PatchSiren

Google CVE debriefs · Page 21

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Google CVE published 2026-06-16

CVE-2026-0129

CVE-2026-0129 debrief based on the supplied source corpus. The vulnerability is an information disclosure issue in the RtcpByePacket::decodeByePacket function due to a missing bounds check. This requires user interaction for exploitation. Android system administrators and security teams should assess exposure and verify patch status. The CVE record and NVD entry provide details on the vulnerability, but i [truncated]

MEDIUM Google CVE published 2026-06-16

CVE-2026-0128

CVE-2026-0128 is a medium-severity vulnerability in the Android operating system that can lead to remote information disclosure. The vulnerability is caused by an integer overflow in the RtcpFbPacket::decodeRtcpFbPacket function, which can result in an out-of-bounds read. User interaction is required for exploitation. This vulnerability affects Android devices and has a medium CVSS score, indicating a mod [truncated]

MEDIUM Google CVE published 2026-06-16

CVE-2026-0127

CVE-2026-0127 is a vulnerability in NrmmMsgCodec::DecodeUPUTransparentContext of cn_NrmmDecoder.cpp. This issue allows for a possible out-of-bounds read due to memory corruption, which could lead to a remote denial of service causing a communication processor crash. No additional execution privileges are needed for exploitation, and user interaction is not required.

CRITICAL Google CVE published 2026-06-16

CVE-2026-0126

CVE-2026-0126 is a possible out of bounds write vulnerability in WC-Radio. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. The CVE was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-0126) and last modified on [cveModifiedAt](https://nvd.nist.gov/vuln/detail/CVE-2026-0126).

HIGH Google CVE published 2026-06-16

CVE-2026-0125

CVE-2026-0125 is a use after free vulnerability in multiple functions of vpu_ioctl.c due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CRITICAL Google CVE published 2026-06-13

CVE-2026-11624

The Model Context Protocol has a security warning advising servers to validate the 'Origin' header on all incoming connections to prevent DNS rebinding attacks. Prior to the v0.25.0 release, users had no way to validate the origin's host. In v0.25.0, a new '--allowed-hosts' flag was introduced alongside the existing '--allowed-origins' flag, enabling users to specify permitted hosts at server startup. Bot [truncated]

HIGH Google CVE published 2026-06-11

CVE-2026-12035

CVE-2026-12035 is a use after free vulnerability in Views in Google Chrome on Windows prior to 149.0.7827.115. This vulnerability, with a CVSS score of 8.8, could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page.

HIGH Google CVE published 2026-06-11

CVE-2026-12034

CVE-2026-12034 is a High-severity vulnerability in Google Chrome on Linux. Insufficient validation of untrusted input in Linux Toolkit Theming allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].

MEDIUM Google CVE published 2026-06-11

CVE-2026-12033

CVE-2026-12033 is an out of bounds read vulnerability in VideoCapture in Google Chrome prior to 149.0.7827.115. This vulnerability allowed a remote attacker who had compromised the GPU process to obtain potentially sensitive information from process memory via a crafted HTML page. The CVSS score for this vulnerability is 5.3, with a severity rating of MEDIUM.

LOW Google CVE published 2026-06-11

CVE-2026-12032

CVE-2026-12032 is a High-severity vulnerability in Google Chrome on Android prior to 149.0.7827.115. This issue involves an inappropriate implementation in Passwords, allowing a remote attacker who has compromised the renderer process to bypass site isolation via a crafted HTML page.

HIGH Google CVE published 2026-06-11

CVE-2026-12031

CVE-2026-12031 is a High-severity vulnerability in Google Chrome on Windows. The vulnerability is caused by an inappropriate implementation in Views, which could allow a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The CVSS score for this vulnerability is 8.3, indicating a High severity.

HIGH Google CVE published 2026-06-11

CVE-2026-12030

CVE-2026-12030 is a High-severity vulnerability in Google Chrome on Android, allowing a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability is caused by an out-of-bounds write in the GPU.

HIGH Google CVE published 2026-06-11

CVE-2026-12029

CVE-2026-12029 is a high-severity vulnerability in Google Chrome on Windows, allowing a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability is caused by a use-after-free issue in the Video component. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code in the context of the sandbox.

HIGH Google CVE published 2026-06-11

CVE-2026-12028

CVE-2026-12028 is a high-severity vulnerability in Google Chrome on Android prior to version 149.0.7827.115. The vulnerability is a use-after-free issue in the GPU, which could allow a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The CVSS score for this vulnerability is 8.3, indicating a high level of severity.

CRITICAL Google CVE published 2026-06-11

CVE-2026-12027

A critical vulnerability, CVE-2026-12027, was discovered in Google Chrome prior to version 149.0.7827.115. The issue is related to an inappropriate implementation in Headless, which could allow a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. This vulnerability has been assigned a CVSS score of 9.6, indicating a critical severity level.

