PatchSiren

Google CVE debriefs · Page 33

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11036

CVE-2026-11036 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. This vulnerability is related to an inappropriate implementation in the Document Object Model (DOM). A remote attacker could exploit this vulnerability by creating a crafted HTML page, potentially bypassing the same origin policy. The CVSS score for this vulnerability is 6.5, indicating a Medium severity lev [truncated]

HIGH Google CVE published 2026-06-04

CVE-2026-11035

CVE-2026-11035 is a Medium severity vulnerability in Google Chrome's Custom Tabs on Android, allowing local attackers to escalate privileges via a crafted XML file. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].

MEDIUM Google CVE published 2026-06-04

CVE-2026-11034

CVE-2026-11034 is a Medium severity vulnerability in Google Chrome on Android prior to 149.0.7827.53. The vulnerability is caused by insufficient validation of untrusted input in Tab Group Sync, allowing a remote attacker to inject arbitrary scripts or HTML (UXSS) via malicious network traffic. The CVSS score for this vulnerability is 6.1.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11033

CVE-2026-11033 is a Medium severity vulnerability in Google Chrome on Mac prior to 149.0.7827.53. This issue involves an uninitialized use in WebML, which could allow a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. The vulnerability has a CVSS score of 6.5 and is classified as CWE-457.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11032

CVE-2026-11032 is a medium-severity vulnerability in Google Chrome prior to 149.0.7827.53. This vulnerability is related to an inappropriate implementation in the Password Manager. A remote attacker can exploit this vulnerability by creating a crafted HTML page, which can lead to the leakage of cross-origin data. The CVSS score for this vulnerability is 6.5, indicating a medium level of severity.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11031

CVE-2026-11031 is a Medium severity vulnerability in Google Chrome prior to 149.0.7827.53. The vulnerability is caused by insufficient validation of untrusted input in Password Manager, allowing a remote attacker to perform UI spoofing via malicious network traffic. The CVSS score for this vulnerability is 4.3.

HIGH Google CVE published 2026-06-04

CVE-2026-11030

CVE-2026-11030 is a Use after free vulnerability in Network in Google Chrome prior to 149.0.7827.53. This vulnerability, with a CVSS score of 8.8, could allow a remote attacker to potentially exploit heap corruption via malicious network traffic. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].

HIGH Google CVE published 2026-06-04

CVE-2026-11028

CVE-2026-11028 is a use-after-free vulnerability in the Media component of Google Chrome on Linux and ChromeOS prior to 149.0.7827.53. This vulnerability allows a remote attacker who has compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. The CVSS score for this vulnerability is 8.8, indicating a high severity level.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11027

CVE-2026-11027 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. The issue is caused by insufficient validation of untrusted input in Glic, which allows a remote attacker who has compromised the renderer process to leak cross-origin data via a crafted HTML page.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11026

CVE-2026-11026 is a medium-severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by an inappropriate implementation in Extensions, which allows an attacker who convinces a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. The CVSS score for this vulnerability is 6.5, indicating a medium severity level.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11025

CVE-2026-11025 is a Medium severity vulnerability in Google Chrome on Android prior to 149.0.7827.53. This vulnerability is caused by insufficient policy enforcement in Navigation, allowing a remote attacker to bypass content security policy via a crafted HTML page. The CVSS score for this vulnerability is 6.5.

HIGH Google CVE published 2026-06-04

CVE-2026-11024

CVE-2026-11024 is a stack buffer overflow vulnerability in Skia, a graphics library used in Google Chrome. This vulnerability could allow a remote attacker to potentially exploit stack corruption via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11023

CVE-2026-11023 is a medium-severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by an inappropriate implementation in WebAppInstalls, which allows a remote attacker who has compromised the renderer process to bypass same origin policy via a crafted HTML page. The CVSS score for this vulnerability is 6.5, indicating a medium severity level.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11022

CVE-2026-11022 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. The issue involves insufficient validation of untrusted input in DevTools, allowing a remote attacker who has compromised the renderer process to bypass same origin policy via a crafted HTML page.

