PatchSiren

Google CVE debriefs · Page 31

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Google CVE published 2026-06-04

CVE-2026-11102

A Medium severity vulnerability was discovered in Google Chrome's Isolated Web Apps feature. This vulnerability, tracked as CVE-2026-11102, could allow a remote attacker to execute arbitrary code inside a sandbox via a malicious file. The vulnerability was addressed in Google Chrome version 149.0.7827.53.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11101

CVE-2026-11101 is a Medium severity vulnerability in Google Chrome on Windows, caused by an uninitialized use in Dawn. This vulnerability allows a remote attacker to leak cross-origin data via a crafted HTML page. The vulnerability has a CVSS score of 6.5 and was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-11101).

CRITICAL Google CVE published 2026-06-04

CVE-2026-11100

CVE-2026-11100 is a use-after-free vulnerability in the File Input component of Google Chrome on Mac systems. This vulnerability, with a CVSS score of 9.6, could allow a remote attacker to potentially escape the sandbox by convincing a user to engage in specific UI gestures via a crafted HTML page. The vulnerability was first published on [cve-org](https://www.cve.org/CVERecord?id=CVE-2026-11100) on 2026- [truncated]

MEDIUM Google CVE published 2026-06-04

CVE-2026-11098

CVE-2026-11098 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. The issue involves insufficient validation of untrusted input in the GPU, allowing a remote attacker who has compromised the renderer process to leak cross-origin data via a crafted HTML page.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11097

A medium-severity vulnerability, CVE-2026-11097, was found in Google Chrome's WebView on Android. This issue, caused by an inappropriate implementation, allows remote attackers to leak cross-origin data via a crafted HTML page. The vulnerability has a CVSS score of 6.5 and was published on 2026-06-04.

CRITICAL Google CVE published 2026-06-04

CVE-2026-11095

CVE-2026-11095 is a critical vulnerability in Google Chrome prior to version 149.0.7827.53. The issue involves insufficient validation of untrusted input in Codecs, allowing a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. This vulnerability has a CVSS score of 9.6, indicating a high severity level.

CRITICAL Google CVE published 2026-06-04

CVE-2026-11094

CVE-2026-11094 is a Use after free vulnerability in Codecs in Google Chrome on Windows prior to 149.0.7827.53. This vulnerability, with a CVSS score of 9.6, could allow a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].

MEDIUM Google CVE published 2026-06-04

CVE-2026-11093

CVE-2026-11093 is a Medium severity vulnerability in Google Chrome prior to 149.0.7827.53. This issue is related to an inappropriate implementation in Printing, which could allow a remote attacker who has compromised the renderer process to leak cross-origin data via a crafted HTML page. The CVSS score for this vulnerability is 6.5.

HIGH Google CVE published 2026-06-04

CVE-2026-11091

A vulnerability was discovered in Google Chrome prior to version 149.0.7827.53, specifically in the Dawn implementation. This vulnerability, tracked as CVE-2026-11091, allows a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. The Chromium security severity of this issue is classified as Medium, with a CVSS score of 8.8, indicating a HIGH severity level.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11090

CVE-2026-11090 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by an uninitialized use in ANGLE, which allows a remote attacker to leak cross-origin data via a crafted HTML page. The CVSS score for this vulnerability is 6.5.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11089

CVE-2026-11089 is a Medium severity vulnerability in Google Chrome prior to 149.0.7827.53. This issue involves an uninitialized use in the Media component, which could allow a remote attacker who has compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. The vulnerability has a CVSS score of 6.5 and is categorized under CWE-457 and CWE-908.

CRITICAL Google CVE published 2026-06-04

CVE-2026-11088

CVE-2026-11088 is a critical vulnerability in Google Chrome, specifically in the ANGLE (Almost Native Graphics Layer Engine) component. The vulnerability is caused by an integer overflow, which can be exploited by a remote attacker who has compromised the renderer process. This could potentially allow the attacker to perform a sandbox escape via a crafted HTML page. The vulnerability has a CVSS score of 9 [truncated]

MEDIUM Google CVE published 2026-06-04

CVE-2026-11087

CVE-2026-11087 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by an uninitialized use in ANGLE, which allows a remote attacker who has compromised the renderer process to leak cross-origin data via a crafted HTML page. The CVSS score for this vulnerability is 6.5.

HIGH Google CVE published 2026-06-04

CVE-2026-11086

A vulnerability was discovered in Google Chrome, specifically in the Dawn component. This issue is classified as an inappropriate implementation, which could allow a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability has been assigned a CVSS score of 8.8, indicating a high severity level.

