PatchSiren

Google CVE debriefs · Page 32

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Google CVE published 2026-06-04

CVE-2026-11068

CVE-2026-11068 is a use-after-free vulnerability in WebSockets in Google Chrome prior to 149.0.7827.53. This vulnerability allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11067

CVE-2026-11067 is a vulnerability in Google Chrome prior to 149.0.7827.53. This issue, categorized as an Uninitialized Use in Dawn, allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. The Chromium security severity of this vulnerability is rated as Medium, with a CVSS score of 6.5.

CRITICAL Google CVE published 2026-06-04

CVE-2026-11066

CVE-2026-11066 is a critical vulnerability in Google Chrome prior to version 149.0.7827.53. The issue is caused by insufficient validation of untrusted input in ANGLE, which could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability has a CVSS score of 9.6 and is classified as CRITICAL.

CRITICAL Google CVE published 2026-06-04

CVE-2026-11065

CVE-2026-11065 is a use-after-free vulnerability in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome. This vulnerability, with a CVSS score of 9.6, was reported as having a medium severity by the Chromium security team. The vulnerability allows a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. Google Chrome versions [truncated]

MEDIUM Google CVE published 2026-06-04

CVE-2026-11064

CVE-2026-11064 is a Medium severity vulnerability in Google Chrome on Android prior to 149.0.7827.53. This vulnerability is caused by a race condition in the GPU, which could allow a remote attacker who has compromised the renderer process to leak cross-origin data via a crafted HTML page. The Chromium security severity of this vulnerability is Medium, with a CVSS score of 6.5.

CRITICAL Google CVE published 2026-06-04

CVE-2026-11063

CVE-2026-11063 is a critical vulnerability in Google Chrome on Windows, allowing a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability has a CVSS score of 9.6 and is classified as CRITICAL. It was published on 2026-06-04T23:17:10.793Z and modified on 2026-06-08T14:51:57.013Z.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11062

CVE-2026-11062 is a Medium severity vulnerability in Google Chrome prior to 149.0.7827.53. The vulnerability is caused by insufficient policy enforcement in Extensions, allowing an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. The CVSS score for this vulnerability is 4.3.

CRITICAL Google CVE published 2026-06-04

CVE-2026-11061

A critical vulnerability, CVE-2026-11061, was discovered in Google Chrome prior to version 149.0.7827.53. This vulnerability is caused by a type confusion in ANGLE, which could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The Chromium security severity of this vulnerability is rated as Medium, but the CVSS score is 9.6, indicating a Critical severity.

HIGH Google CVE published 2026-06-04

CVE-2026-11060

CVE-2026-11060 is a Use after free vulnerability in Media in Google Chrome on Windows prior to 149.0.7827.53. This vulnerability allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The CVSS score for this vulnerability is 8.8, indicating a HIGH severity. The vulnerability was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-11060) and modifi [truncated]

HIGH Google CVE published 2026-06-04

CVE-2026-11059

CVE-2026-11059 is a Use after free vulnerability in Blink in Google Chrome prior to 149.0.7827.53. This vulnerability allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The CVSS score for this vulnerability is 8.8, indicating a HIGH severity. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].

HIGH Google CVE published 2026-06-04

CVE-2026-11058

CVE-2026-11058 is an integer overflow vulnerability in CredentialProvider in Google Chrome on Windows prior to 149.0.7827.53. This vulnerability allowed a remote attacker who had compromised the renderer process to perform OS-level privilege escalation via a crafted HTML page. The CVSS score for this vulnerability is 7.5, with a severity rating of HIGH.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11057

CVE-2026-11057 is a vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by an uninitialized use in Skia, which allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. The Chromium security severity of this vulnerability is Medium, with a CVSS score of 6.5.

HIGH Google CVE published 2026-06-04

CVE-2026-11055

CVE-2026-11055 is a use-after-free vulnerability in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome on Windows systems. This vulnerability, which was reported with a CVSS score of 8.8 and classified as HIGH severity, could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability was addressed in Google Chrome version 149.0.7827.53.

HIGH Google CVE published 2026-06-04

CVE-2026-11054

CVE-2026-11054 is a use-after-free vulnerability in WebRTC in Google Chrome prior to 149.0.7827.53. This vulnerability allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The CVSS score for this vulnerability is 8.8, indicating a high severity. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].

CRITICAL Google CVE published 2026-06-04

CVE-2026-11052

CVE-2026-11052 is a critical vulnerability in Google Chrome on Windows, with a CVSS score of 9.6. The vulnerability is caused by a type confusion in the GPU, which allows a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. This vulnerability was published on June 4, 2026, and modified on June 8, 2026.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11051

CVE-2026-11051 is an out of bounds read vulnerability in ANGLE in Google Chrome on Linux prior to 149.0.7827.53. A remote attacker could exploit this via a crafted HTML page to obtain potentially sensitive information from process memory. The vulnerability has a CVSS score of 6.5 and is classified as Medium severity.

