PatchSiren

Google CVE debriefs · Page 19

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Google CVE published 2026-06-17

CVE-2026-12449

CVE-2026-12449 is a high-severity vulnerability in Google Chrome's Chromoting feature on Windows. It was reported on June 17, 2026, and modified on June 18, 2026. The vulnerability allows a local attacker to perform OS-level privilege escalation via a malicious file. The CVSS score for this vulnerability is 7.8, indicating a high level of severity. Users of Google Chrome on Windows should update to versio [truncated]

HIGH Google CVE published 2026-06-17

CVE-2026-12448

CVE-2026-12448 is a High-severity vulnerability in Google Chrome's WebView on Android, allowing remote attackers to escalate privileges via a crafted HTML page. This issue was addressed in Chrome version 149.0.7827.155. Organizations should prioritize updating Chrome to the latest version to mitigate this vulnerability. The CVSS score for this vulnerability is 8.8, indicating a high level of severity. Thi [truncated]

HIGH Google CVE published 2026-06-17

CVE-2026-12447

CVE-2026-12447 is a high-severity vulnerability in Google Chrome's WebRTC component. A remote attacker can exploit this heap buffer overflow by crafting a malicious HTML page, allowing them to execute arbitrary code within a sandbox environment. This vulnerability was publicly disclosed on June 17, 2026, and the Chrome browser was updated to version 149.0.7827.155 to address the issue. Users should update [truncated]

MEDIUM Google CVE published 2026-06-17

CVE-2026-12446

CVE-2026-12446 is a high-severity vulnerability in Google Chrome's Passwords implementation. The issue allowed a remote attacker to leak cross-origin data via a crafted HTML page. Google Chrome versions prior to 149.0.7827.155 are affected. This vulnerability has significant implications for users who handle sensitive information or require high security standards. The vulnerability's high severity rating [truncated]

HIGH Google CVE published 2026-06-17

CVE-2026-12445

CVE-2026-12445 is a high-severity use after free vulnerability in Google Chrome Extensions. An attacker could exploit this vulnerability by convincing a user to install a malicious extension, potentially leading to heap corruption. The vulnerability was reported to have a CVSS score of 7.5 and was publicly disclosed on June 17, 2026. Users of Google Chrome prior to version 149.0.7827.155 are affected. The [truncated]

MEDIUM Google CVE published 2026-06-17

CVE-2026-12444

CVE-2026-12444 is a High-severity vulnerability in Google Chrome's Chromoting feature on Windows. It allows a local attacker to obtain potentially sensitive information from process memory via a malicious file. The vulnerability has a CVSS score of 5.5 and is considered Medium severity. Google Chrome versions prior to 149.0.7827.155 are affected. Users should update to the latest version to mitigate this [truncated]

HIGH Google CVE published 2026-06-17

CVE-2026-12443

CVE-2026-12443 is a critical use-after-free vulnerability in Google Chrome's Web Authentication feature. The vulnerability, which was published on June 17, 2026, allows remote attackers to execute arbitrary code via a crafted HTML page. The CVSS score for this vulnerability is 8.8, indicating a high severity. Google Chrome versions prior to 149.0.7827.155 are affected by this vulnerability. Users should u [truncated]

HIGH Google CVE published 2026-06-17

CVE-2026-12442

CVE-2026-12442 is a critical use-after-free vulnerability in Google Chrome's Passwords feature on Android. It was reported on June 17, 2026, and modified on June 18, 2026. The vulnerability has a CVSS score of 8.8 and can be exploited via a crafted HTML page, allowing remote attackers to execute arbitrary code. This issue was addressed in Chrome version 149.0.7827.155. Users should update their Chrome bro [truncated]

HIGH Google CVE published 2026-06-17

CVE-2026-12441

A critical vulnerability, CVE-2026-12441, was discovered in Google Chrome's File Input component on Linux systems. This use-after-free vulnerability, rated as Critical by Chromium, allows remote attackers to potentially exploit heap corruption via a crafted HTML page. The vulnerability has a CVSS score of 8.8, indicating a high severity. Google Chrome users on Linux systems should prioritize updating to v [truncated]

