PatchSiren

Google CVE debriefs · Page 4

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Google CVE published 2026-09-15

CVE-2026-0179

A permission bypass vulnerability exists in the Bootloader component of Google Android. This issue could lead to local escalation of privilege with System execution privileges needed. User interaction is not required for exploitation. The vulnerability requires System execution privileges to exploit, and user interaction is not needed. The impact of this vulnerability is limited to the Bootloader componen [truncated]

MEDIUM Google CVE published 2026-09-15

CVE-2026-0177

A possible out-of-bounds read due to a missing bounds check in crypto-aes.c could lead to local information disclosure with System execution privileges needed. This vulnerability affects Google Android systems, specifically in the do_sss_aes_gcm_256_op function of crypto-aes.c. The vulnerability has a CVSS score of 4.4 and is classified as MEDIUM severity. Defenders and system administrators should assess [truncated]

HIGH Google CVE published 2026-09-15

CVE-2026-0171

CVE-2026-0171 is a high-severity vulnerability in Google Android, potentially allowing remote code execution with no additional execution privileges needed. The vulnerability is caused by a logic error leading to an out-of-bounds write in multiple locations. User interaction is not required for exploitation. The CVSS score is 8.8, indicating a high severity level. This vulnerability affects Android device [truncated]

HIGH Google CVE published 2026-09-15

CVE-2026-0170

CVE-2026-0170 is a high-severity vulnerability in the Vp9DecodeFrameTag of vp9hwd_headers.cc, potentially leading to remote escalation of privilege without additional execution privileges needed. No user interaction is required for exploitation. The vulnerability's high CVSS score of 8.8 emphasizes the need for immediate attention from defenders responsible for systems using the affected component. Affect [truncated]

HIGH Google CVE published 2026-09-15

CVE-2026-0159

CVE-2026-0159 debrief based on the supplied source corpus. The vulnerability is a possible out-of-bounds write due to a missing bounds check in Cellular Modem, which could lead to remote code execution with no additional execution privileges needed. Defenders responsible for Cellular Modem functionality and Android security should assess exposure and prioritize verification. The CVE record and NVD entry p [truncated]

MEDIUM Google CVE published 2026-09-11

CVE-2026-62139

Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit by Google versions <= 1.186.0. Defenders responsible for maintaining and securing WordPress installations using Site Kit by Google should assess exposure and prioritize verification and updates. The vulnerability allows attackers to perform unintended actions on behalf of users. The CVE record and NVD entry provide limited information, with the [truncated]

MEDIUM Google CVE published 2026-09-09

CVE-2026-83530

A memory allocation vulnerability in the Common Expression Language (CEL) environment allows a user to provide an expression with a string length longer than the configured ParserExpressionSizeLimit, leading to a potential denial-of-service (DoS) attack. This vulnerability affects the CEL environment, which is used for evaluating expressions. The vulnerability can be exploited by providing an expression w [truncated]

MEDIUM Google CVE published 2026-09-09

CVE-2026-87656

CVE-2026-87656 is a MEDIUM-severity vulnerability in Google Chrome prior to version 153.0.8010.36, allowing a remote attacker to bypass system access restrictions via a crafted HTML page. The vulnerability has a CVSS score of 5.4 and is classified as CWE-754. This vulnerability affects Google Chrome deployments, and defenders should assess exposure and prioritize updating to version 153.0.8010.36 or later [truncated]

MEDIUM Google CVE published 2026-09-09

CVE-2026-87627

CVE-2026-87627 debrief based on the supplied source corpus. The CVE record was published on 2026-09-09T01:17:20.987Z and has not been modified since then. This vulnerability affects Google Chrome on Mac systems prior to version 153.0.8010.36, allowing remote attackers to bypass system access restrictions via a crafted file. The vulnerability has a medium severity with a CVSS score of 6.5. Defenders should [truncated]

MEDIUM Google CVE published 2026-09-09

CVE-2026-87626

CVE-2026-87626 is a Medium-severity vulnerability in Google Chrome prior to version 153.0.8010.36. The vulnerability is caused by incorrect authorization in DeviceBoundSessionCredentials, allowing a remote attacker to bypass web origin policy via crafted network traffic. Defenders responsible for managing Google Chrome deployments should assess exposure and prioritize updating to version 153.0.8010.36 or [truncated]

