PatchSiren

Google CVE debriefs · Page 30

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11132

CVE-2026-11132 is a Medium severity vulnerability in Google Chrome's Paint component. It was published on 2026-06-04 and modified on 2026-06-08. The vulnerability allowed a remote attacker to bypass same origin policy via a crafted HTML page. The CVSS score is 6.5.

CRITICAL Google CVE published 2026-06-04

CVE-2026-11131

CVE-2026-11131 is a critical vulnerability in Google Chrome on Android prior to version 149.0.7827.53. The vulnerability is caused by a use-after-free issue in the Autofill feature. A remote attacker who has compromised the renderer process can potentially perform a sandbox escape via a crafted HTML page. The Chromium security severity of this vulnerability is Medium, but the CVSS score is 9.6, indicating [truncated]

HIGH Google CVE published 2026-06-04

CVE-2026-11130

CVE-2026-11130 is a Use after free vulnerability in Media in Google Chrome prior to 149.0.7827.53. This vulnerability allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The CVSS score for this vulnerability is 8.8, indicating a HIGH severity. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].

MEDIUM Google CVE published 2026-06-04

CVE-2026-11129

CVE-2026-11129 is a Medium severity vulnerability in Google Chrome prior to 149.0.7827.53. This vulnerability is caused by an inappropriate implementation in Extensions, allowing a remote attacker to leak cross-origin data via a crafted HTML page. The CVSS score for this vulnerability is 6.5.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11128

CVE-2026-11128 is a Medium severity vulnerability in Google Chrome's Web Share feature. It was published on 2026-06-04 and modified on 2026-06-09. The vulnerability allowed a remote attacker to leak cross-origin data via a crafted HTML page if a user was convinced to engage in specific UI gestures. The CVSS score is 6.5. The vendor listed is Apple, but the actual affected product is Google Chrome. The vul [truncated]

MEDIUM Google CVE published 2026-06-04

CVE-2026-11127

A Medium severity vulnerability, CVE-2026-11127, was found in Google Chrome on Android prior to version 149.0.7827.53. This issue is related to an inappropriate implementation in WebAPKs, which could allow a remote attacker to perform domain spoofing via a crafted WebAPK. The CVSS score for this vulnerability is 6.5, indicating a Medium severity level.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11126

CVE-2026-11126 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by an inappropriate implementation in DevTools, which allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. The CVSS score for this vulnerability is 4.3.

HIGH Google CVE published 2026-06-04

CVE-2026-11125

CVE-2026-11125 is a Use after free vulnerability in Compositing in Google Chrome prior to 149.0.7827.53. This vulnerability allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The CVSS score for this vulnerability is 8.8, indicating a HIGH severity. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].

HIGH Google CVE published 2026-06-04

CVE-2026-11124

CVE-2026-11124 is an integer overflow vulnerability in Skia, a graphics library used in Google Chrome. This vulnerability could allow a remote attacker to cause heap corruption via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11123

CVE-2026-11123 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by an uninitialized use in ANGLE, which could allow a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. The CVSS score for this vulnerability is 6.5.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11122

CVE-2026-11122 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. This issue is related to an inappropriate implementation in the Keyboard component, which could allow a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. The vulnerability has a CVSS score of 6.1.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11121

CVE-2026-11121 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. The issue is caused by insufficient validation of untrusted input in Skia, which allows a remote attacker who has compromised the renderer process to leak cross-origin data via a crafted HTML page. The CVSS score for this vulnerability is 6.5.

CRITICAL Google CVE published 2026-06-04

CVE-2026-11120

A critical vulnerability, CVE-2026-11120, was found in Google Chrome's Enterprise Reporting feature. This issue, caused by insufficient validation of untrusted input, allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability had a CVSS score of 9.6, indicating a high severity level. Google has addressed this issue in Chrome version 149.0.7827.53 and later.

CRITICAL Google CVE published 2026-06-04

CVE-2026-11119

A critical vulnerability, CVE-2026-11119, was discovered in Google Chrome for Android prior to version 149.0.7827.53. This vulnerability, rated with a CVSS score of 9.6, involves an inappropriate implementation in the GPU, allowing a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The Chromium security severity is classified as Medium.

HIGH Google CVE published 2026-06-04

CVE-2026-11118

CVE-2026-11118 is a use-after-free vulnerability in WebRTC in Google Chrome prior to 149.0.7827.53. This vulnerability allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The CVSS score for this vulnerability is 8.8, indicating a high severity. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].