CRITICAL Google CVE published 2026-06-04

CVE-2026-11021

CVE-2026-11021 is a critical vulnerability in Google Chrome on Windows, allowing a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability has a CVSS score of 9.6 and is classified as CRITICAL.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11020

CVE-2026-11020 is a Medium severity vulnerability in Google Chrome prior to 149.0.7827.53. This vulnerability is caused by an inappropriate implementation in Extensions, which allowed a remote attacker to leak cross-origin data via a crafted XML file. The vulnerability has a CVSS score of 6.5 and is classified as CWE-346 and CWE-352.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11019

A medium-severity vulnerability, CVE-2026-11019, was found in Google Chrome on Android prior to version 149.0.7827.53. This issue is related to an inappropriate implementation in the Payments feature, which could allow a remote attacker who has compromised the renderer process to perform domain spoofing via a crafted HTML page. The CVSS score for this vulnerability is 6.5, indicating a medium level of severity.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11018

CVE-2026-11018 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by insufficient policy enforcement in Actor, allowing a remote attacker to bypass navigation restrictions via a crafted HTML page. The CVSS score for this vulnerability is 6.5.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11017

A medium-severity vulnerability, CVE-2026-11017, was found in Google Chrome prior to version 149.0.7827.53. This issue is related to an inappropriate implementation in Link Preview, which could allow a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11016

CVE-2026-11016 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. The issue involves insufficient validation of untrusted input in the Network component, allowing a remote attacker who has compromised the renderer process to bypass the same-origin policy via a crafted HTML page. The CVSS score for this vulnerability is 6.5.

HIGH Google CVE published 2026-06-04

CVE-2026-11015

CVE-2026-11015 is an out-of-bounds read vulnerability in WebGPU in Google Chrome prior to version 149.0.7827.53. This vulnerability allowed a remote attacker to perform an out-of-bounds memory read via a crafted HTML page. The Chromium security severity of this vulnerability is rated as Medium, with a CVSS score of 8.1, indicating a High severity level.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11013

CVE-2026-11013 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by insufficient validation of untrusted input in the Network component, allowing a remote attacker who has compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page.

HIGH Google CVE published 2026-06-04

CVE-2026-11012

CVE-2026-11012 is a use-after-free vulnerability in the Serial component of Google Chrome on Android. The vulnerability occurs when the browser's rendering process is compromised, allowing a remote attacker to potentially escape the sandbox via a crafted HTML page. The CVSS score for this vulnerability is 8.3, indicating a high severity level.

HIGH Google CVE published 2026-06-04

CVE-2026-11011

CVE-2026-11011 is a vulnerability in Google Chrome prior to version 149.0.7827.53. The issue is related to insufficient policy enforcement in Password Manager, which allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. This vulnerability has a CVSS score of 8.1 and is considered HIGH severity.

HIGH Google CVE published 2026-06-04

CVE-2026-11010

CVE-2026-11010 is a use-after-free vulnerability in WebShare in Google Chrome on Android prior to 149.0.7827.53. This vulnerability allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The CVSS score for this vulnerability is 8.3, indicating a high severity. The vulnerability was published on [cve-org](https://www.cve.org/CVERe [truncated]

CRITICAL Google CVE published 2026-06-04

CVE-2026-11009

CVE-2026-11009 is a use after free vulnerability in USB in Google Chrome on Windows. The vulnerability, which has a CVSS score of 9.6 and a severity of CRITICAL, allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability was reported on June 4, 2026, and the Chrome browser was updated to version 149.0.7827.53 to address the issue.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11008

CVE-2026-11008 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by insufficient validation of untrusted input in WebAppInstalls, which allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11007

CVE-2026-11007 is a Medium severity vulnerability in Google Chrome on Android. Insufficient validation of untrusted input in WebView allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11006

CVE-2026-11006 is an out of bounds read vulnerability in Dawn in Google Chrome prior to 149.0.7827.53. A remote attacker could exploit this vulnerability to perform an out of bounds memory read via a crafted HTML page. The vulnerability has a CVSS score of 6.5 and is classified as Medium severity.

MEDIUM Google CVE published 2026-06-04

CVE-2026-11005

CVE-2026-11005 is a vulnerability in Google Chrome on Windows, specifically in the ANGLE (Almost Native Graphics Layer Engine) component. The vulnerability allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. The vulnerability has a CVSS score of 5.3 and is classified as Medium severity.