PatchSiren

Google CVE debriefs · Page 36

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Google CVE published 2026-06-04

CVE-2026-10944

CVE-2026-10944 is a vulnerability in Google Chrome on iOS, specifically related to insufficient policy enforcement in Autofill. This issue, which was reported with a CVSS score of 6.5 and categorized as MEDIUM severity, could allow a remote attacker to leak cross-origin data via a crafted HTML page. The vulnerability was first published on [cvePublishedAt] and subsequently modified on [cveModifiedAt].

HIGH Google CVE published 2026-06-04

CVE-2026-10943

CVE-2026-10943 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.53. This use-after-free issue in WebRTC could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and is considered High severity by Chromium.

HIGH Google CVE published 2026-06-04

CVE-2026-10942

CVE-2026-10942 is a High-severity vulnerability in Google Chrome's UI implementation on Windows. The vulnerability, which was published on 2026-06-04, allows a local attacker to perform privilege escalation via a malicious file. The CVSS score for this vulnerability is 7.8, indicating a High severity level. The vulnerability was addressed in Google Chrome version 149.0.7827.53. Users are advised to update [truncated]

HIGH Google CVE published 2026-06-04

CVE-2026-10941

CVE-2026-10941 is a High severity vulnerability in Google Chrome prior to 149.0.7827.53. The vulnerability is caused by an out of bounds memory access in Skia, which allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The CVSS score for this vulnerability is 8.8, indicating a High severity. The vulnerability was published on [cve-org](https://www.cve.org/CVERecord? [truncated]

HIGH Google CVE published 2026-06-04

CVE-2026-10940

CVE-2026-10940 is a High severity vulnerability in Google Chrome on Windows prior to 149.0.7827.53. A remote attacker who had compromised the renderer process could potentially perform a sandbox escape via a crafted HTML page. The vulnerability has a CVSS score of 8.3 and is classified as High severity.

HIGH Google CVE published 2026-06-04

CVE-2026-10939

CVE-2026-10939 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.53. This use-after-free issue in WebRTC could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and is considered High severity by Chromium.

MEDIUM Google CVE published 2026-06-04

CVE-2026-10938

CVE-2026-10938 is a High-severity vulnerability in Google Chrome prior to version 149.0.7827.53. This issue involves an inappropriate implementation in the Input component, which could allow a remote attacker who has compromised the renderer process to bypass site isolation via a crafted HTML page. The CVSS score for this vulnerability is 6.5, categorized as MEDIUM severity. Google has addressed this issu [truncated]

MEDIUM Google CVE published 2026-06-04

CVE-2026-10937

CVE-2026-10937 is a High-severity vulnerability in Google Chrome prior to version 149.0.7827.53. This issue involves an inappropriate implementation in Passwords, which could allow a remote attacker to bypass same-origin policy via a crafted HTML page. The vulnerability has a CVSS score of 6.5, indicating a Medium severity level.

HIGH Google CVE published 2026-06-04

CVE-2026-10936

A Type Confusion vulnerability in V8 in Google Chrome prior to 149.0.7827.53 was reported. This vulnerability, with a CVSS score of 8.8, could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

HIGH Google CVE published 2026-06-04

CVE-2026-10935

CVE-2026-10935 is a High severity vulnerability in Google Chrome prior to 149.0.7827.53. This Type Confusion issue in V8 could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and is considered High severity.

HIGH Google CVE published 2026-06-04

CVE-2026-10934

CVE-2026-10934 is a High severity vulnerability in Google Chrome on Android prior to 149.0.7827.53. The vulnerability is caused by a use after free in Autofill, which could allow a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The CVSS score for this vulnerability is 8.3, indicating a High severity.

HIGH Google CVE published 2026-06-04

CVE-2026-10933

CVE-2026-10933 is a high-severity vulnerability in Google Chrome on Windows, allowing a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability is caused by a use-after-free issue in the Audio component. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code in the context of the sandbox.

HIGH Google CVE published 2026-06-04

CVE-2026-10932

CVE-2026-10932 is a high-severity vulnerability in Google Chrome on Android prior to version 149.0.7827.53. This use-after-free issue in the UI component could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and is classified as High by Chromium security severity.

CRITICAL Google CVE published 2026-06-04

CVE-2026-10931

CVE-2026-10931 is a critical vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by a use after free in the FileSystem component, which could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability has a CVSS score of 9.6 and is considered critical.

HIGH Google CVE published 2026-06-04

CVE-2026-10930

CVE-2026-10930 is a High severity vulnerability in Google Chrome on Mac. The vulnerability is an out of bounds read in ANGLE, which could allow a remote attacker to perform an out of bounds memory read via a crafted HTML page. The vulnerability has a CVSS score of 8.1.

