PatchSiren

Google CVE debriefs · Page 28

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11194

A vulnerability was discovered in Google Chrome prior to version 149.0.7827.53. The issue is related to an inappropriate implementation in the Network component, which could allow a remote attacker to leak cross-origin data via a crafted HTML page. The vulnerability has been assigned a CVSS score of 6.5 and is classified as Medium severity.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11193

CVE-2026-11193 is a Medium severity vulnerability in Google Chrome's Password Manager, which allowed a remote attacker to bypass discretionary access control via a crafted HTML page. The vulnerability was published on 2026-06-04 and modified on 2026-06-09.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11192

CVE-2026-11192 is a Medium severity vulnerability in Google Chrome prior to 149.0.7827.53. The vulnerability is caused by insufficient validation of untrusted input in Password Manager, allowing a remote attacker to perform UI spoofing via malicious network traffic. The CVSS score for this vulnerability is 4.3.

HIGH Google CVE published 2026-06-04

CVE-2026-11191

CVE-2026-11191 is a vulnerability in ANGLE in Google Chrome prior to 149.0.7827.53. This issue allows a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and is classified as HIGH severity. It was published on [cvePublishedAt] and modified on [cveModifiedAt].

MEDIUM Google CVE published 2026-06-04

CVE-2026-11190

CVE-2026-11190 is a Medium severity vulnerability in Google Chrome prior to 149.0.7827.53. The vulnerability is caused by an inappropriate implementation in Extensions, which allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted Chrome Extension. The CVSS score for this vulnerability is 6.5.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11189

CVE-2026-11189 is a Medium severity vulnerability in Google Chrome prior to 149.0.7827.53. The vulnerability is caused by insufficient validation of untrusted input in DevTools, allowing an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. The CVSS score for this vulnerability is 6.5.

HIGH Google CVE published 2026-06-04

CVE-2026-11188

CVE-2026-11188 is a use-after-free vulnerability in the USB component of Google Chrome on Android. The vulnerability occurs when the browser attempts to access memory that has already been freed, which can lead to a sandbox escape. An attacker could exploit this vulnerability by crafting a malicious HTML page. The Chromium security team classified this vulnerability as Medium severity. The CVSS score for [truncated]

MEDIUM Google CVE published 2026-06-04

CVE-2026-11187

CVE-2026-11187 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by an inappropriate implementation in Glic, which allows a remote attacker to bypass navigation restrictions via a crafted HTML page. The CVSS score for this vulnerability is 6.3.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11186

A Medium severity vulnerability, CVE-2026-11186, was found in Google Chrome prior to version 149.0.7827.53. This issue is related to an inappropriate implementation in CSS, which could allow a remote attacker to inject arbitrary scripts or HTML, leading to a User Interaction Security Spoofing (UXSS) vulnerability.

HIGH Google CVE published 2026-06-04

CVE-2026-11185

CVE-2026-11185 is a use-after-free vulnerability in V8 in Google Chrome prior to 149.0.7827.53. An attacker could exploit this vulnerability to execute arbitrary code inside a sandbox via a crafted Chrome Extension if they convinced a user to install the extension. The vulnerability has a CVSS score of 8.1 and is considered HIGH severity.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11184

A vulnerability in Google Chrome, tracked as CVE-2026-11184, allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. This issue was due to insufficient policy enforcement in the Actor component. The vulnerability has a CVSS score of 6.3, indicating a medium severity level.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11183

CVE-2026-11183 is a vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is an out-of-bounds read in GWP-ASan, which could allow a local attacker to obtain potentially sensitive information from process memory via a malicious file. The Chromium security severity of this vulnerability is Medium, with a CVSS score of 6.5.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11182

CVE-2026-11182 is a medium-severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by an inappropriate implementation in SVG, which allows a remote attacker to leak cross-origin data via a crafted HTML page. The CVSS score for this vulnerability is 6.5, indicating a medium level of severity.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11181

CVE-2026-11181 is a medium-severity vulnerability in Google Chrome prior to version 149.0.7827.53. This issue is related to an inappropriate implementation in Media Session, which could allow a remote attacker to bypass same origin policy via a crafted HTML page. The vulnerability has a CVSS score of 6.3 and is classified as CWE-346.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11180

CVE-2026-11180 is a medium-severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by an inappropriate implementation in SVG, which allows a remote attacker to leak cross-origin data via a crafted HTML page. The CVSS score for this vulnerability is 6.5, indicating a medium level of severity.

HIGH Google CVE published 2026-06-04

CVE-2026-11179

CVE-2026-11179 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by an inappropriate implementation in ORB, which allows remote attackers to bypass site isolation via a crafted HTML page. The CVSS score for this vulnerability is 8.8, indicating a HIGH severity. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].