CRITICAL Google CVE published 2026-06-17

CVE-2026-12440

A critical vulnerability, CVE-2026-12440, was discovered in Google Chrome on Windows, allowing a remote attacker to potentially perform a sandbox escape via a crafted HTML page. This use after free issue in DigitalCredentials has a CVSS score of 9.6, indicating a high severity. Users of Google Chrome on Windows should update to version 149.0.7827.155 or later to mitigate this vulnerability. The vulnerabil [truncated]

HIGH Google CVE published 2026-06-17

CVE-2026-12438

CVE-2026-12438 is a Critical vulnerability in Google Chrome's WebView on Android prior to version 149.0.7827.155. This vulnerability allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The Chromium security severity of this vulnerability is Critical, with a CVSS score of 8.3 and a HIGH severity rating. The vulnerability affect [truncated]

HIGH Google CVE published 2026-06-17

CVE-2026-12437

A use after free vulnerability was discovered in Google Chrome's WebShare feature on Windows prior to version 149.0.7827.155. This vulnerability, CVE-2026-12437, allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The vulnerability is considered critical and affects users of Google Chrome on Windows. Successful exploitation co [truncated]

CRITICAL Google CVE published 2026-06-17

CVE-2026-0092

A critical vulnerability was found in Package Manager, which could allow for local escalation of privilege with no additional execution privileges needed. User interaction is not required for exploitation. The CVE record was published on 2026-06-17T13:19:26.813Z and has not been modified since then. The vulnerability affects Google Android 17.0. Security teams should review the supplied official advisory [truncated]

CRITICAL Google CVE published 2026-06-17

CVE-2026-0083

CVE-2026-0083 is a critical vulnerability in the Android operating system, specifically affecting the NFC (Near Field Communication) component. The issue arises from a race condition in the `Nfc::eventCallback()` function, leading to a use-after-free vulnerability. This could allow an attacker to escalate privileges locally without requiring additional execution privileges or user interaction. The vulnera [truncated]

CRITICAL Google CVE published 2026-06-17

CVE-2026-0082

A critical vulnerability was discovered in the NfcDispatcher.java file of the Android operating system. The issue arises from an insecure default value in the tryStartActivity function, which could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not required for exploitation. This vulnerability has a CVSS score of 10, indicating a critical severity [truncated]

CRITICAL Google CVE published 2026-06-17

CVE-2026-0081

CVE-2026-0081 is a critical vulnerability in Google Android's NFC component. A missing permission check allows local attackers to spoof NFC events, potentially leading to privilege escalation with no additional execution privileges needed. User interaction is not required for exploitation. The vulnerability has a CVSS score of 10 and is considered critical.

CRITICAL Google CVE published 2026-06-17

CVE-2026-0071

CVE-2026-0071 is a critical vulnerability in SettingsLib that could lead to local escalation of privilege with no additional execution privileges needed. The vulnerability is caused by a logic error in the code, which results in a missing permission check. This issue affects Android devices and could allow attackers to gain elevated privileges. Users and administrators should be aware of this vulnerabilit [truncated]

CRITICAL Google CVE published 2026-06-17

CVE-2026-0068

CVE-2026-0068 is a local escalation of privilege vulnerability in Google Android PackageInstallerService.java. The vulnerability exists due to a desync from persistence in createSessionInternal of PackageInstallerService.java, allowing a user to remove a DPC app from a managed device without DO consent. This could lead to local escalation of privilege if a user can install a malicious app with no addition [truncated]

CRITICAL Google CVE published 2026-06-17

CVE-2026-0064

A critical vulnerability, CVE-2026-0064, has been identified in Google Android, potentially leading to a persistent denial of service. This vulnerability has a CVSS score of 10 and is classified as CRITICAL. The issue can be exploited locally without additional execution privileges, and user interaction is not required. The vulnerability was published on June 17, 2026, and last modified on the same day.

