These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-11641 is a high-severity vulnerability in Google Chrome on Windows, allowing remote attackers to execute arbitrary code via a crafted HTML page. The vulnerability is caused by a use-after-free issue in the Bluetooth component of Google Chrome. An attacker can exploit this vulnerability by convincing a user to engage in specific UI gestures.
CVE-2026-11640 is an integer overflow vulnerability in libyuv in Google Chrome prior to 149.0.7827.103. A remote attacker who had compromised the renderer process could potentially perform a sandbox escape via a crafted HTML page. The vulnerability has a CVSS score of 8.3 and is considered HIGH severity.
CVE-2026-11639 is a high-severity vulnerability in Google Chrome on Mac, allowing remote attackers to execute arbitrary code via a crafted HTML page. The vulnerability is caused by a use-after-free issue in the Compositing component. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system. The CVSS score for this vulnerability is 7.5, indicati [truncated]
CVE-2026-11638 is a critical vulnerability in Google Chrome prior to version 149.0.7827.103. The vulnerability is caused by a use-after-free issue in the Printing component, which could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The CVSS score for this vulnerability is 9.6, indicating a high severity.
CVE-2026-11637 is a high-severity vulnerability in Google Chrome on Mac, with a CVSS score of 8.8. The vulnerability is caused by a use-after-free issue in the Views component, which can be exploited by a remote attacker to execute arbitrary code via a crafted HTML page. The vulnerability was published on June 9, 2026, and has been patched in Google Chrome version 149.0.7827.103.
CVE-2026-11636 is a high-severity vulnerability in Google Chrome on Windows, allowing potential heap corruption via a crafted HTML page. The vulnerability is caused by a use-after-free issue in the Autofill feature. An attacker could exploit this vulnerability by convincing a user to engage in specific UI gestures.
CVE-2026-11635 is a high-severity vulnerability in Google Chrome on Mac, allowing a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability is caused by a use-after-free issue in the Bluetooth component. The CVSS score for this vulnerability is 8.3, indicating a high level of severity.
CVE-2026-11634 is a critical vulnerability in Google Chrome on Windows, allowing a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability is caused by a use-after-free issue in the Gamepad component. The CVSS score for this vulnerability is 9.6, indicating a high severity.
CVE-2026-11633 is a high-severity vulnerability in Google Chrome on Mac, with a CVSS score of 8.8. The vulnerability is caused by a use-after-free issue in the Bluetooth component, which can be exploited by a remote attacker to execute arbitrary code via a malicious peripheral. This vulnerability was published on June 9, 2026, and has been patched in Google Chrome version 149.0.7827.103.
CVE-2026-11632 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.103. The vulnerability is caused by a use-after-free issue in the TabStrip component. An attacker can exploit this vulnerability by convincing a user to engage in specific UI gestures and then execute arbitrary code via a crafted HTML page. The CVSS score for this vulnerability is 7.5, indicating a high level of severity.
CVE-2026-11631 is a high-severity vulnerability in Google Chrome on Windows, allowing a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability is caused by a use-after-free issue in the Aura component. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code in the context of the sandbox.
CVE-2026-11630 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.103. The vulnerability is caused by a use-after-free issue in the File Input component, which could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. The CVSS score for this vulnerability is 8.8, indicating a high level of severity.
CVE-2026-11629 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.103. The vulnerability is caused by a use-after-free issue in the Ozone component, which could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. The CVSS score for this vulnerability is 8.8, indicating a high level of severity.
CVE-2026-11628 is a use-after-free vulnerability in Ozone, a component of Google Chrome. This vulnerability, which has a CVSS score of 6.8 and is classified as Medium severity, could allow a local attacker to potentially exploit heap corruption via physical access to the device. The vulnerability was published on June 9, 2026, and last modified on the same day.
Google Chromium V8 Out-of-Bounds Read and Write Vulnerability debrief. The vulnerability has been added to the CISA Known Exploited Vulnerabilities catalog, indicating potential for exploitation. Defenders responsible for Google Chromium V8 deployments should assess exposure and prioritize mitigations. Cloud service providers should follow BOD 22-01 guidance. The vulnerability is a high-severity issue in [truncated]
CVE-2026-11309 is a vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by insufficient policy enforcement in History, which allows a remote attacker to perform UI spoofing via a crafted HTML page. The Chromium security severity of this vulnerability is Low, and the CVSS score is 4.3, which is considered MEDIUM.
