These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-11004 is an out of bounds read vulnerability in ANGLE in Google Chrome prior to 149.0.7827.53. A remote attacker who had compromised the renderer process could obtain potentially sensitive information from process memory via a crafted HTML page. The CVSS score for this vulnerability is 5.3, indicating a medium severity.
CVE-2026-11003 is a use-after-free vulnerability in WebRTC in Google Chrome prior to 149.0.7827.53. This vulnerability allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The CVSS score for this vulnerability is 8.8, indicating a high severity.
CVE-2026-11002 is a use-after-free vulnerability in the Autofill feature of Google Chrome. This vulnerability, which has a CVSS score of 9.6 and is classified as CRITICAL, could allow a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The vulnerability was published on [cvePublishedAt] and last modified on [cveModifiedAt].
CVE-2026-11001 is a medium-severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by an inappropriate implementation in Payments, allowing remote attackers who convince a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. The CVSS score for this vulnerability is 6.5, indicating a medium severity level.
CVE-2026-11000 is a use-after-free vulnerability in the Fonts component of Google Chrome on Linux, prior to version 149.0.7827.53. This vulnerability allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and is classified as HIGH severity.
CVE-2026-10999 is an integer overflow vulnerability in ANGLE in Google Chrome on Windows prior to 149.0.7827.53. This vulnerability allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. The CVSS score for this vulnerability is 6.5, indicating a medium severity. The vulnerability was published on [cvePubli [truncated]
CVE-2026-10998 is an out of bounds read vulnerability in Media in Google Chrome prior to 149.0.7827.53. An attacker on the local network segment could perform an out of bounds memory read via malicious network traffic. The vulnerability has a CVSS score of 4 and a severity of MEDIUM. Google Chrome versions prior to 149.0.7827.53 are affected.
CVE-2026-10997 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by insufficient policy enforcement in Extensions, which allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted Chrome Extension. The Chromium security severity is Medium, with a CVSS score of 6.5.
CVE-2026-10996 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by an inappropriate implementation in Workers, which allowed a remote attacker to bypass same origin policy via a crafted HTML page. The CVSS score for this vulnerability is 6.5.
CVE-2026-10995 is a heap buffer overflow vulnerability in the TabStrip component of Google Chrome. The vulnerability occurs when a remote attacker convinces a user to engage in specific UI gestures, potentially leading to heap corruption via a crafted HTML page. This issue was reported with a CVSS score of 8.8 and a severity of HIGH.
CVE-2026-10994 is a vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by an uninitialized use in ANGLE, which allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. The Chromium security severity of this vulnerability is Medium, with a CVSS score of 6.5.
CVE-2026-10993 is a Medium severity vulnerability in Google Chrome, specifically a heap buffer overflow in the Skia library. This issue was addressed in Chrome version 149.0.7827.53.
CVE-2026-10992 is a vulnerability in Google Chrome prior to version 149.0.7827.53. The issue is related to insufficient data validation in the Animation component, which could allow a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. This vulnerability has been classified as Medium severity by Chromium, with a CVSS score of 6.5.
CVE-2026-10991 is a use-after-free vulnerability in V8 in Google Chrome prior to 149.0.7827.53. A remote attacker could convince a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity.
CVE-2026-10990 is a use-after-free vulnerability in the Glic component of Google Chrome prior to version 149.0.7827.53. This vulnerability, with a CVSS score of 9.6, could allow a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].
A High-severity vulnerability, CVE-2026-10989, was found in Google Chrome's V8 engine. This issue, caused by an inappropriate implementation, could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page if a user is convinced to engage in specific UI gestures. The vulnerability was patched in Chrome version 149.0.7827.53.
CVE-2026-10988 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is a use-after-free issue in the Views component, which could allow a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The CVSS score for this vulnerability is 8.8, indicating a high level of severity.
CVE-2026-10987 is an integer overflow vulnerability in the V8 engine of Google Chrome. This issue, which was reported with a CVSS score of 8.8 and categorized as High severity by Chromium, could allow a remote attacker to execute arbitrary code within a sandbox environment by providing a specially crafted HTML page. The vulnerability was made public on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE [truncated]
CVE-2026-10986 is an integer overflow vulnerability in the Media component of Google Chrome. This issue was exploitable by a remote attacker, allowing them to execute arbitrary code within a sandbox environment via a malicious file. The vulnerability was addressed in Google Chrome version 149.0.7827.53.
CVE-2026-10985 is a vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is an out-of-bounds read in Skia, which could allow a remote attacker to leak cross-origin data via a crafted HTML page. The CVSS score for this vulnerability is 6.5, with a severity rating of MEDIUM.
CVE-2026-10984 is a High-severity vulnerability in Google Chrome on Android prior to 149.0.7827.53. This issue is related to an inappropriate implementation in Accessibility, which could allow a remote attacker to perform UI spoofing via a crafted HTML page. The CVSS score for this vulnerability is 5.4, categorized as MEDIUM severity.
CVE-2026-10983 is a critical vulnerability in Google Chrome prior to version 149.0.7827.53. The issue lies in the insufficient validation of untrusted input in Dawn, a component of Google Chrome. This vulnerability, with a CVSS score of 9.6, could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The Chromium security severity is rated as High.
CVE-2026-10982 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.53. This use-after-free issue in WebXR allows remote attackers to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and is considered High severity by Chromium security.
CVE-2026-10981 is a High-severity vulnerability in Google Chrome prior to version 149.0.7827.53. The issue involves insufficient validation of untrusted input in Codecs, allowing a remote attacker who has compromised the renderer process to leak cross-origin data via a crafted video file.
CVE-2026-10980 is a vulnerability in Google Chrome prior to version 149.0.7827.53. The issue is related to insufficient validation of untrusted input in DevTools, which allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. This vulnerability has a CVSS score of 6.5 and is classified as MEDIUM severity.
CVE-2026-10979 is an out of bounds read vulnerability in ANGLE in Google Chrome prior to 149.0.7827.53. A remote attacker could exploit this vulnerability to obtain potentially sensitive information from process memory via a crafted HTML page. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM.
CVE-2026-10978 is a high-severity vulnerability in Google Chrome on Windows, caused by a use-after-free issue in Chromoting. This vulnerability, with a CVSS score of 8.8, allows remote attackers to execute arbitrary code via malicious network traffic. The issue was addressed in Google Chrome version 149.0.7827.53.
CVE-2026-10977 is a High-severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by an uninitialized use in Skia, which allows a remote attacker who has compromised the renderer process to leak cross-origin data via a crafted HTML page. The CVSS score for this vulnerability is 6.5, with a severity rating of MEDIUM.
CVE-2026-10976 is a High severity vulnerability in Google Chrome prior to 149.0.7827.53. This issue, described as an 'Uninitialized Use in Dawn,' allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. The vulnerability has a CVSS score of 7.4 and is considered High severity.
CVE-2026-10975 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.53. This use-after-free issue in WebRTC could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and is considered High severity by Chromium.