These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A critical vulnerability, CVE-2026-10974, was found in Google Chrome prior to version 149.0.7827.53. This issue is related to insufficient validation of untrusted input in ANGLE, which could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability has a CVSS score of 9.6 and is considered CRITICAL.
CVE-2026-10973 is a High severity vulnerability in Google Chrome prior to 149.0.7827.53. This issue, described as an uninitialized use in Dawn, allows a remote attacker to leak cross-origin data via a crafted HTML page. The vulnerability has a CVSS score of 7.4 and is categorized as High severity. It was published on [cvePublishedAt] and last modified on [cveModifiedAt].
CVE-2026-10972 is a critical vulnerability in Google Chrome on Linux, caused by a use-after-free issue in the Ozone component. This vulnerability, with a CVSS score of 9.6, could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability was published on June 4, 2026, and modified on June 8, 2026.
CVE-2026-10971 is a critical vulnerability in Google Chrome on Windows, with a CVSS score of 9.6. The issue is caused by insufficient validation of untrusted input in the Printing feature, which allows a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVE-2026-10970 is a High-severity vulnerability in Google Chrome prior to version 149.0.7827.53. The issue involves insufficient validation of untrusted input in InterestGroups, which could allow a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVE-2026-10969 is a High-severity vulnerability in Google Chrome prior to version 149.0.7827.53. The issue involves insufficient validation of untrusted input in Extensions, which could allow a remote attacker who has compromised the renderer process to perform privilege escalation via a crafted HTML page.
CVE-2026-10968 is a High-severity vulnerability in Google Chrome on Windows. Insufficient validation of untrusted input in Dawn allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.
CVE-2026-10967 is a high-severity vulnerability in Google Chrome on Android prior to version 149.0.7827.53. The vulnerability is a use-after-free issue in the SurfaceCapture component, which could allow a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The CVSS score for this vulnerability is 8.3, indicating a high level of severity.
A critical vulnerability, CVE-2026-10966, was discovered in Google Chrome prior to version 149.0.7827.53. This vulnerability is caused by an inappropriate implementation in Codecs, which could allow a remote attacker to potentially perform a sandbox escape via a crafted video file. The Chromium security severity of this vulnerability is rated as High, with a CVSS score of 9.6.
CVE-2026-10965 is an integer overflow vulnerability in DevTools in Google Chrome prior to 149.0.7827.53. A remote attacker can exploit this vulnerability to run arbitrary code inside a sandbox via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and is considered High severity by Chromium.
CVE-2026-10964 is an integer overflow vulnerability in V8 in Google Chrome prior to 149.0.7827.53. This vulnerability allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The Chromium security severity of this vulnerability is High, with a CVSS score of 8.8. The CVE was published on 2026-06-04T23:16:59.503Z and modified on 2026-06-05T15:33:50.163Z.
CVE-2026-10963 is an integer overflow vulnerability in V8 in Google Chrome prior to 149.0.7827.53. This vulnerability allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The Chromium security severity of this vulnerability is High, with a CVSS score of 8.8.
A Type Confusion vulnerability in Media in Google Chrome prior to 149.0.7827.53 was reported. This vulnerability, with a CVSS score of 8.8, could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
CVE-2026-10961 is a high-severity vulnerability in Google Chrome for iOS prior to version 149.0.7827.53. This use-after-free issue allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The vulnerability has a CVSS score of 8.3 and is classified as High by Chromium security severity.
CVE-2026-10960 is a High severity vulnerability in Google Chrome prior to 149.0.7827.53. This issue involves an uninitialized use in the Codecs component, which could enable a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The vulnerability has been assigned a CVSS score of 8.3, indicating a High severity level.
CVE-2026-10959 is a high-severity vulnerability in Google Chrome on Android prior to version 149.0.7827.53. The vulnerability is caused by a use-after-free issue in the Input component, which can be exploited by a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The CVSS score for this vulnerability is 8.8, indicating a high level of severity.
CVE-2026-10958 is a high-severity vulnerability in Google Chrome for iOS prior to version 149.0.7827.53. This use-after-free vulnerability allows a remote attacker to execute arbitrary code on an affected device via a crafted HTML page when a user engages in specific UI gestures.
CVE-2026-10957 is a use after free vulnerability in Glic in Google Chrome prior to 149.0.7827.53. This vulnerability allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The CVSS score for this vulnerability is 8.8, indicating a high severity. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].
CVE-2026-10956 is a Use after free vulnerability in MimeHandlerView in Google Chrome prior to 149.0.7827.53. This vulnerability, with a CVSS score of 8.8, could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].
CVE-2026-10955 is a High-severity vulnerability in Google Chrome on Windows, allowing remote attackers to potentially perform out-of-bounds memory access via a crafted HTML page. The vulnerability is caused by a type confusion in ANGLE (Almost Native Graphics Layer Engine).
CVE-2026-10954 is a Use after free vulnerability in the Actor component of Google Chrome prior to version 149.0.7827.53. This vulnerability, rated as High severity by Chromium, allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The CVSS score for this vulnerability is 8.8.
CVE-2026-10953 is a high-severity vulnerability in Google Chrome on Android prior to version 149.0.7827.53. This use-after-free issue in the Core component could allow a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The vulnerability has a CVSS score of 8.3 and is classified as High by Chromium security severity.
CVE-2026-10952 is a high-severity vulnerability in Google Chrome for iOS prior to version 149.0.7827.53. This use-after-free issue allows remote attackers to potentially exploit heap corruption via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and is considered High severity by Chromium security.
CVE-2026-10951 is a Use after free vulnerability in Autofill in Google Chrome on iOS prior to 149.0.7827.53. This vulnerability, with a CVSS score of 8.8, could allow a remote attacker who convinces a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page.
CVE-2026-10950 is a vulnerability in Google Chrome on iOS, specifically related to insufficient policy enforcement in Autofill. This issue, with a CVSS score of 6.5 (Medium severity), could allow a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2026-10949 is a High-severity vulnerability in Google Chrome, specifically a heap buffer overflow in the Video component. This issue, tracked by Chromium as a High severity security issue, could allow a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVE-2026-10948 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.53. This use-after-free issue in WebRTC could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and is considered High severity by Chromium.
CVE-2026-10947 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.53. This use-after-free issue in WebRTC could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and is considered High severity by Chromium.
CVE-2026-10946 is a High-severity vulnerability in Google Chrome, specifically a heap buffer overflow in the Media component. This issue was addressed in Chrome version 149.0.7827.53. An attacker could exploit this vulnerability by convincing a user to engage in specific UI gestures via a crafted HTML page, allowing for arbitrary code execution within a sandbox.
CVE-2026-10945 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is a use-after-free issue in the PDF component of Google Chrome, which allows a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file, requiring specific UI gestures from the user. The CVSS score for this vulnerability is 8.8, indicating a high level of severity.