PatchSiren

Google CVE debriefs · Page 26

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Google CVE published 2026-06-05

CVE-2026-11258

CVE-2026-11258 is a vulnerability in Google Chrome prior to version 149.0.7827.53. The issue is related to an inappropriate implementation in File System Access, which could allow a remote attacker to bypass discretionary access control by convincing a user to engage in specific UI gestures via a crafted HTML page. The Chromium security severity of this vulnerability is rated as Low, with a CVSS score of [truncated]

MEDIUM Google CVE published 2026-06-05

CVE-2026-11257

A vulnerability was discovered in Google Chrome prior to version 149.0.7827.53. The issue is related to an inappropriate implementation in the Browser component, which could allow a remote attacker to bypass navigation restrictions via a crafted HTML page. The Chromium security severity of this issue is rated as Low.

HIGH Google CVE published 2026-06-05

CVE-2026-11256

CVE-2026-11256 is an integer overflow vulnerability in the GPU of Google Chrome. This issue, which was reported with a CVSS score of 8.3 and categorized as HIGH severity, could allow a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The vulnerability was addressed in Google Chrome version 149.0.7827.53.

HIGH Google CVE published 2026-06-05

CVE-2026-11255

CVE-2026-11255 is a vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by insufficient validation of untrusted input in the Storage Access API. This allows a remote attacker who has compromised the renderer process to leak cross-origin data via a crafted HTML page. The Chromium security severity of this vulnerability is rated as Low.

MEDIUM Google CVE published 2026-06-05

CVE-2026-11254

CVE-2026-11254 is a MEDIUM severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by an inappropriate implementation in Permissions, which allows a remote attacker to perform UI spoofing via a crafted HTML page. The CVSS score for this vulnerability is 4.3.

MEDIUM Google CVE published 2026-06-05

CVE-2026-11253

A vulnerability was discovered in Google Chrome prior to version 149.0.7827.53, related to an inappropriate implementation in Permissions. This vulnerability, tracked as CVE-2026-11253, could allow a remote attacker to leak cross-origin data via a crafted HTML page. The Chromium security severity of this issue is rated as Low, and it has a CVSS score of 4.3, indicating a Medium severity level.

MEDIUM Google CVE published 2026-06-05

CVE-2026-11252

CVE-2026-11252 is a vulnerability in Google Chrome prior to version 149.0.7827.53. The issue is related to insufficient policy enforcement in Content Settings, which could allow a remote attacker to bypass discretionary access control via a crafted HTML page. The Chromium security severity of this vulnerability is rated as Low, and the CVSS score is 4.3, which is considered Medium severity.

LOW Google CVE published 2026-06-05

CVE-2026-11251

CVE-2026-11251 is a vulnerability in Google Chrome prior to version 149.0.7827.53. The issue is related to insufficient policy enforcement in Password Manager, which allowed a remote attacker who had compromised the renderer process to bypass discretionary access control via a crafted HTML page. The Chromium security severity of this vulnerability is rated as Low.

CRITICAL Google CVE published 2026-06-05

CVE-2026-11250

CVE-2026-11250 is a critical vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by an inappropriate implementation in DevTools, which allows a remote attacker who has compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. The Chromium security severity of this vulnerability is rated as Low, but the C [truncated]

MEDIUM Google CVE published 2026-06-05

CVE-2026-11249

CVE-2026-11249 is a use-after-free vulnerability in the Network component of Google Chrome prior to version 149.0.7827.53. This vulnerability could allow a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. The CVSS score for this vulnerability is 4.7, with a severity rating of MEDIUM.

HIGH Google CVE published 2026-06-05

CVE-2026-11248

A vulnerability was discovered in Google Chrome prior to version 149.0.7827.53. The issue is related to an inappropriate implementation in Google Lens, which could allow a remote attacker to bypass navigation restrictions via a crafted HTML page. The Chromium security severity of this issue is rated as Low.

MEDIUM Google CVE published 2026-06-05

CVE-2026-11246

CVE-2026-11246 is a vulnerability in Google Chrome prior to version 149.0.7827.53. The issue is related to insufficient validation of untrusted input in IndexedDB, which could allow a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. The Chromium security severity of this vulnerability is rated as Low, and it has a CVSS score of 5.3, categorized [truncated]

MEDIUM Google CVE published 2026-06-05

CVE-2026-11245

CVE-2026-11245 is a MEDIUM severity vulnerability in Google Chrome's Payments feature. It was published on 2026-06-05T00:17:00.857Z and last modified on 2026-06-05T20:40:42.617Z. The vulnerability allows a remote attacker to perform UI spoofing via a crafted HTML page. The CVSS score is 4.3.

LOW Google CVE published 2026-06-05

CVE-2026-11244

CVE-2026-11244 is a Low severity vulnerability in Google Chrome prior to 149.0.7827.53. This issue involves Insufficient validation of untrusted input in WebAuthentication, which could allow a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. The vulnerability has a CVSS score of 3.1 and is classified as Low in severity.

MEDIUM Google CVE published 2026-06-05

CVE-2026-11243

CVE-2026-11243 is a MEDIUM severity vulnerability in Google Chrome prior to 149.0.7827.53. This vulnerability, described as an inappropriate implementation in Downloads, allows a remote attacker to bypass navigation restrictions via a crafted HTML page. The CVSS score for this vulnerability is 5.4.

