PatchSiren

Google CVE debriefs · Page 22

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Google CVE published 2026-06-11

CVE-2026-12010

CVE-2026-12010 is a critical vulnerability in Google Chrome on Android, specifically a heap buffer overflow in the GPU. This vulnerability, published on [cvePublishedAt], was exploited via a crafted HTML page, potentially allowing a remote attacker who had compromised the renderer process to perform a sandbox escape.

HIGH Google CVE published 2026-06-11

CVE-2026-12008

CVE-2026-12008 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.115. The vulnerability is a use-after-free issue in the DigitalCredentials component, which could allow a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The CVSS score for this vulnerability is 8.3, indicating a high level of severity.

HIGH Google CVE published 2026-06-11

CVE-2026-12007

CVE-2026-12007 is a critical use after free vulnerability in Google Chrome on Windows prior to version 149.0.7827.115. This vulnerability allowed a remote attacker to execute arbitrary code via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity.

MEDIUM Google CVE published 2026-06-09

CVE-2026-11701

CVE-2026-11701 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.103. This issue is related to an inappropriate implementation in the Guest View feature, which could allow a remote attacker to perform UI spoofing via a crafted HTML page. The vulnerability has a CVSS score of 5.4 and is categorized as Medium severity.

HIGH Google CVE published 2026-06-09

CVE-2026-11700

CVE-2026-11700 is a use-after-free vulnerability in the Tracing component of Google Chrome prior to version 149.0.7827.103. This vulnerability could allow a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The CVSS score for this vulnerability is 8.3, indicating a high severity. The vulnerability was published on [cvePublishedAt] and [truncated]

HIGH Google CVE published 2026-06-09

CVE-2026-11699

CVE-2026-11699 is a Use after free vulnerability in Bluetooth in Google Chrome on Mac. This vulnerability, with a CVSS score of 8.8, could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. The vulnerability was published on June 9, 2026, and has been categorized as High severity by Chromium.

HIGH Google CVE published 2026-06-09

CVE-2026-11698

CVE-2026-11698 is a Use after free vulnerability in Bluetooth in Google Chrome on Mac. The vulnerability was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-11698) and had a CVSS score of 8.8, indicating High severity. The vulnerability allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. The vulnerability was fixed in Google Chrome version 149.0.7827.103.

CRITICAL Google CVE published 2026-06-09

CVE-2026-11697

CVE-2026-11697 is a critical vulnerability in Google Chrome prior to version 149.0.7827.103. The issue involves insufficient validation of untrusted input in the UI, which could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. This vulnerability has been rated as Critical with a CVSS score of 9.6.

MEDIUM Google CVE published 2026-06-09

CVE-2026-11696

CVE-2026-11696 is a High severity vulnerability in Google Chrome on Windows prior to 149.0.7827.103. A remote attacker who had compromised the renderer process could obtain potentially sensitive information from process memory via a crafted HTML page. The CVSS score for this vulnerability is 5.3, with a severity rating of MEDIUM.

MEDIUM Google CVE published 2026-06-09

CVE-2026-11695

A vulnerability was discovered in Google Chrome prior to version 149.0.7827.103. The issue is related to an inappropriate implementation in the Passwords feature, which could allow a remote attacker to leak cross-origin data via a crafted HTML page. The Chromium security severity of this vulnerability is rated as High, with a CVSS score of 4.3, indicating a Medium severity level.

HIGH Google CVE published 2026-06-09

CVE-2026-11694

CVE-2026-11694 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.103. This use-after-free issue in ServiceWorker allows a remote attacker who has compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability has a CVSS score of 7.5 and is considered High severity by Chromium.

HIGH Google CVE published 2026-06-09

CVE-2026-11693

CVE-2026-11693 is a High-severity vulnerability in Google Chrome prior to version 149.0.7827.103. The vulnerability is caused by an inappropriate implementation in Plugins, allowing a remote attacker who has compromised the renderer process to bypass site isolation via a crafted HTML page. The CVSS score for this vulnerability is 8.1.

HIGH Google CVE published 2026-06-09

CVE-2026-11692

CVE-2026-11692 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.103. The vulnerability is a use-after-free issue in the Read Anything feature, which could allow a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The CVSS score for this vulnerability is 8.3, indicating a high level of severity.

LOW Google CVE published 2026-06-09

CVE-2026-11691

CVE-2026-11691 is a vulnerability in Google Chrome prior to version 149.0.7827.103. The vulnerability is caused by insufficient validation of untrusted input in the New Tab Page. This allows a remote attacker who has compromised the renderer process to leak cross-origin data via a crafted HTML page. The Chromium security severity of this vulnerability is High, but the CVSS score is 3.1, indicating a Low severity.

HIGH Google CVE published 2026-06-09

CVE-2026-11690

CVE-2026-11690 is a High severity vulnerability in Google Chrome on Mac, allowing a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability is caused by an out of bounds read and write in the Media component.