MEDIUM Google CVE published 2026-09-09

CVE-2026-87610

CVE-2026-87610 is a Medium-severity vulnerability in Google Chrome's Omnibox feature, allowing remote attackers to bypass system access restrictions via a crafted HTML page. The CVE record was published on 2026-09-09T01:17:19.097Z and was last modified on 2026-09-11T13:57:46.783Z. The NVD entry is currently Analyzed. Defenders responsible for Google Chrome deployments should assess exposure and prioritize [truncated]

HIGH Google CVE published 2026-09-09

CVE-2026-87608

CVE-2026-87608: Improper certificate validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. This vulnerability affects Google Chrome deployments, particularly those in environments where social engineering attacks are a concern. Defenders should assess exposure and prioritize verification [truncated]

HIGH Google CVE published 2026-09-09

CVE-2026-87606

CVE-2026-87606 debrief: Google Chrome SiteIsolation missing authorization allows remote attackers to bypass site isolation via crafted HTML pages. This vulnerability, with a CVSS score of 8.1 and classified as HIGH severity, affects Google Chrome versions prior to 153.0.8010.36. Defenders should assess exposure, prioritize remediation, and verify site isolation configurations to prevent potential unauthor [truncated]

CRITICAL Google CVE published 2026-09-09

CVE-2026-87595

CVE-2026-87595 debrief: Server-side request forgery in Google Chrome allows remote attackers to bypass system access restrictions via crafted HTML pages. This vulnerability, classified as a server-side request forgery issue, affects Google Chrome prior to version 153.0.8010.36. The vulnerability allows remote attackers to bypass system access restrictions via crafted HTML pages, potentially increasing exp [truncated]

MEDIUM Google CVE published 2026-09-09

CVE-2026-87590

CVE-2026-87590 is a medium-severity vulnerability in Google Chrome's Passwords feature prior to version 153.0.8010.36. The vulnerability allows a remote attacker to potentially leak sensitive information via crafted network traffic. Defenders should assess exposure and prioritize updates to 153.0.8010.36 or later. The CVE record and NVD entry provide details, but additional information on potential exploi [truncated]

MEDIUM Google CVE published 2026-09-09

CVE-2026-87589

CVE-2026-87589 is an incorrect authorization vulnerability in SiteIsolation in Google Chrome prior to 153.0.8010.36. A remote attacker who has compromised the renderer process can bypass system access restrictions via a crafted HTML page. The vulnerability has a CVSS score of 6.5 and a severity of Medium. This vulnerability affects Google Chrome deployments and requires immediate attention from defenders [truncated]

MEDIUM Google CVE published 2026-09-09

CVE-2026-87584

CVE-2026-87584 is an incorrect authorization vulnerability in Google Chrome's WebUI. The vulnerability allowed a remote attacker to bypass system access restrictions via a crafted HTML page. It has a CVSS score of 6.5 and is classified as Medium severity. Defenders should assess exposure and prioritize patching to prevent potential unauthorized access. The vulnerability affects Google Chrome's WebUI, whic [truncated]

MEDIUM Google CVE published 2026-09-09

CVE-2026-87580

CVE-2026-87580 is an incorrect authorization vulnerability in WebAppInstalls in Google Chrome prior to version 153.0.8010.36. This vulnerability allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. The Chromium security severity is rated as Medium with a CVSS score of 6.5.

MEDIUM Google CVE published 2026-09-09

CVE-2026-87575

CVE-2026-87575 is an incorrect authorization vulnerability in Google Chrome's Loader component prior to version 153.0.8010.36. This CVE was published on 2026-09-09T01:17:15.277Z and was last modified on 2026-09-14T13:18:59.007Z. The NVD entry is currently Modified. The vulnerability allows remote attackers to bypass system access restrictions via a crafted HTML page, with a CVSS score of 5.4 and a severit [truncated]

MEDIUM Google CVE published 2026-09-09

CVE-2026-87571

Google Chrome users should assess exposure to CVE-2026-87571, a medium-severity vulnerability allowing remote attackers to bypass web origin policy via crafted network traffic. Defenders should verify Chrome versions prior to 153.0.8010.36 and prioritize patching. This vulnerability, caused by improper certificate validation in the Loader component, could lead to security risks if exploited. Users should [truncated]

