These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-11227 is a MEDIUM severity vulnerability in Google Chrome prior to version 149.0.7827.53. This vulnerability, described as 'Incorrect security UI in Tab Hover Cards,' allows a remote attacker to perform domain spoofing via a crafted domain name. The Chromium security severity is rated as Low, with a CVSS score of 6.5.
CVE-2026-11226 is a vulnerability in Google Chrome on Android prior to 149.0.7827.53. This issue involves Insufficient policy enforcement in PreviewTab, which could allow a remote attacker to bypass same origin policy via a crafted HTML page. The vulnerability has a CVSS score of 6.5 and is classified as MEDIUM severity. It was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-11226) [truncated]
CVE-2026-11225 is a MEDIUM severity vulnerability in Google Chrome prior to 149.0.7827.53. This issue is caused by an inappropriate implementation in WebUI, allowing a remote attacker to perform domain spoofing via a crafted domain name. The Chromium security severity is rated as Low. The CVSS score is 6.5.
CVE-2026-11223 is a vulnerability in Google Chrome prior to version 149.0.7827.53. The issue is related to insufficient validation of untrusted input in the Network component, which could allow a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. The vulnerability has a CVSS score of 6.5 and is classified as Medium severity.
CVE-2026-11221 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by insufficient validation of untrusted input in PointerLock, which could allow a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. The CVSS score for this vulnerability is 4.3.
CVE-2026-11220 is a vulnerability in Google Chrome prior to version 149.0.7827.53. The issue is related to Insufficient validation of untrusted input in Navigation, which could allow a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. The Chromium security severity of this vulnerability is rated as Low. The CVSS score is 6.5, with a severity rating of MEDIUM.
A MEDIUM severity vulnerability, CVE-2026-11219, was found in Google Chrome prior to version 149.0.7827.53. This issue is related to an inappropriate implementation in the Navigation component, which could allow a remote attacker to bypass navigation restrictions via a crafted HTML page. The CVSS score for this vulnerability is 4.3.
CVE-2026-11218 is a Medium severity vulnerability in Google Chrome on Windows. It was published on 2026-06-04 and modified on 2026-06-05. The vulnerability is caused by an inappropriate implementation in PlatformIntegration, which allowed a remote attacker to execute arbitrary code via a malicious file if the user was convinced to engage in specific UI gestures.
CVE-2026-11216 is a MEDIUM severity vulnerability in Google Chrome prior to 149.0.7827.53. The vulnerability is caused by an incorrect security UI in File Input, allowing a remote attacker who convinces a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. The Chromium security severity is rated as Low.
A medium-severity vulnerability, CVE-2026-11215, was found in Google Chrome's Cronet implementation on Android. This issue, published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-11215), allowed remote attackers to perform domain spoofing via crafted domain names. Users should update Chrome to version 149.0.7827.53 or later to mitigate this risk.
A medium-severity vulnerability was discovered in Google Chrome for iOS, tracked as CVE-2026-11214. This issue, caused by an inappropriate implementation, allowed a remote attacker to leak cross-origin data via a crafted HTML page. Users of Google Chrome on iOS are advised to update to version 149.0.7827.53 or later to mitigate this vulnerability.
CVE-2026-11213 is a critical vulnerability in Google Chrome prior to version 149.0.7827.53. The issue is related to insufficient validation of untrusted input in Reading Mode, which allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. This vulnerability has a CVSS score of 9.6 and is classified as CRITICAL.
CVE-2026-11212 is a Medium-severity vulnerability in Google Chrome's DevTools, which allowed an attacker to leak cross-origin data via a crafted Chrome Extension. The vulnerability was patched in Chrome version 149.0.7827.53.
CVE-2026-11211 is an integer overflow vulnerability in the V8 engine of Google Chrome, which could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity.
CVE-2026-11210 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. The issue lies in the inappropriate implementation in Safe Browsing, which allowed a remote attacker to bypass discretionary access control via a crafted RAR file. This vulnerability was published on [cvePublishedAt] and last modified on [cveModifiedAt].
CVE-2026-11209 is a Medium severity vulnerability in Google Chrome's Passwords implementation. A remote attacker who had compromised the renderer process could obtain potentially sensitive information from process memory via a crafted HTML page. The vulnerability was published on 2026-06-04 and modified on 2026-06-06.
CVE-2026-11208 is a Medium severity vulnerability in Google Chrome prior to 149.0.7827.53. This use after free vulnerability in Codecs allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. The vulnerability has a CVSS score of 6.5 and is classified as CWE-416.
CVE-2026-11207 is a critical vulnerability in Google Chrome prior to version 149.0.7827.53. The issue is related to insufficient validation of untrusted input in Autofill, which could allow a remote attacker to potentially perform a sandbox escape via malicious network traffic. The vulnerability has a CVSS score of 9.6 and is classified as CRITICAL.
CVE-2026-11206 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by insufficient policy enforcement in ServiceWorker, which allows a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2026-11205 is a Medium-severity vulnerability in Google Chrome on iOS. Insufficient validation of untrusted input allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted QR code if a user was convinced to engage in specific UI gestures.
A Medium severity vulnerability, CVE-2026-11204, was found in Google Chrome's Signin feature on iOS. This issue, caused by an inappropriate implementation, allows remote attackers to bypass navigation restrictions via a crafted HTML page. The vulnerability has a CVSS score of 6.5.
A medium-severity vulnerability, CVE-2026-11203, was discovered in Google Chrome on Mac. This issue is related to an inappropriate implementation in the GPU, which could allow a remote attacker to leak cross-origin data via a crafted HTML page. The vulnerability has a CVSS score of 6.5.
A remote attacker can potentially perform a sandbox escape via a crafted HTML page due to inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53.
CVE-2026-11201 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.53. This use-after-free issue in ServiceWorker could allow an attacker who convinces a user to install a malicious extension to execute arbitrary code. The vulnerability has a CVSS score of 8.8 and is classified as CWE-416.
CVE-2026-11200 is a medium-severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by an inappropriate implementation in WebRTC, which allows a remote attacker to leak cross-origin data via a crafted HTML page. The CVSS score for this vulnerability is 6.5, indicating a medium severity level.
CVE-2026-11199 is a Medium severity vulnerability in Google Chrome prior to 149.0.7827.53. The vulnerability is caused by an inappropriate implementation in WebRTC, which allows an attacker in a privileged network position to leak cross-origin data via malicious network traffic. The CVSS score for this vulnerability is 5.9.
CVE-2026-11198 is a critical vulnerability in Google Chrome prior to version 149.0.7827.53. The issue is caused by insufficient validation of untrusted input in Codecs, which could allow a remote attacker to potentially perform a sandbox escape via a crafted video file. The vulnerability has a CVSS score of 9.6 and is classified as CRITICAL.
A Medium severity vulnerability was discovered in Google Chrome prior to version 149.0.7827.53. The issue is related to insufficient policy enforcement in Workers, which could allow a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page.
A Type Confusion in XML vulnerability was discovered in Google Chrome prior to version 149.0.7827.53. This vulnerability, tracked as CVE-2026-11196, could allow a remote attacker to obtain potentially sensitive information from process memory via a crafted XML file. The Chromium security team classified this issue as Medium severity.
A medium severity vulnerability, CVE-2026-11195, was found in Google Chrome's MHTML implementation prior to version 149.0.7827.53. This issue allowed a remote attacker to leak cross-origin data by convincing a user to engage in specific UI gestures via a crafted HTML page.