These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-0129 debrief based on the supplied source corpus. The vulnerability is an information disclosure issue in the RtcpByePacket::decodeByePacket function due to a missing bounds check. This requires user interaction for exploitation. Android system administrators and security teams should assess exposure and verify patch status. The CVE record and NVD entry provide details on the vulnerability, but i [truncated]
CVE-2026-0128 is a medium-severity vulnerability in the Android operating system that can lead to remote information disclosure. The vulnerability is caused by an integer overflow in the RtcpFbPacket::decodeRtcpFbPacket function, which can result in an out-of-bounds read. User interaction is required for exploitation. This vulnerability affects Android devices and has a medium CVSS score, indicating a mod [truncated]
CVE-2026-0127 is a vulnerability in NrmmMsgCodec::DecodeUPUTransparentContext of cn_NrmmDecoder.cpp. This issue allows for a possible out-of-bounds read due to memory corruption, which could lead to a remote denial of service causing a communication processor crash. No additional execution privileges are needed for exploitation, and user interaction is not required.
CVE-2026-0126 is a possible out of bounds write vulnerability in WC-Radio. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. The CVE was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-0126) and last modified on [cveModifiedAt](https://nvd.nist.gov/vuln/detail/CVE-2026-0126).
CVE-2026-0125 is a use after free vulnerability in multiple functions of vpu_ioctl.c due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
The Model Context Protocol has a security warning advising servers to validate the 'Origin' header on all incoming connections to prevent DNS rebinding attacks. Prior to the v0.25.0 release, users had no way to validate the origin's host. In v0.25.0, a new '--allowed-hosts' flag was introduced alongside the existing '--allowed-origins' flag, enabling users to specify permitted hosts at server startup. Bot [truncated]
CVE-2026-12035 is a use after free vulnerability in Views in Google Chrome on Windows prior to 149.0.7827.115. This vulnerability, with a CVSS score of 8.8, could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2026-12034 is a High-severity vulnerability in Google Chrome on Linux. Insufficient validation of untrusted input in Linux Toolkit Theming allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].
CVE-2026-12033 is an out of bounds read vulnerability in VideoCapture in Google Chrome prior to 149.0.7827.115. This vulnerability allowed a remote attacker who had compromised the GPU process to obtain potentially sensitive information from process memory via a crafted HTML page. The CVSS score for this vulnerability is 5.3, with a severity rating of MEDIUM.
CVE-2026-12032 is a High-severity vulnerability in Google Chrome on Android prior to 149.0.7827.115. This issue involves an inappropriate implementation in Passwords, allowing a remote attacker who has compromised the renderer process to bypass site isolation via a crafted HTML page.
CVE-2026-12031 is a High-severity vulnerability in Google Chrome on Windows. The vulnerability is caused by an inappropriate implementation in Views, which could allow a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The CVSS score for this vulnerability is 8.3, indicating a High severity.
CVE-2026-12030 is a High-severity vulnerability in Google Chrome on Android, allowing a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability is caused by an out-of-bounds write in the GPU.
CVE-2026-12029 is a high-severity vulnerability in Google Chrome on Windows, allowing a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability is caused by a use-after-free issue in the Video component. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code in the context of the sandbox.
CVE-2026-12028 is a high-severity vulnerability in Google Chrome on Android prior to version 149.0.7827.115. The vulnerability is a use-after-free issue in the GPU, which could allow a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The CVSS score for this vulnerability is 8.3, indicating a high level of severity.
A critical vulnerability, CVE-2026-12027, was discovered in Google Chrome prior to version 149.0.7827.115. The issue is related to an inappropriate implementation in Headless, which could allow a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. This vulnerability has been assigned a CVSS score of 9.6, indicating a critical severity level.
CVE-2026-12026 is an out of bounds read vulnerability in Video in Google Chrome on ChromeOS prior to 149.0.7827.115. A remote attacker who had compromised the renderer process could obtain potentially sensitive information from process memory via a crafted HTML page. The Chromium security severity is rated as High.
CVE-2026-12025 is a vulnerability in Google Chrome prior to version 149.0.7827.115. The issue is related to insufficient validation of untrusted input in the Network component, which could allow a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. The Chromium security severity of this vulnerability is rated as High, and the CVSS score is 5.3, with [truncated]
CVE-2026-12024 is a vulnerability in Google Chrome prior to version 149.0.7827.115. The issue is related to insufficient policy enforcement in DevTools, which allowed a remote attacker to bypass the same origin policy via a crafted HTML page. The vulnerability has a CVSS score of 6.5 and is classified as Medium severity.
CVE-2026-12023 is a Use after free vulnerability in the GPU of Google Chrome on Mac systems. This vulnerability, with a CVSS score of 8.3, could allow a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].
A High-severity vulnerability, CVE-2026-12022, was found in Google Chrome on Mac. This issue, caused by a race condition in Safe Browsing, could allow a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].
CVE-2026-12020 is a high-severity vulnerability in Google Chrome on Mac, allowing remote attackers to potentially exploit heap corruption via a crafted HTML page. The vulnerability is caused by a use-after-free issue in the Autofill feature. Successful exploitation could lead to heap corruption.
CVE-2026-12019 is a High-severity vulnerability in Google Chrome's Codecs component. A remote attacker who has compromised the renderer process can exploit this heap buffer overflow vulnerability via a crafted HTML page to potentially perform a sandbox escape.
CVE-2026-12018 is a High-severity vulnerability in Google Chrome on Windows, allowing local attackers to perform OS-level privilege escalation via a malicious file. The vulnerability is caused by an inappropriate implementation in Mojo and was patched in version 149.0.7827.115.
CVE-2026-12017 is a High-severity vulnerability in Google Chrome prior to 149.0.7827.115. This issue is related to an inappropriate implementation in Extensions, which allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. The CVSS score for this vulnerability is 3.1, with a severity rating of LOW. The vulnerability was published on [cvePublish [truncated]
A High-severity vulnerability, CVE-2026-12016, was found in Google Chrome prior to version 149.0.7827.115. The vulnerability is caused by an inappropriate implementation in DevTools, which could allow a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVE-2026-12015 is a use after free vulnerability in Autofill in Google Chrome prior to version 149.0.7827.115. This vulnerability allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. The Chromium security severity of this vulnerability is rated as High, and it has a CVSS score of 5.3, which is considered [truncated]
CVE-2026-12014 is a High severity vulnerability in Google Chrome prior to 149.0.7827.115. The vulnerability is a use after free in Cast, which could allow an attacker on the local network segment to potentially perform a sandbox escape via malicious network traffic. The CVSS score for this vulnerability is 8.3, indicating a High severity. The vulnerability was published on [cvePublishedAt] and modified on [truncated]
CVE-2026-12013 is a high-severity vulnerability in Google Chrome on Windows, allowing remote attackers to potentially exploit heap corruption via a crafted HTML page. The vulnerability is caused by a use-after-free issue in the Media component.
CVE-2026-12012 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.115. The vulnerability is a use-after-free issue in the Network component, which could allow an attacker in a privileged network position to potentially exploit heap corruption via malicious network traffic. The CVSS score for this vulnerability is 8.1, indicating a high level of severity.
CVE-2026-12011 is a high-severity vulnerability in Google Chrome on Windows, allowing a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability is caused by a use-after-free issue in WebMIDI. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code in the context of the browser.