MEDIUM Google CVE published 2026-09-09

CVE-2026-87551

CVE-2026-87551 is a medium-severity vulnerability in Google Chrome prior to 153.0.8010.36, allowing a remote attacker to bypass web origin policy via crafted network traffic by improperly validating certificates in CORS. This vulnerability requires social engineering tactics to exploit. Defenders should assess exposure and prioritize updates to 153.0.8010.36 or later. The CVE record and NVD entry provide [truncated]

MEDIUM Google CVE published 2026-09-09

CVE-2026-87546

CVE-2026-87546 is a vulnerability in Google Chrome's Safebrowsing feature on Mac systems prior to version 153.0.8010.36. This issue, caused by incorrect type conversion or casting, allows a remote attacker to bypass system access restrictions via a crafted file. The vulnerability has a CVSS score of 4.3, indicating a medium severity level. Defenders responsible for managing Google Chrome installations on [truncated]

CRITICAL Google CVE published 2026-09-09

CVE-2026-87544

CVE-2026-87544 is a critical vulnerability in Google Chrome prior to version 153.0.8010.36, allowing remote attackers to bypass system access restrictions via a crafted HTML page. The vulnerability has a CVSS score of 9.8 and is classified as CRITICAL. Chrome users, particularly those with high-security requirements, should assess their exposure and update to version 153.0.8010.36 or later. This vulnerabi [truncated]

MEDIUM Google CVE published 2026-09-09

CVE-2026-87522

PatchSiren debrief for CVE-2026-87522: Missing authorization in WebView in Google Chrome on Android prior to 153.0.8010.36 allows remote attackers to potentially bypass system access restrictions via crafted network traffic. Defenders should assess exposure, prioritize remediation, and verify system updates. This vulnerability has a medium severity and defenders should review WebView authorization checks [truncated]

MEDIUM Google CVE published 2026-09-09

CVE-2026-87519

CVE-2026-87519 is an incorrect authorization vulnerability in Google Chrome's Safebrowsing feature prior to version 153.0.8010.36. This vulnerability could allow a remote attacker to bypass system access restrictions via a crafted HTML page, leveraging social engineering tactics. The Chromium security team classified this issue as Low severity. Affected Google Chrome deployments should be assessed for exp [truncated]

MEDIUM Google CVE published 2026-09-09

CVE-2026-87511

A missing authorization vulnerability in Google Chrome's DevTools prior to version 153.0.8010.36 allows remote attackers to obtain cross-origin data via a crafted Chrome extension. This issue, tracked as CVE-2026-87511, has a CVSS score of 4.3 and is classified as Medium severity. The vulnerability impacts environments where DevTools are used or extensions are allowed, emphasizing the need for defenders t [truncated]

MEDIUM Google CVE published 2026-09-09

CVE-2026-87473

CVE-2026-87473 debrief: Google Chrome FileHandling authorization bypass via crafted HTML page. This incorrect authorization vulnerability in FileHandling allows a remote attacker to bypass system access restrictions via social engineering and a crafted HTML page. Defenders should assess exposure and prioritize verification of Chrome version, updating to 153.0.8010.36 or later. The vulnerability has a CVSS [truncated]

MEDIUM Google CVE published 2026-09-09

CVE-2026-87469

CVE-2026-87469 is a medium-severity vulnerability in Google Chrome Extensions, caused by improper input validation, allowing remote attackers to bypass web origin policy via crafted network traffic. The vulnerability affects Google Chrome prior to version 153.0.8010.36 and requires verification of Chrome browser and Extension configurations to ensure they are up-to-date. Defenders should assess exposure a [truncated]

Known exploited Google CVE published 2026-09-09

CVE-2026-87491

Google Chromium V8 Out of Bounds Write Vulnerability debrief. The vulnerability is in the Google Chromium V8 product. Defenders should assess exposure and prioritize patching due to potential for exploitation and possible impact on sensitive data and systems. The CVE record was published on 2026-09-09T00:00:00.000Z and has not been modified since then. This vulnerability is in the CISA Known Exploited Vul [truncated]

CRITICAL Google CVE published 2026-09-08

CVE-2026-49883

CVE-2026-49883 is a critical vulnerability in Google Android, allowing local information disclosure without additional execution privileges. The vulnerability exists in the PermissionsManager.java file, where a missing permission check enables monitoring of sensitive device state data. This issue affects Android versions 14.0, 16.0, and 17.0, and defenders should assess exposure and prioritize patching ac [truncated]