These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-11293 is a use-after-free vulnerability in the Input component of Google Chrome, affecting versions prior to 149.0.7827.53. This vulnerability, with a CVSS score of 9.6, could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].
A vulnerability was discovered in Google Chrome on Android, specifically in the Android Autofill feature. This issue, tracked as CVE-2026-11291, allowed a remote attacker to bypass the same origin policy via a crafted HTML page. The vulnerability was rated as Low severity by Chromium and has a CVSS score of 4.3, which categorizes it as MEDIUM severity.
CVE-2026-11290 is an integer overflow vulnerability in WebView in Google Chrome on Android prior to 149.0.7827.53. A local attacker can exploit this vulnerability to cause a denial of service via a malicious file. The CVSS score for this vulnerability is 5, and the severity is MEDIUM.
CVE-2026-11289 is a MEDIUM severity vulnerability in Google Chrome prior to 149.0.7827.53. This vulnerability, described as a side-channel information leakage in Paint, allows a remote attacker to leak cross-origin data via a crafted HTML page. The vulnerability has a CVSS score of 6.5 and is considered by Chromium as having a Low security severity.
CVE-2026-11288 is a vulnerability in Google Chrome prior to version 149.0.7827.53. The issue is related to insufficient policy enforcement in CSS, which could allow a remote attacker to leak cross-origin data via a crafted HTML page. The Chromium security severity of this vulnerability is rated as Low, and it has a CVSS score of 6.5, categorized as MEDIUM severity.
CVE-2026-11287 is a vulnerability in Google Chrome on Android, prior to version 149.0.7827.53, that allows a remote attacker who has compromised the renderer process to bypass navigation restrictions via a crafted HTML page. The vulnerability has a CVSS score of 6.5 and is classified as Medium severity.
CVE-2026-11286 is a vulnerability in Google Chrome prior to version 149.0.7827.53. The issue is related to insufficient validation of untrusted input in Wallet, which allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. The Chromium security severity of this vulnerability is rated as Low, and it has a CVSS score of 4.3, which is considered MEDIUM.
A vulnerability was discovered in Google Chrome for iOS, allowing a remote attacker to perform UI spoofing via a crafted HTML page. This issue was addressed in Chrome version 149.0.7827.53.
CVE-2026-11284 is a side-channel information leakage vulnerability in PerformanceAPIs in Google Chrome prior to version 149.0.7827.53. This vulnerability, with a CVSS score of 6.5 and a severity of MEDIUM, allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2026-11283 is a vulnerability in Google Chrome on Mac, specifically affecting the Shortcuts feature. The issue, categorized as Insufficient validation of untrusted input, allowed a remote attacker to bypass navigation restrictions via a malicious file. This vulnerability was rated as Low severity by Chromium and has a CVSS score of 6.5, classified as MEDIUM.
CVE-2026-11281 is an integer overflow vulnerability in Chromoting in Google Chrome on Windows prior to 149.0.7827.53. This vulnerability allowed a local attacker to obtain potentially sensitive information from process memory via a crafted ETW event. The CVSS score for this vulnerability is 5, with a severity rating of MEDIUM. The vulnerability was published on [cvePublishedAt](https://www.cve.org/CVEReco [truncated]
CVE-2026-11280 is a MEDIUM severity vulnerability in Google Chrome on iOS prior to 149.0.7827.53. This vulnerability, described as an inappropriate implementation in Signin, allows a remote attacker to perform UI spoofing via a crafted HTML page. The CVSS score for this vulnerability is 4.3.
CVE-2026-11279 is an out of bounds read vulnerability in DevTools in Google Chrome prior to 149.0.7827.53. This vulnerability allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The Chromium security severity of this vulnerability is rated as Low. The CVSS score for this vulnerability is 8.8, which is considered HIGH.
CVE-2026-11277 is a vulnerability in Google Chrome on iOS prior to 149.0.7827.53. The vulnerability is caused by insufficient policy enforcement, which allowed a remote attacker to bypass discretionary access control via a crafted HTML page. The Chromium security severity is rated as Low, and the CVSS score is 4.3, with a severity rating of MEDIUM.
