip claim-checking logic silently. The CV [truncated]
CVE-2026-11717 is a critical authentication bypass vulnerability in Google's MCP Toolbox for Databases. The vulnerability exists in the generic opaque token validation path, specifically in the validateOpaqueToken function. When verifying an unparsed opaque token via an OAuth 2.0 introspection endpoint, the toolbox decodes the response into an introspectResp struct. If the introspection endpoint responds [truncated]
A possible persistent denial of service exists due to a missing permission check in AndroidManifest.xml. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. The vulnerability affects Android devices and has a critical severity level with a CVSS score of 10. Android users and administrators should be aware of this vulne [truncated]
CVE-2026-28615 is a critical vulnerability in the Telecomm component of the Android operating system. It allows for local escalation of privilege due to a permissions bypass, enabling an attacker to initiate unauthorized phone calls without requiring additional execution privileges or user interaction. This issue has a CVSS score of 10 and is classified as CRITICAL. Android users and administrators should [truncated]
A local information disclosure vulnerability exists in MmsSmsProvider of MmsSmsProvider.java due to a missing permission check. This could allow local attackers to retrieve sensitive information without needing additional execution privileges or user interaction. The vulnerability has a CVSS score of 10 and a severity of CRITICAL. Android users and administrators should be aware of this vulnerability and [truncated]
CVE-2026-28575 is a local denial of service vulnerability in Android PackageInstaller. The vulnerability exists in the PackageInstaller.Session#transfer method of the frameworks/base/services/core/java/com/android/server/pm/PackageInstallerSession.java file. An attacker could exploit this vulnerability to cause a local denial of service without requiring additional execution privileges. User interaction i [truncated]
CVE-2026-12469 is a High-severity vulnerability in Google Chrome on Android prior to 149.0.7827.155. This issue involves an uninitialized use in the GPU, which could allow a remote attacker to leak cross-origin data via a crafted HTML page. The Chromium security team has assessed this vulnerability as High severity. Affected product deployments should be reviewed for potential exposure, and owners should [truncated]
CVE-2026-12467 is a high-severity use after free vulnerability in Google Chrome's Extensions feature. This vulnerability, which was published on June 17, 2026, allows a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The CVSS score for this vulnerability is 8.3, indicating a high level of severity. Users of Google Chrome prior to ve [truncated]
CVE-2026-12466 is a high-severity vulnerability in Google Chrome's WebRTC feature on Windows. A remote attacker can exploit this heap buffer overflow by crafting a malicious HTML page, allowing for arbitrary code execution. Google patched this issue in Chrome version 149.0.7827.155. Users should update to the latest version to mitigate this risk. This vulnerability was publicly disclosed on June 17, 2026, [truncated]
A high-severity vulnerability was discovered in Google Chrome's Views implementation on Linux, affecting versions prior to 149.0.7827.155. This issue allowed a remote attacker who had compromised the renderer process to inject arbitrary scripts or HTML, potentially leading to UXSS attacks. The vulnerability was reported and patched, with the stable channel update for desktop released on June 17, 2026. Use [truncated]
CVE-2026-12462 is a high-severity use after free vulnerability in Google Chrome's Media component. This PatchSiren debrief provides an AI-assisted analysis of a use after free vulnerability in Google Chrome prior to version 149.0.7827.155. The vulnerability allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. The affected pr [truncated]
CVE-2026-12461 is an out-of-bounds read vulnerability in the WebRTC component of Google Chrome on Windows prior to version 149.0.7827.155. This vulnerability allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. The Chromium security severity is rated as High, with a CVSS score of 6.5 and a MEDIUM severity rating. The vulnerability impacts users [truncated]
CVE-2026-12460 is a High-severity vulnerability in Google Chrome, where insufficient policy enforcement in File System Access allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. This issue was addressed in Google Chrome version 149.0.7827.155. Users should update to the latest version to mitigate this risk. The vulnerability was publicly disc [truncated]
CVE-2026-12459 is a High-severity vulnerability in Google Chrome's Serial implementation. A remote attacker can inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. This issue was patched in Chrome version 149.0.7827.155. Users should update Chrome to the latest version to mitigate this risk. The vulnerability has a CVSS score of 6.1, indicating a Medium severity level. Chrome users are advise [truncated]
A High-severity vulnerability, CVE-2026-12458, was found in Google Chrome's Passwords feature. This issue, caused by inappropriate implementation, allows a remote attacker to leak cross-origin data via a crafted HTML page by convincing a user to engage in specific UI gestures. The vulnerability has a High severity rating and a CVSS score of 3.1. The Chromium security severity of this issue is rated as Hig [truncated]
A high-severity vulnerability was discovered in Google Chrome's Extensions, allowing remote attackers to bypass site isolation via a crafted HTML page. This issue is caused by inappropriate implementation in Extensions. The vulnerability has a CVSS score of 4.2 and is classified as MEDIUM severity. It was reported and patched prior to the publication of this CVE. The vulnerability impacts users of Google [truncated]
CVE-2026-12455 is a high-severity use after free vulnerability in Google Chrome's Tab Strip feature. This PatchSiren debrief provides an AI-assisted analysis of the CVE record and available source details. The vulnerability allows a remote attacker to potentially exploit heap corruption via a crafted HTML page by convincing a user to engage in specific UI gestures. Users of Google Chrome, particularly tho [truncated]
CVE-2026-12454 is a high-severity vulnerability in Google Chrome on Mac, allowing a remote attacker to potentially perform a sandbox escape via a crafted HTML page due to a race condition in Safe Browsing. This vulnerability has a CVSS score of 8.3 and is rated as High by Chromium. The vulnerability affects users who browse the internet and may be exposed to crafted HTML pages. To mitigate this vulnerabil [truncated]
CVE-2026-12453 is a vulnerability in Google Chrome prior to version 149.0.7827.155. The issue involves insufficient validation of untrusted input in the Input component, allowing a remote attacker who has compromised the renderer process to bypass the same origin policy via a crafted HTML page. This vulnerability has been classified as High severity by Chromium and Medium by CVSS with a score of 4.2.
CVE-2026-12451 is a high-severity vulnerability in Google Chrome's DigitalCredentials component. A remote attacker who has compromised the renderer process could potentially perform a sandbox escape via a crafted HTML page. The vulnerability has a CVSS score of 8.3 and was published on 2026-06-17. Users of Google Chrome prior to version 149.0.7827.155 are affected. The CVE was modified on 2026-06-18 to re [truncated]
CVE-2026-12450 is a High-severity vulnerability in Google Chrome's Media implementation. A remote attacker can exploit this issue by crafting an HTML page to obtain potentially sensitive information from process memory. This vulnerability was publicly disclosed on June 17, 2026, and has a CVSS score of 6.5 (Medium severity). Users of Google Chrome prior to version 149.0.7827.155 are affected. To mitigate [truncated]