These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-9965 is a high-severity out-of-bounds write vulnerability in ANGLE, the graphics layer used by Google Chrome. The flaw exists in Chrome versions prior to 148.0.7778.216 and can be triggered by a remote attacker through a crafted HTML page, potentially leading to heap corruption. The vulnerability was published in the NVD on May 28, 2026, and modified on May 29, 2026. Google has assigned this a Ch [truncated]
A use-after-free vulnerability in the Bluetooth subsystem of Google Chrome on macOS allows arbitrary code execution when a user installs a malicious Chrome extension. The flaw, rated High severity by Chromium, exists in Chrome versions prior to 148.0.7778.216. The CVSS 3.1 score of 8.1 reflects high impact to confidentiality, integrity, and availability despite requiring high attack complexity. The vulner [truncated]
An uninitialized use vulnerability in Google Chrome on iOS prior to version 148.0.7778.216 enables remote code execution inside the browser sandbox. The flaw requires user interaction through specific UI gestures triggered by a crafted HTML page. The Chromium security team rates this as High severity. The underlying weakness is CWE-457 (Use of Uninitialized Variable). The CVSS 3.1 vector indicates network [truncated]
A use-after-free vulnerability in WebRTC within Google Chrome versions prior to 148.0.7778.216 enables remote code execution inside the browser sandbox. An attacker can exploit this flaw by convincing a user to visit a crafted HTML page, triggering memory corruption during WebRTC session handling. The vulnerability carries a High severity rating from the Chromium security team and an 8.8 CVSS score, refle [truncated]
A use-after-free vulnerability in Google Chrome's SurfaceCapture component, rated High severity by Chromium and scored CVSS 8.8, allows remote attackers to potentially exploit heap corruption via a crafted HTML page. The flaw affects Chrome versions prior to 148.0.7778.216. Google addressed this in a stable channel update released May 2026. No known exploitation in ransomware campaigns has been documented [truncated]
An integer overflow vulnerability in PDFium, the PDF rendering engine embedded in Google Chrome, allowed arbitrary code execution within the sandbox from a compromised renderer process. The flaw was triggered by a crafted font file. Google rated this a High-severity issue and addressed it in Chrome 148.0.7778.216.
A race condition in WebRTC on Google Chrome for Windows, fixed in version 148.0.7778.216, could allow a remote attacker to leak cross-origin data by enticing a user to visit a crafted HTML page. The Chromium project rated this flaw as High severity, though the published CVSS 3.1 base score is 3.1 (Low). The weakness is categorized as CWE-362 (Concurrent Execution using Shared Resource with Improper Synchr [truncated]
A use-after-free vulnerability in PDFium, the PDF rendering engine embedded in Google Chrome, could allow remote attackers to exploit heap corruption through a crafted PDF file. The vulnerability affects Chrome versions prior to 148.0.7778.216 and carries a High severity rating from the Chromium security team. The CVSS 3.1 score of 8.8 reflects network attackability with low complexity, no privileges requ [truncated]
Use-after-free in Google Chrome's PDF component enables remote code execution via crafted PDF files.
A use-after-free vulnerability in Google Chrome on iOS, fixed in version 148.0.7778.216, enables remote code execution when a user performs specific UI gestures on a crafted HTML page. The Chromium project rates this flaw as High severity. The vulnerability was published in the NVD on 2026-05-28 and last modified on 2026-05-29.
A cross-origin data leak vulnerability in Google Chrome on iOS, caused by inappropriate implementation in iOS-specific code. A remote attacker could exploit this via a crafted HTML page to leak data across origins. The Chromium security team rated this High severity. The issue affects Chrome on iOS versions prior to 148.0.7778.216. Google released a stable channel update addressing this vulnerability. The [truncated]
A use-after-free vulnerability in Google Chrome's TabStrip component, present in versions prior to 148.0.7778.216, enables remote attackers to potentially achieve heap corruption through crafted HTML pages when combined with specific user UI gestures. The vulnerability carries a High severity rating from the Chromium security team and a CVSS 3.1 score of 7.5 (HIGH). The use-after-free condition (CWE-416) [truncated]
Out-of-bounds read in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome versions prior to 148.0.7778.216. A remote attacker can leverage a crafted HTML page to read beyond allocated buffer boundaries in process memory, potentially exposing sensitive information. The Chromium project rates this flaw as High severity. The vulnerability was disclosed via the Chrome stable channel release notes [truncated]
A use-after-free vulnerability in Google Chrome's WebAudio component allows remote code execution inside the browser sandbox when a user visits a crafted HTML page. The flaw was fixed in Chrome 148.0.7778.216. Google rates this as High severity. The NVD-assigned CVSS 3.1 score is 8.8 (High), reflecting network attack vector, low attack complexity, no privileges required, user interaction required, and hig [truncated]
A use-after-free vulnerability in Google Chrome's UI component, present in versions prior to 148.0.7778.216, enables remote attackers to potentially escape the browser sandbox through crafted HTML content. The Chromium security team has assigned this a High severity rating. The vulnerability stems from improper memory management (CWE-416) in the UI subsystem, where freed memory may be accessed under speci [truncated]
A same-origin policy bypass in Google Chrome on iOS, rated High severity by Chromium but scored LOW (3.1) under CVSS 3.1. The vulnerability stems from insufficient validation of untrusted input in iOS-specific code paths. A remote attacker who has already compromised the renderer process can leverage a crafted HTML page to bypass same-origin protections. The attack requires user interaction (UI:R) and hig [truncated]
A use-after-free vulnerability in Google Chrome's Core component on Windows allows a remote attacker who has already compromised the renderer process to potentially escape the browser sandbox. The vulnerability is rated High severity by Chromium and carries a CVSS 3.1 score of 8.3. The flaw exists in Chrome versions prior to 148.0.7778.216 on Windows platforms. Successful exploitation requires user intera [truncated]
A use-after-free vulnerability in the Views component of Google Chrome on macOS, fixed in version 148.0.7778.216, enables sandbox escape from a compromised renderer process. The Chromium security team rates this High severity. The flaw requires an attacker to first compromise the renderer process, then leverage the use-after-free via a crafted HTML page to break out of the Chrome sandbox. The CVSS v3.1 sc [truncated]
A use-after-free vulnerability in Chrome's XML processing allows remote code execution inside the sandbox when a user visits a crafted HTML page. Google rated this High severity and patched it in Chrome 148.0.7778.216. The NVD entry was published on 2026-05-28 and last modified on 2026-05-29. No known exploitation in ransomware campaigns has been catalogued in CISA KEV.