HIGH Google CVE published 2026-06-04

CVE-2026-11085

CVE-2026-11085 is an integer overflow vulnerability in the GPU of Google Chrome on Android versions prior to 149.0.7827.53. This vulnerability, with a CVSS score of 8.8, could allow a remote attacker to potentially perform out-of-bounds memory access via a crafted HTML page. The vulnerability is considered to have a High severity rating by the CVSS scoring system.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11084

A medium severity vulnerability, CVE-2026-11084, was found in Google Chrome's Password Manager. This issue, caused by an inappropriate implementation, allows remote attackers to leak cross-origin data via crafted HTML pages. The vulnerability has a CVSS score of 6.5 and was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-11084).

MEDIUM Google CVE published 2026-06-04

CVE-2026-11083

A medium severity vulnerability, CVE-2026-11083, was found in Google Chrome's Password Manager. This issue, caused by an inappropriate implementation, allows remote attackers to leak cross-origin data via crafted HTML pages. The vulnerability has a CVSS score of 6.5 and was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-11083).

CRITICAL Google CVE published 2026-06-04

CVE-2026-11082

A race condition vulnerability was discovered in the GPU component of Google Chrome on Android prior to version 149.0.7827.53. This vulnerability, tracked as CVE-2026-11082, could allow a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The Chromium security team classified this issue as Medium severity.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11081

CVE-2026-11081 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. This vulnerability is related to an inappropriate implementation in Canvas, which allowed a remote attacker to bypass same origin policy via a crafted HTML page. The CVSS score for this vulnerability is 6.5, indicating a Medium severity level.

HIGH Google CVE published 2026-06-04

CVE-2026-11080

CVE-2026-11080 is a use-after-free vulnerability in WebView in Google Chrome on Android prior to 149.0.7827.53. This vulnerability, with a CVSS score of 8.8, could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page.

HIGH Google CVE published 2026-06-04

CVE-2026-11079

CVE-2026-11079 is a vulnerability in Google Chrome prior to version 149.0.7827.53. The issue is caused by insufficient validation of untrusted input in Codecs, allowing a remote attacker to perform an out-of-bounds memory write via a crafted video file. The vulnerability has a CVSS score of 8.8 and is classified as HIGH severity.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11078

CVE-2026-11078 is a medium-severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by an inappropriate implementation in FileSystem, which allows a remote attacker who has compromised the renderer process to bypass same origin policy via a crafted HTML page. The CVSS score for this vulnerability is 6.5, indicating a medium severity level.

HIGH Google CVE published 2026-06-04

CVE-2026-11077

CVE-2026-11077 is a vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by a bad cast in Dawn, which allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The Chromium security severity of this vulnerability is Medium, but it has a high CVSS score of 8.8.

HIGH Google CVE published 2026-06-04

CVE-2026-11076

A Type Confusion in CSS vulnerability was discovered in Google Chrome prior to 149.0.7827.53. This HIGH-severity vulnerability, with a CVSS score of 8.8, allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability was publicly disclosed on 2026-06-04 and last modified on 2026-06-06.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11075

CVE-2026-11075 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is an out-of-bounds read in V8, which could allow a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

HIGH Google CVE published 2026-06-04

CVE-2026-11074

CVE-2026-11074 is a use-after-free vulnerability in WebRTC in Google Chrome on Linux, prior to version 149.0.7827.53. This vulnerability, with a CVSS score of 8.8, could allow a remote attacker to execute arbitrary code via a crafted HTML page. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].

MEDIUM Google CVE published 2026-06-04

CVE-2026-11073

CVE-2026-11073 is a use-after-free vulnerability in WebGL in Google Chrome prior to 149.0.7827.53. This vulnerability allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. Google Chrome has released a patch for this vulnerability.

HIGH Google CVE published 2026-06-04

CVE-2026-11072

CVE-2026-11072 is a use-after-free vulnerability in WebView in Google Chrome on Android prior to 149.0.7827.53. This vulnerability allowed a local attacker to execute arbitrary code via a malicious file. The Chromium security severity is rated as Medium, with a CVSS score of 7.8, and CVSS severity of HIGH.

CRITICAL Google CVE published 2026-06-04

CVE-2026-11070

CVE-2026-11070 is a critical vulnerability in Google Chrome on Windows, with a CVSS score of 9.6. The vulnerability is caused by insufficient validation of untrusted input in Chromoting, which allows a remote attacker who has compromised the network process to potentially perform a sandbox escape via malicious network traffic. This vulnerability was publicly disclosed on 2026-06-04 and last modified on 2026-06-08.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11069

CVE-2026-11069 is a Medium severity vulnerability in Google Chrome's Cast feature. It was published on 2026-06-04 and modified on 2026-06-08. The vulnerability allowed a remote attacker to bypass same origin policy via a crafted HTML page.