HIGH Google CVE published 2026-06-05

CVE-2026-11242

CVE-2026-11242 is a vulnerability in Google Chrome prior to version 149.0.7827.53. The issue is related to insufficient validation of untrusted input in Plugins, which allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. This vulnerability has been classified as having a high severity with a CVSS score of 7.5.

HIGH Google CVE published 2026-06-05

CVE-2026-11241

CVE-2026-11241 is a vulnerability in Google Chrome's Cast feature, which allowed an attacker on the local network segment to perform privilege escalation via a crafted HTML page. The vulnerability was reported with a CVSS score of 8 and a severity of HIGH.

LOW Google CVE published 2026-06-05

CVE-2026-11240

CVE-2026-11240 is a vulnerability in Google Chrome prior to version 149.0.7827.53. The issue is related to insufficient validation of untrusted input in the Loader component. This vulnerability allowed a remote attacker, who had compromised the renderer process, to bypass site isolation via a crafted HTML page. The Chromium security severity of this issue is rated as Low. The CVSS score for this vulnerabi [truncated]

HIGH Google CVE published 2026-06-05

CVE-2026-11239

CVE-2026-11239 is a vulnerability in Google Chrome prior to version 149.0.7827.53. The issue is related to an inappropriate implementation in Extensions, which could allow a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. The Chromium security severity of this issue is rated as Low. The CVSS score for this vulnerability is 7.5, and the CVSS [truncated]

MEDIUM Google CVE published 2026-06-05

CVE-2026-11238

CVE-2026-11238 is a MEDIUM severity vulnerability in Google Chrome prior to 149.0.7827.53. The vulnerability is caused by an inappropriate implementation in DevTools, which allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. The CVSS score for this vulnerability is 5.9. The vulnerability w [truncated]

HIGH Google CVE published 2026-06-04

CVE-2026-11237

CVE-2026-11237 is a vulnerability in Google Chrome prior to 149.0.7827.53. The vulnerability is caused by insufficient validation of untrusted input in Media, allowing a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. The Chromium security severity is rated as Low, but the CVSS score is 8.3, indicating a HIGH severity. The vulnerability was publishe [truncated]

HIGH Google CVE published 2026-06-04

CVE-2026-11236

CVE-2026-11236 is a vulnerability in Google Chrome prior to version 149.0.7827.53. The issue is related to insufficient policy enforcement in Web Bluetooth, which could allow a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The Chromium security severity of this issue is rated as Low. The CVSS score for this vulnerability is 8.3, i [truncated]

HIGH Google CVE published 2026-06-04

CVE-2026-11235

CVE-2026-11235 is a vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is related to insufficient policy enforcement in Compositing, which allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. The CVSS score for this vulnerability is 8.8, indicating a high severity. The vulnerability was publishe [truncated]

MEDIUM Google CVE published 2026-06-04

CVE-2026-11234

CVE-2026-11234 is a MEDIUM severity vulnerability in Google Chrome prior to version 149.0.7827.53. This issue is related to an inappropriate implementation in FoldableAPIs, which allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. The CVSS score for this vulnerability is 4.3.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11233

CVE-2026-11233 is a vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by insufficient policy enforcement in FoldableAPIs, which allows a remote attacker who has compromised the renderer process to bypass same origin policy via a crafted HTML page. The Chromium security severity of this vulnerability is Low, and the CVSS score is 4.7, which is classified as MEDIUM.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11232

A vulnerability was discovered in Google Chrome prior to version 149.0.7827.53. The issue is related to an inappropriate implementation in TabGroups, which could allow a remote attacker to perform UI spoofing via malicious network traffic. The Chromium security severity of this vulnerability is rated as Low, with a CVSS score of 5.4 and a CVSS severity of MEDIUM.

HIGH Google CVE published 2026-06-04

CVE-2026-11231

CVE-2026-11231 is a HIGH severity vulnerability in Google Chrome on Mac, with a CVSS score of 8.1. The vulnerability is caused by an inappropriate implementation in Safe Browsing, allowing remote attackers to execute arbitrary code via a malicious file. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].

HIGH Google CVE published 2026-06-04

CVE-2026-11230

CVE-2026-11230 is a Use after free vulnerability in Extensions in Google Chrome prior to 149.0.7827.53. This vulnerability allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The Chromium security severity is rated as Low.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11229

CVE-2026-11229 is a MEDIUM severity vulnerability in Google Chrome prior to 149.0.7827.53. The issue is an inappropriate implementation in the Enterprise version of Google Chrome, which allows a local attacker to perform privilege escalation via physical access to the device. The vulnerability has a CVSS score of 6.1 and a CVSS severity of MEDIUM. It was published on [cvePublishedAt] and modified on [cveModifiedAt].

MEDIUM Google CVE published 2026-06-04

CVE-2026-11228

CVE-2026-11228 is a MEDIUM severity vulnerability in Google Chrome prior to 149.0.7827.53. The vulnerability is caused by an inappropriate implementation in File Input, allowing a remote attacker who convinces a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. The CVSS score for this vulnerability is 4.3.