HIGH Google CVE published 2026-06-09

CVE-2026-11689

CVE-2026-11689 is a High-severity vulnerability in Google Chrome prior to version 149.0.7827.103. The issue involves insufficient policy enforcement in Passwords, allowing a remote attacker who has compromised the renderer process to bypass site isolation via a crafted HTML page.

HIGH Google CVE published 2026-06-09

CVE-2026-11688

CVE-2026-11688 is a High-severity vulnerability in Google Chrome prior to version 149.0.7827.103. This inappropriate implementation in SVG allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-11688).

HIGH Google CVE published 2026-06-09

CVE-2026-11687

CVE-2026-11687 is a high-severity vulnerability in Google Chrome on Mac, allowing remote attackers to potentially exploit heap corruption via a crafted HTML page. The vulnerability is caused by a use-after-free issue in the Dawn component. Users can mitigate this vulnerability by updating Google Chrome to version 149.0.7827.103 or later.

LOW Google CVE published 2026-06-09

CVE-2026-11686

CVE-2026-11686 is a vulnerability in Google Chrome on macOS, specifically in the Dawn component. The issue is caused by insufficient validation of untrusted input, which could allow a remote attacker who has compromised the renderer process to leak cross-origin data via a crafted HTML page. This vulnerability has been rated as High severity by Chromium and has a CVSS score of 3.1, which is considered Low severity.

MEDIUM Google CVE published 2026-06-09

CVE-2026-11685

CVE-2026-11685 is a High-severity vulnerability in Google Chrome on Mac. It was reported on June 9, 2026, and patched in version 149.0.7827.103. An attacker could exploit the inappropriate implementation in MediaCapture to leak cross-origin data via a crafted HTML page.

LOW Google CVE published 2026-06-09

CVE-2026-11684

CVE-2026-11684 is a vulnerability in Google Chrome prior to version 149.0.7827.103. The vulnerability is caused by insufficient policy enforcement in the Network component, allowing a remote attacker who has compromised the utility process to leak cross-origin data via a crafted HTML page. The Chromium security severity of this vulnerability is High, but the CVSS score is 3.1, indicating a Low severity.

HIGH Google CVE published 2026-06-09

CVE-2026-11683

CVE-2026-11683 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.103. This use-after-free issue in WebCodecs allows remote attackers to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and is considered High severity by Chromium.

HIGH Google CVE published 2026-06-09

CVE-2026-11682

CVE-2026-11682 is a High-severity vulnerability in Google Chrome on Linux prior to 149.0.7827.103. A remote attacker who had compromised the renderer process could potentially perform a sandbox escape via a crafted HTML page. The vulnerability has a CVSS score of 8.3 and was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-11682).

HIGH Google CVE published 2026-06-09

CVE-2026-11681

CVE-2026-11681 is a high-severity vulnerability in Google Chrome on Linux, allowing remote attackers to potentially exploit heap corruption via a crafted HTML page. This use-after-free issue was reported in the Ozone component of Google Chrome prior to version 149.0.7827.103.

HIGH Google CVE published 2026-06-09

CVE-2026-11680

CVE-2026-11680 is a high-severity vulnerability in Google Chrome on Windows, allowing remote attackers to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability is caused by a use-after-free issue in the Media component. (Chromium security severity: High) The CVSS score for this vulnerability is 8.8, indicating a high level of severity.

HIGH Google CVE published 2026-06-09

CVE-2026-11679

CVE-2026-11679 is a high-severity vulnerability in Google Chrome on Windows, allowing a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability is caused by a use-after-free issue in the Codecs component.

MEDIUM Google CVE published 2026-06-09

CVE-2026-11678

CVE-2026-11678 is an integer overflow vulnerability in libyuv in Google Chrome prior to 149.0.7827.103. A remote attacker who had compromised the renderer process could obtain potentially sensitive information from process memory via a crafted HTML page. The CVSS score for this vulnerability is 5.3, with a severity of MEDIUM. The vulnerability was published on [cve-org](https://www.cve.org/CVERecord?id=CV [truncated]

HIGH Google CVE published 2026-06-09

CVE-2026-11677

CVE-2026-11677 is a High-severity vulnerability in Google Chrome on Mac. A remote attacker who has compromised the network process can potentially perform a sandbox escape via a crafted HTML page. The vulnerability was published on June 9, 2026, and has a CVSS score of 8.3.

HIGH Google CVE published 2026-06-09

CVE-2026-11676

CVE-2026-11676 is a High-severity vulnerability in Google Chrome. Insufficient validation of untrusted input in Dawn allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

LOW Google CVE published 2026-06-09

CVE-2026-11675

CVE-2026-11675 is an out-of-bounds read vulnerability in Skia, a graphics library used in Google Chrome. This vulnerability, which was reported on June 9, 2026, and had a CVSS score of 3.1, allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.