HIGH Google CVE published 2026-06-04

CVE-2026-11177

CVE-2026-11177 is a Use after free vulnerability in Omnibox in Google Chrome prior to 149.0.7827.53. A remote attacker could exploit heap corruption via a crafted HTML page by convincing a user to engage in specific UI gestures. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11176

CVE-2026-11176 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by an inappropriate implementation in the Media component, which allows a remote attacker to leak cross-origin data via a crafted HTML page. The Chromium security severity of this vulnerability is Medium, with a CVSS score of 6.5.

HIGH Google CVE published 2026-06-04

CVE-2026-11175

CVE-2026-11175 is a vulnerability in Google Chrome on Android, specifically affecting the Messages feature. The issue is related to incorrect security UI, which could allow a remote attacker to perform UI spoofing via a crafted HTML page. This vulnerability was reported with a CVSS score of 8.8, indicating a high severity level.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11174

CVE-2026-11174 is a medium-severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by an inappropriate implementation in Site Isolation, which allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. The CVSS score for this vulnerability is 5.3, indicating a medium severity level.

HIGH Google CVE published 2026-06-04

CVE-2026-11173

CVE-2026-11173 is an out of bounds write vulnerability in V8 in Google Chrome prior to 149.0.7827.53. This vulnerability allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. The CVSS score for this vulnerability is 8.8, indicating a high severity. The vulnerability was published on [cve-org](https://www.cve.org/CVERecord?id= [truncated]

HIGH Google CVE published 2026-06-04

CVE-2026-11172

CVE-2026-11172 is a vulnerability in Google Chrome on Android, specifically affecting the Contact Picker feature. The vulnerability, with a CVSS score of 8.8, allowed a remote attacker to perform UI spoofing via a crafted HTML page. This issue was addressed in Google Chrome version 149.0.7827.53.

HIGH Google CVE published 2026-06-04

CVE-2026-11171

CVE-2026-11171 is an integer overflow vulnerability in Blink in Google Chrome prior to 149.0.7827.53. This vulnerability allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The Chromium security severity of this vulnerability is Medium, and it has a CVSS score of 8.8, indicating a HIGH severity level. The CVE was published on [cvePublishedAt]2026-06-04T23:17:23.84 [truncated]

HIGH Google CVE published 2026-06-04

CVE-2026-11170

A vulnerability was discovered in Google Chrome's Chromoting feature on Linux systems, which could allow a remote attacker to perform OS-level privilege escalation via malicious network traffic. This issue was addressed in Google Chrome version 149.0.7827.53.

HIGH Google CVE published 2026-06-04

CVE-2026-11169

A vulnerability in Google Chrome, tracked as CVE-2026-11169, was publicly disclosed on 2026-06-04. This issue is related to an inappropriate implementation in XML, which could allow a remote attacker to inject arbitrary scripts or HTML, potentially leading to UXSS (Universal Cross-Site Scripting). The vulnerability has been categorized as Medium severity by the Chromium security team and has a CVSS score [truncated]

MEDIUM Google CVE published 2026-06-04

CVE-2026-11168

CVE-2026-11168 is a Medium severity vulnerability in Google Chrome prior to 149.0.7827.53. This issue is related to an inappropriate implementation in Extensions, which could allow a remote attacker who has compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. The Chromium security severity for this issue is Medium, with a CVSS score of 6.5.

CRITICAL Google CVE published 2026-06-04

CVE-2026-11167

CVE-2026-11167 is a critical vulnerability in Google Chrome on Android prior to 149.0.7827.53. The vulnerability is caused by an inappropriate implementation in WebView, which could allow a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The Chromium security severity is rated as Medium, but the CVSS score is 9.6, indicating a Criti [truncated]

MEDIUM Google CVE published 2026-06-04

CVE-2026-11166

CVE-2026-11166 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. This issue is related to an inappropriate implementation in SVG, which could allow a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. The vulnerability has a CVSS score of 6.8 and is classified as UXSS (Universal Cross-Site Scripting).

CRITICAL Google CVE published 2026-06-04

CVE-2026-11165

CVE-2026-11165 is a use-after-free vulnerability in WebMIDI in Google Chrome on iOS prior to version 149.0.7827.53. This vulnerability, with a CVSS score of 9.6, could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability was published on [cve-org](https://www.cve.org/CVERecord?id=CVE-2026-11165) and detailed further on [nvd](https://nvd.nist.gov/vuln/d [truncated]

HIGH Google CVE published 2026-06-04

CVE-2026-11164

CVE-2026-11164 is a use-after-free vulnerability in Blink in Google Chrome prior to 149.0.7827.53. This vulnerability allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The CVSS score for this vulnerability is 8.8, indicating a high severity. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].