HIGH Google CVE published 2026-06-04

CVE-2026-11117

CVE-2026-11117 is a use-after-free vulnerability in Google Chrome on Windows prior to version 149.0.7827.53. This vulnerability allowed a remote attacker to run arbitrary code via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity.

HIGH Google CVE published 2026-06-04

CVE-2026-11116

CVE-2026-11116 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by a use after free in Chromoting, which allows a remote attacker to execute arbitrary code via malicious network traffic. The CVSS score for this vulnerability is 8.8, indicating a high severity. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].

HIGH Google CVE published 2026-06-04

CVE-2026-11115

CVE-2026-11115 is a high-severity vulnerability in Google Chrome on Windows, with a CVSS score of 7.3. The vulnerability is caused by a use-after-free issue in the Updater component, which can be exploited by a local attacker to perform OS-level privilege escalation via a malicious file. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].

CRITICAL Google CVE published 2026-06-04

CVE-2026-11114

CVE-2026-11114 is a use-after-free vulnerability in Device Trust in Google Chrome on Mac prior to version 149.0.7827.53. This vulnerability, with a CVSS score of 9.6, could allow a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The vulnerability was published on [cve-org](https://www.cve.org/CVERecord?id=CVE-2026-11114) and detaile [truncated]

CRITICAL Google CVE published 2026-06-04

CVE-2026-11113

CVE-2026-11113 is a critical vulnerability in Google Chrome prior to version 149.0.7827.53. The issue is caused by insufficient validation of untrusted input in ANGLE, which allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. This vulnerability has a CVSS score of 9.6 and is classified as CRITICAL.

CRITICAL Google CVE published 2026-06-04

CVE-2026-11112

CVE-2026-11112 is a critical vulnerability in Google Chrome on Linux. Insufficient validation of untrusted input in Chromoting allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted Chrome Extension. This vulnerability has a CVSS score of 9.6 and a severity of CRITICAL.

HIGH Google CVE published 2026-06-04

CVE-2026-11111

CVE-2026-11111 is an out of bounds read vulnerability in ANGLE in Google Chrome prior to 149.0.7827.53. A remote attacker could exploit this vulnerability to perform an out of bounds memory read via a crafted HTML page. The vulnerability has a CVSS score of 8.1 and is classified as HIGH severity.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11110

CVE-2026-11110 is a Medium severity vulnerability in Google Chrome prior to 149.0.7827.53. This issue involves an uninitialized use in ANGLE, which could allow a remote attacker to leak cross-origin data via a crafted HTML page. The vulnerability has a CVSS score of 6.5 and is categorized as CWE-457.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11109

CVE-2026-11109 is a Medium severity vulnerability in Google Chrome prior to 149.0.7827.53. This issue, described as an uninitialized use in ANGLE, allows a remote attacker to leak cross-origin data via a crafted HTML page. The vulnerability has a CVSS score of 6.5 and is categorized as CWE-457.

HIGH Google CVE published 2026-06-04

CVE-2026-11108

A remote attacker can exploit CVE-2026-11108, a Medium-severity inappropriate implementation issue in NFC in Google Chrome on Android versions prior to 149.0.7827.53. This vulnerability enables the attacker to perform privilege escalation via a crafted HTML page. The CVSS score for this vulnerability is 8.8, indicating a HIGH severity level.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11107

CVE-2026-11107 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. This issue, categorized under CWE-451, involves an inappropriate implementation in the Downloads feature, enabling remote attackers to perform UI spoofing via a crafted HTML page. The vulnerability has a CVSS score of 4.3 and is considered a Medium threat.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11106

A vulnerability in Google Chrome, tracked as CVE-2026-11106, was publicly disclosed on June 4, 2026. The issue is related to an inappropriate implementation in the Media component of Google Chrome, which could allow a remote attacker to leak cross-origin data via a crafted HTML page. This vulnerability was rated as Medium severity by the Chromium security team, with a CVSS score of 6.5.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11105

CVE-2026-11105 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. The issue involves insufficient validation of untrusted input in WebUI, allowing a remote attacker who has compromised the renderer process to leak cross-origin data via a crafted HTML page. The vulnerability has a CVSS score of 6.5.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11104

CVE-2026-11104 is a Medium severity vulnerability in Google Chrome prior to 149.0.7827.53. The vulnerability is caused by an uninitialized use in ANGLE, which allows a remote attacker who has compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. The CVSS score for this vulnerability is 6.5.

HIGH Google CVE published 2026-06-04

CVE-2026-11103

A local attacker can exploit CVE-2026-11103, a Medium-severity privilege escalation vulnerability in Google Chrome's Installer on Windows, by creating a malicious file. This issue was addressed in Chrome version 149.0.7827.53.