Use-after-free vulnerability in ANGLE, the graphics rendering layer used by Google Chrome. A remote attacker who has already compromised the renderer process can exploit this flaw to potentially escape the Chrome sandbox via a crafted HTML page. The vulnerability affects Chrome versions prior to 148.0.7778.216 on Windows, macOS, and Linux. Google has assigned a High severity rating to this issue.
A use-after-free vulnerability in Google Chrome's Media component on Windows allows remote code execution inside the sandbox when a user visits a crafted HTML page. The flaw was addressed in Chrome stable channel update 148.0.7778.216, published 2026-05-28. The Chromium security team rated this High severity. No known exploitation in ransomware campaigns has been catalogued in CISA KEV.
CVE-2026-9944 is a high-severity uninitialized use vulnerability in ANGLE, the graphics layer used by Google Chrome. The flaw exists in versions prior to 148.0.7778.216 and enables a remote attacker who has already compromised the renderer process to leak cross-origin data through a crafted HTML page. The vulnerability stems from CWE-457 (Use of Uninitialized Variable), which can lead to information discl [truncated]
A medium-severity out-of-bounds read vulnerability in WebGL on Google Chrome for Android, disclosed on 2026-05-28, enables remote attackers to leak cross-origin data via a crafted HTML page. The flaw was fixed in Chrome 148.0.7778.216. No known exploitation in ransomware campaigns has been reported.
An uninitialized use vulnerability in ANGLE, the graphics translation layer used by Google Chrome, allows a remote attacker who has already compromised the renderer process to bypass site isolation protections. The vulnerability stems from CWE-457 (Use of Uninitialized Variable) and affects Chrome versions prior to 148.0.7778.216. Successful exploitation requires the attacker to first achieve renderer com [truncated]
A use-after-free vulnerability in ANGLE, the graphics layer used by Google Chrome, was patched in Chrome 148.0.7778.216. The flaw allowed remote attackers to execute arbitrary code within the browser sandbox via a crafted HTML page. ANGLE (Almost Native Graphics Layer Engine) translates OpenGL ES API calls to native graphics APIs, making this vulnerability reachable through web content. The use-after-free [truncated]
A heap buffer overflow vulnerability in ANGLE, the graphics layer used by Google Chrome, enables remote attackers to potentially achieve heap corruption through a crafted HTML page. ANGLE (Almost Native Graphics Layer Engine) translates OpenGL ES API calls to platform-native graphics APIs, making this vulnerability reachable from web content. The Chromium security team has rated this High severity with a [truncated]
A heap buffer overflow in Google Chrome's WebCodecs API allows remote code execution inside the sandbox when a user visits a crafted HTML page. Google rated this High severity and patched it in Chrome 148.0.7778.216. The vulnerability was published in the NVD on 28 May 2026 and last modified on 29 May 2026. No known exploitation in ransomware campaigns has been catalogued by CISA KEV.
A high-severity inappropriate implementation vulnerability in Google Chrome's V8 JavaScript engine allows remote code execution inside the sandbox via a crafted HTML page. The vulnerability affects Chrome versions prior to 148.0.7778.216. Google has released a stable channel update addressing this issue. The CVSS 3.1 score of 8.8 reflects network attack vector, low attack complexity, no privileges require [truncated]
Use-after-free vulnerability in Google Chrome's UI component on Windows, rated High severity by Chromium. A remote attacker who has already compromised the renderer process could leverage this flaw to potentially escape the Chrome sandbox via a crafted HTML page. The vulnerability was addressed in Chrome stable channel update 148.0.7778.216.
A use-after-free vulnerability in Google Chrome's graphics (GFX) subsystem on macOS allows a remote attacker who has already compromised the renderer process to potentially escape the browser sandbox. The flaw, rated High severity by Chromium, exists in Chrome versions prior to 148.0.7778.216 on Mac. The CVSS 3.1 score of 8.3 reflects high impact across confidentiality, integrity, and availability with ne [truncated]