CVE-2026-11275 is a vulnerability in Google Chrome on Android, prior to version 149.0.7827.53. The issue is an inappropriate implementation in Page Info, which allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. The Chromium security severity is rated as Low, and the CVSS score is 6.5 (Medium).
A MEDIUM severity vulnerability, CVE-2026-11274, was found in Google Chrome on iOS prior to 149.0.7827.53. This issue is related to an inappropriate implementation in DOM Distiller, which could allow a remote attacker to bypass navigation restrictions via a crafted HTML page. The CVSS score for this vulnerability is 4.3.
CVE-2026-11273 is a MEDIUM severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by insufficient validation of untrusted input in Omnibox, allowing a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. The CVSS score for this vulnerability is 6.1.
CVE-2026-11272 is a vulnerability in Google Chrome on iOS, specifically affecting the Reading List feature. An attacker could exploit this vulnerability by convincing a user to engage in specific UI gestures, allowing for privilege escalation via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity.
CVE-2026-11271 is a MEDIUM severity vulnerability in Google Chrome prior to 149.0.7827.53. This vulnerability is caused by an inappropriate implementation in Passwords, allowing a remote attacker who convinces a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. The CVSS score for this vulnerability is 6.5.
CVE-2026-11270 is a MEDIUM severity vulnerability in Google Chrome on Android prior to 149.0.7827.53. This vulnerability is caused by an inappropriate implementation in the UI, which allows a remote attacker to leak cross-origin data via a crafted HTML page. The Chromium security severity is rated as Low.
CVE-2026-11269 is a vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is related to an inappropriate implementation in Extensions, which allowed an attacker in a privileged network position to execute arbitrary code inside a sandbox via a crafted Chrome Extension. The Chromium security severity of this vulnerability is rated as Low, but the CVSS score is 7.1, indicating a High severity.
CVE-2026-11268 is a vulnerability in Google Chrome on Windows, specifically in the ANGLE (Almost Native Graphics Layer Engine) component. The vulnerability is caused by an uninitialized use issue, which allows a remote attacker to leak cross-origin data via a crafted HTML page. The vulnerability has a CVSS score of 6.5 and is classified as Medium severity.
CVE-2026-11267 is a MEDIUM severity vulnerability in Google Chrome prior to 149.0.7827.53. The vulnerability is caused by insufficient policy enforcement in Extensions, which allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension. The Chromium security severity is rated as Low. The CVSS score is 4.3.
A vulnerability was discovered in Google Chrome prior to version 149.0.7827.53. The issue is related to an inappropriate implementation in SafeBrowsing, which could allow a remote attacker to bypass Safe Browsing via a malicious file. The Chromium security severity of this issue is rated as Low, and the CVSS score is 4.3, indicating a Medium severity.
A vulnerability was discovered in Google Chrome's Autofill feature, which could allow a remote attacker to leak cross-origin data via a crafted HTML page. This issue was addressed in Google Chrome version 149.0.7827.53.
CVE-2026-11263 is a vulnerability in Google Chrome on Android, specifically related to insufficient policy enforcement in WebAuthentication. This issue, with a CVSS score of 6.5 and a Medium severity level, could allow a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.
CVE-2026-11262 is a use-after-free vulnerability in the TabStrip component of Google Chrome prior to version 149.0.7827.53. This vulnerability could allow a remote attacker to execute arbitrary code via a crafted HTML page. The CVSS score for this vulnerability is 8.8, indicating a high severity level. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].
CVE-2026-11261 is a vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is related to an inappropriate implementation in PDF, which allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. The Chromium security severity of this vulnerability is Low, and the CVSS score is 4.3, which is considered MEDIUM.
CVE-2026-11260 is a MEDIUM severity vulnerability in Google Chrome prior to 149.0.7827.53. This vulnerability is caused by an inappropriate implementation in Permissions, allowing a remote attacker to bypass content security policy via a crafted HTML page. The CVSS score for this vulnerability is 4.3.
CVE-2026-11259 is a vulnerability in Google Chrome prior to version 149.0.7827.53. The issue is related to insufficient validation of untrusted input in the Cast feature, which could allow a remote attacker to bypass the same-origin policy via a crafted HTML page. The vulnerability has a CVSS score of 4.3, indicating a medium severity level.