HIGH Google CVE published 2026-06-04

CVE-2026-10929

CVE-2026-10929 is a High-severity vulnerability in Google Chrome's ANGLE (Almost Native Graphics Layer Engine) component. The issue is a heap buffer overflow that occurs when processing a crafted HTML page, potentially allowing a remote attacker who has compromised the renderer process to escape the sandbox.

HIGH Google CVE published 2026-06-04

CVE-2026-10928

CVE-2026-10928 is a High severity vulnerability in Google Chrome prior to 149.0.7827.53. The vulnerability is caused by a script injection issue in Headless, which could allow a remote attacker to execute arbitrary code via a crafted HTML page. The CVSS score for this vulnerability is 8.8, indicating a High severity level.

HIGH Google CVE published 2026-06-04

CVE-2026-10927

CVE-2026-10927 is an out of bounds read vulnerability in Dawn in Google Chrome prior to 149.0.7827.53. A remote attacker who had compromised the renderer process could potentially perform a sandbox escape via a crafted HTML page. The vulnerability has a CVSS score of 8.3 and is considered High severity.

HIGH Google CVE published 2026-06-04

CVE-2026-10926

CVE-2026-10926 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is a use-after-free issue in the Cast component, which could allow an attacker on the local network segment to execute arbitrary code via malicious network traffic. The CVSS score for this vulnerability is 8.8, indicating a high level of severity.

HIGH Google CVE published 2026-06-04

CVE-2026-10925

CVE-2026-10925 is a High-severity vulnerability in Google Chrome on Mac, allowing a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability is caused by an out-of-bounds write in Skia.

HIGH Google CVE published 2026-06-04

CVE-2026-10924

CVE-2026-10924 is an integer overflow vulnerability in Chromecast in Google Chrome prior to 149.0.7827.53. A remote attacker who had compromised the renderer process could potentially perform a sandbox escape via a crafted HTML page. The vulnerability has a CVSS score of 8.3 and is classified as High severity.

HIGH Google CVE published 2026-06-04

CVE-2026-10923

CVE-2026-10923 is a high-severity vulnerability in Google Chrome on Android prior to 149.0.7827.53. The vulnerability is caused by a use-after-free issue in WebAppInstalls, which could allow a local attacker to execute arbitrary code via a malicious file. The CVSS score for this vulnerability is 8.8, indicating a high level of severity. This vulnerability was published on [cvePublishedAt] and modified on [truncated]

HIGH Google CVE published 2026-06-04

CVE-2026-10922

CVE-2026-10922 is a High-severity vulnerability in Google Chrome prior to version 149.0.7827.53. The issue lies in the insufficient validation of untrusted input in DevTools, which could allow a remote attacker to bypass the same-origin policy via malicious network traffic if a user is convinced to engage in specific UI gestures.

HIGH Google CVE published 2026-06-04

CVE-2026-10921

CVE-2026-10921 is an integer overflow vulnerability in Dawn in Google Chrome prior to 149.0.7827.53. A remote attacker who had compromised the renderer process could potentially perform a sandbox escape via a crafted HTML page. The vulnerability has a CVSS score of 8.3 and is classified as High severity.

HIGH Google CVE published 2026-06-04

CVE-2026-10920

CVE-2026-10920 is a High severity vulnerability in Google Chrome on Mac prior to 149.0.7827.53. The vulnerability is caused by insufficient validation of untrusted input in WebShare, allowing a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The CVSS score for this vulnerability is 8.3, indicating a High severity.

HIGH Google CVE published 2026-06-04

CVE-2026-10919

CVE-2026-10919 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.53. The vulnerability is caused by a use after free in ANGLE, which could allow a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The CVSS score for this vulnerability is 8.3, indicating a high level of severity.

HIGH Google CVE published 2026-06-04

CVE-2026-10918

CVE-2026-10918 is a High severity vulnerability in Google Chrome prior to 149.0.7827.53. The vulnerability is a use after free in Viz, which could allow a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The CVSS score for this vulnerability is 8.3, indicating a High severity. The vulnerability was published on [cvePublishedAt] and m [truncated]

HIGH Google CVE published 2026-06-04

CVE-2026-10917

CVE-2026-10917 is a High-severity vulnerability in Google Chrome prior to version 149.0.7827.53. The issue involves insufficient validation of untrusted input in the Media component, which could allow a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

MEDIUM Google CVE published 2026-06-04

CVE-2026-10916

CVE-2026-10916 is a High-severity vulnerability in Google Chrome's DevTools, allowing a remote attacker to inject arbitrary scripts or HTML via a crafted HTML page.

HIGH Google CVE published 2026-06-04

CVE-2026-10915

CVE-2026-10915 is a High severity vulnerability in Google Chrome on iOS prior to 149.0.7827.53. This use after free vulnerability in Core allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The CVSS score for this vulnerability is 8.3, indicating a High severity. The vulnerability was published on [cvePublishedAt] and modified [truncated]