HIGH Google CVE published 2026-06-04

CVE-2026-11050

CVE-2026-11050 is a use after free vulnerability in V8 in Google Chrome prior to 149.0.7827.53. This vulnerability allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The Chromium security severity is rated as Medium, with a CVSS score of 8.8, indicating a HIGH severity. The CVE was published on [cvePublishedAt]2026-06-04T23:17:09.460Z[/cvePublishedAt] and modifie [truncated]

HIGH Google CVE published 2026-06-04

CVE-2026-11049

CVE-2026-11049 is a use-after-free vulnerability in Google Chrome's Password Manager. This vulnerability, which was published on [cvePublishedAt], allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity. Google Chrome versions prior to 149.0.7827.53 are affected by this vulnerability.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11048

CVE-2026-11048 is a medium-severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by an inappropriate implementation in Extensions, which allows an attacker who convinces a user to install a malicious extension to bypass same-origin policy via a crafted Chrome Extension. The CVSS score for this vulnerability is 6.5, indicating a medium severity. The vulnerabili [truncated]

CRITICAL Google CVE published 2026-06-04

CVE-2026-11047

A critical vulnerability, CVE-2026-11047, was discovered in Google Chrome on Windows. This issue, rated as Medium by Chromium but scoring a 9.6 CVSS score, could allow a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

HIGH Google CVE published 2026-06-04

CVE-2026-11046

CVE-2026-11046 is a vulnerability in Google Chrome prior to version 149.0.7827.53. The issue is related to insufficient validation of untrusted input in the Media component. This vulnerability allowed a remote attacker, who had compromised the renderer process, to execute arbitrary code inside a sandbox via a crafted HTML page. The Chromium security severity of this issue is Medium, and it has a CVSS scor [truncated]

MEDIUM Google CVE published 2026-06-04

CVE-2026-11045

CVE-2026-11045 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by insufficient validation of untrusted input in the GPU, allowing a remote attacker who has compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11044

CVE-2026-11044 is a medium-severity vulnerability in Google Chrome on Mac. An integer overflow in ANGLE allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. The vulnerability was reported on 2026-06-04T23:17:08.780Z and updated on 2026-06-08T15:01:32.437Z. The CVSS score is 6.5.

CRITICAL Google CVE published 2026-06-04

CVE-2026-11043

CVE-2026-11043 is a critical vulnerability in Google Chrome on Mac, with a CVSS score of 9.6. The vulnerability is an out-of-bounds write in ANGLE, which could allow a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The vulnerability was published on June 4, 2026, and modified on June 8, 2026.

HIGH Google CVE published 2026-06-04

CVE-2026-11042

CVE-2026-11042 is a use-after-free vulnerability in the Views component of Google Chrome prior to version 149.0.7827.53. This vulnerability could be exploited by a remote attacker who convinces a user to engage in specific UI gestures, potentially leading to heap corruption via a crafted HTML page. The Chromium security team classified this issue as Medium severity.

HIGH Google CVE published 2026-06-04

CVE-2026-11041

CVE-2026-11041 is a vulnerability in Google Chrome on Windows, where insufficient validation of untrusted input in Media allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity.

HIGH Google CVE published 2026-06-04

CVE-2026-11040

CVE-2026-11040 is a use-after-free vulnerability in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome. This vulnerability was reported with a CVSS score of 8.3, indicating a high severity level. The vulnerability existed prior to Google Chrome version 149.0.7827.53 and could potentially allow a remote attacker, who had compromised the renderer process, to perform a sandbox escape via a craf [truncated]

MEDIUM Google CVE published 2026-06-04

CVE-2026-11039

CVE-2026-11039 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by an uninitialized use in Skia, which allows a remote attacker to leak cross-origin data via a crafted HTML page. The CVSS score for this vulnerability is 6.5.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11038

CVE-2026-11038 is a Medium-severity vulnerability affecting Google Chrome versions prior to 149.0.7827.53. It involves Insufficient policy enforcement in Subresource Integrity, allowing a remote attacker to bypass content security policy via malicious network traffic.

CRITICAL Google CVE published 2026-06-04

CVE-2026-11037

CVE-2026-11037 is an out of bounds write vulnerability in Codecs in Google Chrome prior to 149.0.7827.53. A remote attacker could potentially perform a sandbox escape via a crafted video file. The vulnerability has a CVSS score of 9.6 and is considered CRITICAL.