CVE-2026-11308 is a MEDIUM severity vulnerability in Google Chrome prior to 149.0.7827.53. The vulnerability is caused by an inappropriate implementation in Extensions, which allows an attacker who convinced a user to install a malicious extension to perform privilege escalation via a crafted Chrome Extension. The CVSS score for this vulnerability is 6.3.
CVE-2026-11307 is a use-after-free vulnerability in PDFium in Google Chrome prior to 149.0.7827.53. This vulnerability allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. The CVSS score for this vulnerability is 8.8, indicating a high severity. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].
CVE-2026-11306 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is a use-after-free issue in PDFium, which could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. The CVSS score for this vulnerability is 8.8, indicating a high severity. This vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].
CVE-2026-11305 is a use after free vulnerability in PDFium in Google Chrome prior to 149.0.7827.53. This vulnerability allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. The Chromium security severity is rated as Low, but the CVSS score is 8.8, indicating a HIGH severity. The CVE was published on 2026-06-05T00:17:08.477Z and modified on 2026-06-08T18:04:34.180Z.
CVE-2026-11304 is a use-after-free vulnerability in PDFium in Google Chrome prior to 149.0.7827.53. This vulnerability could allow a remote attacker to potentially exploit heap corruption via a crafted PDF file. The Chromium security severity is rated as Low.
CVE-2026-11303 is a use-after-free vulnerability in PDFium in Google Chrome prior to 149.0.7827.53. This vulnerability allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. The CVSS score for this vulnerability is 8.8, indicating a high severity. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].
CVE-2026-11302 is a vulnerability in Google Chrome on iOS prior to 149.0.7827.53. The vulnerability is caused by insufficient policy enforcement, which allowed a remote attacker to bypass discretionary access control via a crafted HTML page. The Chromium security severity is rated as Low, and the CVSS score is 4.3, with a severity rating of MEDIUM.
A vulnerability was discovered in Google Chrome prior to version 149.0.7827.53, specifically in the LiveCaption feature. This issue, tracked as CVE-2026-11301, is related to an inappropriate implementation that could allow a remote attacker to potentially perform out of bounds memory access via malicious network traffic. The Chromium security team classified this issue as having a Low severity. The vulner [truncated]
CVE-2026-11300 is a MEDIUM severity vulnerability in Google Chrome prior to 149.0.7827.53. This vulnerability is caused by an inappropriate implementation in Permissions, allowing a remote attacker to perform UI spoofing via a crafted HTML page. The Chromium security severity is rated as Low.
CVE-2026-11299 is an integer overflow vulnerability in Google Chrome's Fonts component prior to version 149.0.7827.53. This CVE was published on 2026-06-05T00:17:07.700Z and last modified on 2026-06-09T13:43:58.697Z. The vulnerability allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. The CVSS score for this vulnerability is 6.5, with a sever [truncated]
CVE-2026-11298 is a vulnerability in Google Chrome for iOS prior to version 149.0.7827.53. The vulnerability is caused by an inappropriate implementation in Chrome for iOS, which allowed a remote attacker to bypass same origin policy via a crafted HTML page. The CVSS score for this vulnerability is 4.3, and the severity is MEDIUM.
CVE-2026-11296 is a vulnerability in Google Chrome prior to version 149.0.7827.53. The issue is related to an inappropriate implementation in ImageCapture, which could allow a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. The Chromium security severity of this issue is rated as Low. The CVSS score for this vulnerability is 7.5, and the CV [truncated]
A HIGH severity vulnerability, CVE-2026-11295, was found in Google Chrome on Android prior to 149.0.7827.53. This vulnerability, caused by an inappropriate implementation in WebView, allows a remote attacker to perform privilege escalation via a crafted HTML page. The CVSS score for this vulnerability is 8.8.
CVE-2026-11294 is a low-severity UI spoofing vulnerability in Google Chrome prior to version 149.0.7827.53. This vulnerability allowed a remote attacker to spoof the user interface via a crafted HTML page. The vulnerability has a CVSS score of 4.3 and is classified as Medium severity.