CRITICAL Google CVE published 2026-06-17

CVE-2026-0063

A critical vulnerability was discovered in the PhoneInterfaceManager.java of the Android operating system. The issue, tracked as CVE-2026-0063, could allow an attacker to disable carrier restrictions due to a logic error in the code, potentially leading to local escalation of privilege. This vulnerability exists in the setAllowedCarriers method of PhoneInterfaceManager.java and requires no additional exec [truncated]

LOW Google CVE published 2026-06-17

CVE-2026-0057

A low-severity vulnerability was found in the Contacts Provider of Android, which could allow local information disclosure. The vulnerability is due to a missing permission check, enabling an attacker to access an incoming call's phone number and associated metadata without needing additional execution privileges. User interaction is not required for exploitation. This issue affects Android users and admi [truncated]

HIGH Google CVE published 2026-06-17

CVE-2026-0019

CVE-2026-0019 is a HIGH-severity vulnerability in Google's SettingsLib, enabling local escalation of privilege with a CVSS score of 7.8. The issue arises from a logic error in the code, allowing attackers to disable system components without additional execution privileges or user interaction. This vulnerability was published on June 17, 2026, and last modified on June 18, 2026. Affected products include [truncated]

HIGH Google CVE published 2026-06-17

CVE-2025-48643

A high-severity vulnerability, CVE-2025-48643, exists in multiple locations due to improper input validation, potentially allowing local escalation of privilege without additional execution privileges. User interaction is not required for exploitation. This vulnerability has a CVSS score of 7.8 and is considered HIGH severity. The vulnerability was published on 2026-06-17T13:19:14.140Z and last modified o [truncated]

HIGH Google CVE published 2026-06-17

CVE-2025-48640

A vulnerability exists in Google Android, specifically in multiple locations where a missing permission check allows for 3rd party passkey entry pairing approval. This issue enables remote escalation of privilege with no additional execution privileges needed. User interaction is not required for exploitation. The vulnerability is caused by a missing permission check, which allows an attacker to gain elev [truncated]

HIGH Google CVE published 2026-06-17

CVE-2025-48617

A high-severity vulnerability, CVE-2025-48617, was found in Android's CarrierConfigLoader.java, enabling local privilege escalation. This permissions bypass issue allows attackers to escalate privileges without additional execution privileges needed. Android users and administrators should prioritize patching to prevent local privilege escalation attacks. The vulnerability was published on 2026-06-17T13:1 [truncated]

MEDIUM Google CVE published 2026-06-16

CVE-2026-0165

CVE-2026-0165 debrief based on the supplied source corpus. The vulnerability is an out-of-bounds read in the RTCP packet decoder, which could lead to remote information disclosure. This issue requires user interaction for exploitation and no additional execution privileges are needed. Defenders of Android systems should assess exposure and prioritize verification. The CVE record and NVD entry provide deta [truncated]

HIGH Google CVE published 2026-06-16

CVE-2026-0164

CVE-2026-0164 is a vulnerability in the Modem component, where a missing bounds check could lead to an out-of-bounds write. This could result in remote code execution with no additional execution privileges needed. Notably, user interaction is not required for exploitation. The CVE was published on 2026-06-16T20:16:26.790Z and last modified on 2026-06-16T20:42:25.013Z. For more information, refer to [cve- [truncated]

HIGH Google CVE published 2026-06-16

CVE-2026-0162

CVE-2026-0162 is a memory corruption vulnerability due to type confusion in the ParsePayloads function of AudioSdpParser.cpp. This issue could lead to remote code execution without requiring additional execution privileges or user interaction. The vulnerability was published on [cvePublishedAt] and last modified on [cveModifiedAt].

HIGH Google CVE published 2026-06-16

CVE-2026-0161

CVE-2026-0161 is a vulnerability in the RtpSession.cpp file, which could lead to an out of bounds write due to an integer overflow. This vulnerability has the potential to allow remote escalation of privilege with no additional execution privileges needed. User interaction is not required for exploitation. The CVE was published on 2026-06-16T20:16:26.610Z and last modified on 2026-06-16T20:42:25.013Z.

HIGH Google CVE published 2026-06-16

CVE-2026-0160

CVE-2026-0160 is a vulnerability in the TextRtpPayloadDecoderNode component. An out of bounds write can lead to remote code execution with no additional execution privileges needed. User interaction is not required for exploitation. The CVE was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-0160) and last modified on [cveModifiedAt](https://nvd.nist.gov/vuln/detail/CVE-2026-0160).