PatchSiren

Google CVE debriefs · Page 38

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Google CVE published 2026-06-04

CVE-2026-10883

CVE-2026-10883 is a Critical vulnerability in Google Chrome prior to 149.0.7827.53. The vulnerability is caused by a Type Confusion in ANGLE, which could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. The CVSS score for this vulnerability is 8.8, indicating a HIGH severity. The vulnerability was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-202 [truncated]

HIGH Google CVE published 2026-06-04

CVE-2026-10882

CVE-2026-10882 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.53. This use-after-free issue in the Network component allows remote attackers to execute arbitrary code via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and is considered Critical by Chromium security severity.

CRITICAL Google CVE published 2026-06-04

CVE-2026-10881

CVE-2026-10881 is a Critical vulnerability in Google Chrome prior to 149.0.7827.53. The vulnerability is an out of bounds read and write in ANGLE, which could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The CVSS score for this vulnerability is 9.6, indicating a high severity. The vulnerability was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=C [truncated]

CRITICAL Google CVE published 2026-06-01

CVE-2026-0072

PatchSiren defensive debrief for CVE-2026-0072, published 2026-06-01. A missing permission check in `addInputMethodListener` of `com.android.server.inputmethod.InputMethodManagerService` enables local privilege escalation without requiring additional execution privileges or user interaction. The vulnerability is rated CRITICAL with a CVSS score of 10. The weakness maps to CWE-285 (Improper Authorization). [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9993

A use-after-free vulnerability in Google Chrome's Views component, present in versions prior to 148.0.7778.216, enables a remote attacker who has already compromised the renderer process to potentially escape the browser sandbox by tricking a user into opening a crafted PDF file. The Chromium security team rates this flaw as High severity. The vulnerability was published in the NVD on 2026-05-28 and last [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9992

A use-after-free vulnerability in Google Chrome's Network component, rated High severity by Chromium, allows remote code execution inside the browser sandbox when a user visits a crafted HTML page. The flaw was addressed in Chrome 148.0.7778.216 for desktop platforms.

LOW Google CVE published 2026-05-28

CVE-2026-9991

A cross-origin data leak vulnerability in Google Chrome's media implementation on Windows, rated Low severity (CVSS 3.1) with a High Chromium security severity. The flaw existed in Chrome versions prior to 148.0.7778.216 and could be exploited by a remote attacker who had already compromised the renderer process, using a crafted HTML page to leak cross-origin data. The vulnerability was published on May 2 [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9990

A use-after-free vulnerability in Google Chrome's WebAppInstalls component on macOS, rated High severity by Chromium. The flaw exists in versions prior to 148.0.7778.216 and requires user interaction through specific UI gestures to trigger. Successful exploitation could lead to heap corruption, potentially enabling remote code execution. The vulnerability was disclosed via Chrome's stable channel release [truncated]

MEDIUM Google CVE published 2026-05-28

CVE-2026-9989

A same-origin policy bypass in Google Chrome's media handling, rated High severity by Chromium and Medium (6.3) on the CVSS 3.1 scale. The flaw stems from inappropriate implementation in the browser's Media component and can be triggered when a user processes a crafted video file. A remote attacker who convinces a victim to load malicious video content may bypass same-origin protections, potentially leadi [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9988

A use-after-free vulnerability in WebRTC on Google Chrome for Linux allows remote attackers to potentially escape the browser sandbox via crafted HTML. The flaw carries a High severity rating from Chromium and a CVSS 3.1 score of 8.3. Affected versions are those prior to 148.0.7778.216 on Linux; the CPE indicates the Linux kernel itself is not directly vulnerable, but Chrome on Linux is the affected produ [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9987

A high-severity local code execution vulnerability in Google Chrome on Android, stemming from insufficient validation of untrusted input in the WebAppInstalls component. A local attacker can exploit this by tricking a user into processing a malicious file, resulting in arbitrary code execution with elevated privileges. The Chromium security team rates this severity as High. The issue is resolved in Chrome [truncated]

MEDIUM Google CVE published 2026-05-28

CVE-2026-9986

A UI spoofing vulnerability in Google Chrome's OptimizationGuide component, rated Medium severity (CVSS 4.2). The flaw stems from insufficient validation of untrusted input, enabling a remote attacker who has already compromised the renderer process to spoof UI elements via a crafted HTML page. The Chromium project assigned this a High security severity. Google addressed the issue in Chrome stable channel [truncated]

MEDIUM Google CVE published 2026-05-28

CVE-2026-9985

A high-severity information disclosure vulnerability in Google Chrome on ChromeOS, published 2026-05-28 and modified 2026-05-29. Insufficient validation of untrusted input in the Media component allows a remote attacker who has already compromised the renderer process to extract potentially sensitive information from process memory via a crafted HTML page. The vulnerability is rated CVSS 5.3 (Medium) with [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9984

A use-after-free vulnerability in Google Chrome's UI component on Windows allows remote code execution via crafted HTML pages. The vulnerability, rated High severity by Chromium, has a CVSS 3.1 score of 8.8. It affects Chrome versions prior to 148.0.7778.216 on Windows platforms. The flaw stems from improper memory management (CWE-416) in the browser's user interface layer, where freed memory can be acces [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9983

A type confusion vulnerability in Skia, the 2D graphics library used by Google Chrome, allows remote code execution inside the browser sandbox when a user visits a crafted HTML page. The flaw was fixed in Chrome 148.0.7778.216. Google rates this as High severity. The NVD-assigned CVSS 3.1 score is 8.8 (High), reflecting network attack vector, low complexity, no privileges required, user interaction requir [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9982

