These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-11164 is a use-after-free vulnerability in Blink in Google Chrome prior to 149.0.7827.53. This vulnerability allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The CVSS score for this vulnerability is 8.8, indicating a high severity. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].
CVE-2026-11163 is a use-after-free vulnerability in the Messages feature of Google Chrome on Android versions prior to 149.0.7827.53. The vulnerability is rated as Critical with a CVSS score of 9.6. According to the Chromium security severity classification, it is considered Medium severity. A remote attacker could potentially exploit this vulnerability by crafting an HTML page, which might enable them to [truncated]
A medium-severity vulnerability, CVE-2026-11162, was found in Google Chrome prior to version 149.0.7827.53. This issue is related to an inappropriate implementation in CSS, which could allow a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2026-11161 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by an inappropriate implementation in DataTransfer, which allowed a remote attacker to leak cross-origin data via a crafted HTML page. The CVSS score for this vulnerability is 4.3.
CVE-2026-11160 is an out of bounds read vulnerability in Google Chrome on Linux prior to 149.0.7827.53. A remote attacker could exploit this vulnerability to obtain potentially sensitive information from process memory via a crafted HTML page. The vulnerability has a CVSS score of 6.5 and is classified as Medium severity.
CVE-2026-11159 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by an uninitialized use in Skia, which allows a remote attacker to leak cross-origin data via a crafted HTML page. The CVSS score for this vulnerability is 4.3.
CVE-2026-11158 is a vulnerability in Google Chrome on Mac, where insufficient validation of untrusted input in Downloads allowed a local attacker to potentially perform a sandbox escape via a crafted AppleScript command. This vulnerability has a CVSS score of 8.6 and is classified as HIGH severity.
CVE-2026-11157 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is related to script injection in Accessibility and allows an attacker who has convinced a user to install a malicious extension to inject arbitrary scripts or HTML (UXSS) via a crafted Chrome Extension.
A vulnerability was discovered in Google Chrome prior to version 149.0.7827.53. The issue is related to an inappropriate implementation in CSS, which could allow a remote attacker to leak cross-origin data via a crafted HTML page. The Chromium security severity of this vulnerability is rated as Medium with a CVSS score of 4.3.
A medium-severity vulnerability, CVE-2026-11155, was found in Google Chrome prior to version 149.0.7827.53. This issue is related to an inappropriate implementation in CSS, which could allow a remote attacker to leak cross-origin data via a crafted HTML page.
A critical vulnerability, CVE-2026-11153, was discovered in Google Chrome, allowing remote attackers to leak cross-origin data via a crafted HTML page. This side-channel information leakage in Forms was patched in version 149.0.7827.53.
CVE-2026-11152 is an object lifecycle issue in Dawn in Google Chrome prior to 149.0.7827.53. This vulnerability allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The Chromium security severity is rated as Medium, but the CVSS score is 9.6, indicating a Critical severity. The CVE was published on 2026-06-04T23:17:21.610Z and modified on 2026-06-08T14:56:28.213Z.
CVE-2026-11151 is a vulnerability in Google Chrome's Password Manager, prior to version 149.0.7827.53, that allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page if they had compromised the renderer process. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity.
A vulnerability was discovered in Google Chrome prior to version 149.0.7827.53. The issue is related to an inappropriate implementation in XML, which could allow a remote attacker to inject arbitrary scripts or HTML, leading to a User Interaction Cross-Site Scripting (UXSS) attack. The vulnerability has been categorized as Medium severity by the Chromium security team.
CVE-2026-11149 is a vulnerability in Google Chrome prior to version 149.0.7827.53. The issue is related to insufficient validation of untrusted input in Extensions, which allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. This vulnerability has a CVSS score of 7.5 and is classified as HIGH severity.
CVE-2026-11148 is a medium-severity vulnerability in Google Chrome on Android prior to 149.0.7827.53. The vulnerability is caused by an inappropriate implementation in Payments, allowing a local attacker to leak cross-origin data via a crafted HTML page. The CVSS score for this vulnerability is 6.5.
CVE-2026-11147 is a use-after-free vulnerability in WebML in Google Chrome on Windows prior to 149.0.7827.53. This vulnerability allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The CVSS score for this vulnerability is 8.8, indicating a high severity. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].
CVE-2026-11146 is a critical vulnerability in Google Chrome prior to version 149.0.7827.53. The issue is related to insufficient validation of untrusted input in Chromoting, which allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. This vulnerability has a CVSS score of 9.6 and is classified as CRITICAL.
A Medium severity vulnerability, CVE-2026-11145, was found in Google Chrome on Android prior to version 149.0.7827.53. This vulnerability involves a race condition in the Geolocation feature. A remote attacker could exploit this vulnerability by creating a crafted HTML page, potentially leading to the leakage of cross-origin data. The Chromium security team has assessed this vulnerability as Medium severity.
CVE-2026-11144 is a Use after free vulnerability in Media in Google Chrome prior to 149.0.7827.53. This vulnerability allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. The Chromium security severity is rated as Medium, with a CVSS score of 8.8, indicating a HIGH severity level.
CVE-2026-11143 is an out of bounds read vulnerability in Extensions in Google Chrome on Linux prior to 149.0.7827.53. An attacker could exploit this by getting a user to install a malicious extension, potentially allowing access to sensitive information from process memory.
CVE-2026-11142 is a Medium severity vulnerability in Google Chrome's Paint component. It was published on 2026-06-04 and modified on 2026-06-08. The vulnerability allowed a remote attacker to bypass same origin policy via a crafted HTML page. The CVSS score is 6.5.
CVE-2026-11140 is an out of bounds read vulnerability in Chromecast in Google Chrome prior to 149.0.7827.53. A remote attacker who had compromised the renderer process could obtain potentially sensitive information from process memory via a crafted HTML page. The vulnerability has a CVSS score of 6.5 and is classified as Medium severity.
CVE-2026-11139 is a medium-severity vulnerability in Google Chrome's Paint implementation. The vulnerability allowed a remote attacker to leak cross-origin data via a crafted HTML page. The issue was patched in Google Chrome version 149.0.7827.53.
CVE-2026-11138 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by an uninitialized use in ANGLE, which allows a remote attacker to leak cross-origin data via a crafted HTML page. The CVSS score for this vulnerability is 6.5.
CVE-2026-11137 is a vulnerability in Google Chrome prior to 149.0.7827.53. The vulnerability is caused by an uninitialized use in ANGLE, which allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. The Chromium security severity of this vulnerability is Medium, with a CVSS score of 6.5.
CVE-2026-11136 is a use-after-free vulnerability in Canvas in Google Chrome prior to 149.0.7827.53. This vulnerability allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The CVSS score for this vulnerability is 8.8, indicating a high severity. The vulnerability was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-11136) and modified on [cve [truncated]
CVE-2026-11135 is a Medium severity vulnerability in Google Chrome's Autofill feature. It was published on 2026-06-04 and modified on 2026-06-08. The vulnerability allowed a remote attacker to bypass discretionary access control via a crafted HTML page. The CVSS score is 6.5.
CVE-2026-11134 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by an inappropriate implementation in the Media component, which allows a remote attacker to leak cross-origin data via a crafted HTML page. The CVSS score for this vulnerability is 6.5.
CVE-2026-11133 is a Medium severity vulnerability in Google Chrome's Paint component. It was published on 2026-06-04 and modified on 2026-06-08. The vulnerability allowed a remote attacker to bypass same origin policy via a crafted HTML page. The CVSS score is 6.5.