MEDIUM Google CVE published 2026-06-11

CVE-2026-12026

CVE-2026-12026 is an out of bounds read vulnerability in Video in Google Chrome on ChromeOS prior to 149.0.7827.115. A remote attacker who had compromised the renderer process could obtain potentially sensitive information from process memory via a crafted HTML page. The Chromium security severity is rated as High.

MEDIUM Google CVE published 2026-06-11

CVE-2026-12025

CVE-2026-12025 is a vulnerability in Google Chrome prior to version 149.0.7827.115. The issue is related to insufficient validation of untrusted input in the Network component, which could allow a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. The Chromium security severity of this vulnerability is rated as High, and the CVSS score is 5.3, with [truncated]

MEDIUM Google CVE published 2026-06-11

CVE-2026-12024

CVE-2026-12024 is a vulnerability in Google Chrome prior to version 149.0.7827.115. The issue is related to insufficient policy enforcement in DevTools, which allowed a remote attacker to bypass the same origin policy via a crafted HTML page. The vulnerability has a CVSS score of 6.5 and is classified as Medium severity.

HIGH Google CVE published 2026-06-11

CVE-2026-12023

CVE-2026-12023 is a Use after free vulnerability in the GPU of Google Chrome on Mac systems. This vulnerability, with a CVSS score of 8.3, could allow a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].

HIGH Google CVE published 2026-06-11

CVE-2026-12022

A High-severity vulnerability, CVE-2026-12022, was found in Google Chrome on Mac. This issue, caused by a race condition in Safe Browsing, could allow a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].

HIGH Google CVE published 2026-06-11

CVE-2026-12020

CVE-2026-12020 is a high-severity vulnerability in Google Chrome on Mac, allowing remote attackers to potentially exploit heap corruption via a crafted HTML page. The vulnerability is caused by a use-after-free issue in the Autofill feature. Successful exploitation could lead to heap corruption.

HIGH Google CVE published 2026-06-11

CVE-2026-12019

CVE-2026-12019 is a High-severity vulnerability in Google Chrome's Codecs component. A remote attacker who has compromised the renderer process can exploit this heap buffer overflow vulnerability via a crafted HTML page to potentially perform a sandbox escape.

HIGH Google CVE published 2026-06-11

CVE-2026-12018

CVE-2026-12018 is a High-severity vulnerability in Google Chrome on Windows, allowing local attackers to perform OS-level privilege escalation via a malicious file. The vulnerability is caused by an inappropriate implementation in Mojo and was patched in version 149.0.7827.115.

LOW Google CVE published 2026-06-11

CVE-2026-12017

CVE-2026-12017 is a High-severity vulnerability in Google Chrome prior to 149.0.7827.115. This issue is related to an inappropriate implementation in Extensions, which allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. The CVSS score for this vulnerability is 3.1, with a severity rating of LOW. The vulnerability was published on [cvePublish [truncated]

HIGH Google CVE published 2026-06-11

CVE-2026-12016

A High-severity vulnerability, CVE-2026-12016, was found in Google Chrome prior to version 149.0.7827.115. The vulnerability is caused by an inappropriate implementation in DevTools, which could allow a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

MEDIUM Google CVE published 2026-06-11

CVE-2026-12015

CVE-2026-12015 is a use after free vulnerability in Autofill in Google Chrome prior to version 149.0.7827.115. This vulnerability allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. The Chromium security severity of this vulnerability is rated as High, and it has a CVSS score of 5.3, which is considered [truncated]

HIGH Google CVE published 2026-06-11

CVE-2026-12014

CVE-2026-12014 is a High severity vulnerability in Google Chrome prior to 149.0.7827.115. The vulnerability is a use after free in Cast, which could allow an attacker on the local network segment to potentially perform a sandbox escape via malicious network traffic. The CVSS score for this vulnerability is 8.3, indicating a High severity. The vulnerability was published on [cvePublishedAt] and modified on [truncated]

HIGH Google CVE published 2026-06-11

CVE-2026-12013

CVE-2026-12013 is a high-severity vulnerability in Google Chrome on Windows, allowing remote attackers to potentially exploit heap corruption via a crafted HTML page. The vulnerability is caused by a use-after-free issue in the Media component.

HIGH Google CVE published 2026-06-11

CVE-2026-12012

CVE-2026-12012 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.115. The vulnerability is a use-after-free issue in the Network component, which could allow an attacker in a privileged network position to potentially exploit heap corruption via malicious network traffic. The CVSS score for this vulnerability is 8.1, indicating a high level of severity.

HIGH Google CVE published 2026-06-11

CVE-2026-12011

CVE-2026-12011 is a high-severity vulnerability in Google Chrome on Windows, allowing a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability is caused by a use-after-free issue in WebMIDI. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code in the context of the browser.