A high-severity sandbox escape vulnerability in Google Chrome's ANGLE graphics layer, exploitable by a remote attacker who has already compromised the renderer process. The flaw stems from insufficient validation of untrusted input, allowing crafted HTML content to break out of the renderer sandbox. Chrome versions prior to 148.0.7778.216 are affected. The Chromium project rates this as High severity. No [truncated]

MEDIUM Google CVE published 2026-05-28

CVE-2026-9981

A high-severity information disclosure vulnerability in Google Chrome's Skia graphics engine allows remote attackers to extract potentially sensitive information from process memory by tricking a user into loading a crafted HTML page. The flaw stems from an inappropriate implementation in Skia, Chrome's 2D graphics library, which mishandles certain rendering operations in a way that leaks memory contents. [truncated]

MEDIUM Google CVE published 2026-05-28

CVE-2026-9980

A site isolation bypass in Google Chrome's Printing component, rated High severity by Chromium. The flaw stems from insufficient validation of untrusted input and could allow a remote attacker who has already compromised the renderer process to bypass site isolation protections via a crafted HTML page. The vulnerability affects Chrome versions prior to 148.0.7778.216. The CVE was published on 2026-05-28 a [truncated]

MEDIUM Google CVE published 2026-05-28

CVE-2026-9979

A site isolation bypass vulnerability in Google Chrome's Input handling, rated Medium severity (CVSS 5.0), was disclosed on May 28, 2026. The flaw stems from insufficient validation of untrusted input and requires an attacker to first compromise the renderer process, then leverage a crafted HTML page to bypass site isolation protections. The Chromium security team assigned this a High severity rating inte [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9978

A use-after-free vulnerability in Glic (Google's Linux Integrity Checker / related Chrome component) allows remote code execution inside the Chrome sandbox when a user visits a crafted HTML page. The flaw was fixed in Chrome 148.0.7778.216 for desktop. Google rates this as High severity. The CVSS 3.1 score of 8.8 reflects network attack vector, low complexity, no privileges required, user interaction requ [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9977

A high-severity vulnerability in Google Chrome on Android's WebShare feature, where insufficient validation of untrusted input could allow a remote attacker who had compromised the renderer process to potentially escape the sandbox via a crafted HTML page. The vulnerability was addressed in Chrome version 148.0.7778.216. The Chromium project rated this as High severity. The issue involves improper input v [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9976

A high-severity inappropriate implementation vulnerability in Google Chrome's USB subsystem allows remote code execution via crafted HTML pages. Affected versions are prior to 148.0.7778.216 on Windows, macOS, and Linux. The vulnerability was published by NVD on 2026-05-28 and modified on 2026-05-29. No known exploitation in ransomware campaigns has been reported.

HIGH Google CVE published 2026-05-28

CVE-2026-9974

An out-of-bounds write vulnerability in the GPU component of Google Chrome prior to version 148.0.7778.216 enables a remote attacker who has already compromised the renderer process to potentially escape the browser sandbox. The vulnerability requires user interaction (rendering a crafted HTML page) and has high attack complexity, but successful exploitation yields complete confidentiality, integrity, and [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9973

An out-of-bounds write vulnerability in Google Chrome's V8 JavaScript engine, rated High severity by Chromium, enables remote code execution inside the browser sandbox when a user visits a crafted HTML page. The flaw was addressed in Chrome 148.0.7778.216 for desktop platforms.

HIGH Google CVE published 2026-05-28

CVE-2026-9972

A high-severity vulnerability in Google Chrome on macOS, published 2026-05-28, involves uninitialized use in the Gamepad component. The flaw could allow a remote attacker who has already compromised the renderer process to potentially escape the Chrome sandbox via a crafted HTML page. The issue was fixed in Chrome version 148.0.7778.216. The vulnerability is classified under CWE-457 (Use of Uninitialized [truncated]

MEDIUM Google CVE published 2026-05-28

CVE-2026-9971

A Universal Cross-Site Scripting (UXSS) vulnerability in Google Chrome on iOS, fixed in version 148.0.7778.216, allows remote attackers to inject arbitrary scripts or HTML after convincing a user to perform specific UI gestures. The vulnerability stems from an inappropriate implementation in iOS and carries a High severity rating per Chromium. The CVSS 3.1 score of 5.4 (MEDIUM) reflects network attack vec [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9970

A use-after-free vulnerability in WebGL within Google Chrome versions prior to 148.0.7778.216 enables a remote attacker who has already compromised the renderer process to potentially escape the browser sandbox. The vulnerability carries a High severity rating per Chromium's security classification and a CVSS 3.1 score of 8.3 (HIGH). The issue was published in the NVD on May 28, 2026, with a subsequent mo [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9969

A high-severity remote code execution vulnerability in Google Chrome's ANGLE graphics layer, caused by insufficient validation of untrusted input. A remote attacker can exploit this via a crafted HTML page to execute arbitrary code in the context of the browser process. The vulnerability affects Chrome versions prior to 148.0.7778.216. The Chromium project has assigned this a High severity rating.

HIGH Google CVE published 2026-05-28

CVE-2026-9968

An integer overflow vulnerability in Google Chrome's V8 JavaScript engine, rated High severity by Chromium, enables remote code execution inside the browser sandbox when a user visits a crafted HTML page. The flaw was addressed in Chrome version 148.0.7778.216. The CVSS 3.1 score of 8.8 reflects network attack vector, low attack complexity, no privileges required, user interaction needed, and high impact [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9966

An integer overflow vulnerability in Chrome's XML processing on Windows enables sandbox escape from a compromised renderer process. The attacker must first achieve renderer compromise (e.g., via separate vulnerability), then use a crafted HTML page to trigger the overflow and escape the sandbox. The CVSS 3.1 score of 8.3 reflects high impact (confidentiality, integrity, availability) with network attack v [truncated]