These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-10944 is a vulnerability in Google Chrome on iOS, specifically related to insufficient policy enforcement in Autofill. This issue, which was reported with a CVSS score of 6.5 and categorized as MEDIUM severity, could allow a remote attacker to leak cross-origin data via a crafted HTML page. The vulnerability was first published on [cvePublishedAt] and subsequently modified on [cveModifiedAt].
CVE-2026-10943 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.53. This use-after-free issue in WebRTC could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and is considered High severity by Chromium.
CVE-2026-10942 is a High-severity vulnerability in Google Chrome's UI implementation on Windows. The vulnerability, which was published on 2026-06-04, allows a local attacker to perform privilege escalation via a malicious file. The CVSS score for this vulnerability is 7.8, indicating a High severity level. The vulnerability was addressed in Google Chrome version 149.0.7827.53. Users are advised to update [truncated]
CVE-2026-10941 is a High severity vulnerability in Google Chrome prior to 149.0.7827.53. The vulnerability is caused by an out of bounds memory access in Skia, which allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The CVSS score for this vulnerability is 8.8, indicating a High severity. The vulnerability was published on [cve-org](https://www.cve.org/CVERecord? [truncated]
CVE-2026-10940 is a High severity vulnerability in Google Chrome on Windows prior to 149.0.7827.53. A remote attacker who had compromised the renderer process could potentially perform a sandbox escape via a crafted HTML page. The vulnerability has a CVSS score of 8.3 and is classified as High severity.
CVE-2026-10939 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.53. This use-after-free issue in WebRTC could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and is considered High severity by Chromium.
CVE-2026-10938 is a High-severity vulnerability in Google Chrome prior to version 149.0.7827.53. This issue involves an inappropriate implementation in the Input component, which could allow a remote attacker who has compromised the renderer process to bypass site isolation via a crafted HTML page. The CVSS score for this vulnerability is 6.5, categorized as MEDIUM severity. Google has addressed this issu [truncated]
CVE-2026-10937 is a High-severity vulnerability in Google Chrome prior to version 149.0.7827.53. This issue involves an inappropriate implementation in Passwords, which could allow a remote attacker to bypass same-origin policy via a crafted HTML page. The vulnerability has a CVSS score of 6.5, indicating a Medium severity level.
A Type Confusion vulnerability in V8 in Google Chrome prior to 149.0.7827.53 was reported. This vulnerability, with a CVSS score of 8.8, could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
CVE-2026-10935 is a High severity vulnerability in Google Chrome prior to 149.0.7827.53. This Type Confusion issue in V8 could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and is considered High severity.
CVE-2026-10934 is a High severity vulnerability in Google Chrome on Android prior to 149.0.7827.53. The vulnerability is caused by a use after free in Autofill, which could allow a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The CVSS score for this vulnerability is 8.3, indicating a High severity.
CVE-2026-10933 is a high-severity vulnerability in Google Chrome on Windows, allowing a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability is caused by a use-after-free issue in the Audio component. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code in the context of the sandbox.
CVE-2026-10932 is a high-severity vulnerability in Google Chrome on Android prior to version 149.0.7827.53. This use-after-free issue in the UI component could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and is classified as High by Chromium security severity.
CVE-2026-10931 is a critical vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by a use after free in the FileSystem component, which could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability has a CVSS score of 9.6 and is considered critical.
CVE-2026-10930 is a High severity vulnerability in Google Chrome on Mac. The vulnerability is an out of bounds read in ANGLE, which could allow a remote attacker to perform an out of bounds memory read via a crafted HTML page. The vulnerability has a CVSS score of 8.1.
CVE-2026-10929 is a High-severity vulnerability in Google Chrome's ANGLE (Almost Native Graphics Layer Engine) component. The issue is a heap buffer overflow that occurs when processing a crafted HTML page, potentially allowing a remote attacker who has compromised the renderer process to escape the sandbox.
CVE-2026-10928 is a High severity vulnerability in Google Chrome prior to 149.0.7827.53. The vulnerability is caused by a script injection issue in Headless, which could allow a remote attacker to execute arbitrary code via a crafted HTML page. The CVSS score for this vulnerability is 8.8, indicating a High severity level.
CVE-2026-10927 is an out of bounds read vulnerability in Dawn in Google Chrome prior to 149.0.7827.53. A remote attacker who had compromised the renderer process could potentially perform a sandbox escape via a crafted HTML page. The vulnerability has a CVSS score of 8.3 and is considered High severity.
CVE-2026-10926 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is a use-after-free issue in the Cast component, which could allow an attacker on the local network segment to execute arbitrary code via malicious network traffic. The CVSS score for this vulnerability is 8.8, indicating a high level of severity.
CVE-2026-10925 is a High-severity vulnerability in Google Chrome on Mac, allowing a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability is caused by an out-of-bounds write in Skia.
CVE-2026-10924 is an integer overflow vulnerability in Chromecast in Google Chrome prior to 149.0.7827.53. A remote attacker who had compromised the renderer process could potentially perform a sandbox escape via a crafted HTML page. The vulnerability has a CVSS score of 8.3 and is classified as High severity.
CVE-2026-10923 is a high-severity vulnerability in Google Chrome on Android prior to 149.0.7827.53. The vulnerability is caused by a use-after-free issue in WebAppInstalls, which could allow a local attacker to execute arbitrary code via a malicious file. The CVSS score for this vulnerability is 8.8, indicating a high level of severity. This vulnerability was published on [cvePublishedAt] and modified on [truncated]
CVE-2026-10922 is a High-severity vulnerability in Google Chrome prior to version 149.0.7827.53. The issue lies in the insufficient validation of untrusted input in DevTools, which could allow a remote attacker to bypass the same-origin policy via malicious network traffic if a user is convinced to engage in specific UI gestures.
CVE-2026-10921 is an integer overflow vulnerability in Dawn in Google Chrome prior to 149.0.7827.53. A remote attacker who had compromised the renderer process could potentially perform a sandbox escape via a crafted HTML page. The vulnerability has a CVSS score of 8.3 and is classified as High severity.
CVE-2026-10920 is a High severity vulnerability in Google Chrome on Mac prior to 149.0.7827.53. The vulnerability is caused by insufficient validation of untrusted input in WebShare, allowing a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The CVSS score for this vulnerability is 8.3, indicating a High severity.
CVE-2026-10919 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by a use after free in ANGLE, which could allow a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The CVSS score for this vulnerability is 8.3, indicating a high level of severity.
CVE-2026-10918 is a High severity vulnerability in Google Chrome prior to 149.0.7827.53. The vulnerability is a use after free in Viz, which could allow a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The CVSS score for this vulnerability is 8.3, indicating a High severity. The vulnerability was published on [cvePublishedAt] and m [truncated]
CVE-2026-10917 is a High-severity vulnerability in Google Chrome prior to version 149.0.7827.53. The issue involves insufficient validation of untrusted input in the Media component, which could allow a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVE-2026-10916 is a High-severity vulnerability in Google Chrome's DevTools, allowing a remote attacker to inject arbitrary scripts or HTML via a crafted HTML page.
CVE-2026-10915 is a High severity vulnerability in Google Chrome on iOS prior to 149.0.7827.53. This use after free vulnerability in Core allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The CVSS score for this vulnerability is 8.3, indicating a High severity. The vulnerability was published on [cvePublishedAt] and modified [truncated]