These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-9935 is a high-severity uninitialized use vulnerability in ANGLE, the graphics layer used by Google Chrome. The flaw affects Chrome versions prior to 148.0.7778.216 and enables remote attackers to leak cross-origin data through a crafted HTML page. The vulnerability stems from improper initialization of memory (CWE-457), which can result in information disclosure when processing malicious web con [truncated]
A use-after-free vulnerability in Google Chrome's Aura UI framework allows remote code execution when a user performs specific UI gestures on a malicious HTML page. The vulnerability affects Chrome versions prior to 148.0.7778.216 and has been assigned High severity by the Chromium security team. Use-after-free vulnerabilities occur when a program continues to use a pointer after the memory it references [truncated]
Use-after-free in Chrome Input handling enables remote heap corruption via crafted HTML and specific UI gestures. Google rated High severity. No known exploitation in the wild (not in CISA KEV). Patch available in Chrome 148.0.7778.216.
CVE-2026-9932 is a use-after-free vulnerability in ANGLE, the graphics layer used by Google Chrome on Windows. The flaw was present in versions prior to 148.0.7778.216 and could allow a remote attacker who has already compromised the renderer process to potentially escape the Chrome sandbox. The Chromium security team rated this vulnerability as High severity. The underlying weakness is CWE-416 (Use After [truncated]
A use-after-free vulnerability in Google Chrome's GPU component, fixed in version 148.0.7778.216, could allow a remote attacker who has already compromised the renderer process to potentially escape the browser sandbox. The vulnerability carries a High severity rating from the Chromium security team. The use-after-free weakness (CWE-416) in GPU processing creates a memory corruption condition that, when c [truncated]
CVE-2026-9930 is an out-of-bounds write vulnerability in Dawn, the WebGPU implementation in Google Chrome on macOS. The flaw, rated High severity by Chromium security, was present in versions prior to 148.0.7778.216 and could be exploited by a remote attacker via a crafted HTML page to perform out-of-bounds memory writes. The vulnerability was disclosed on May 28, 2026, with the CVE record modified the fo [truncated]
A high-severity inappropriate implementation vulnerability in WebGL on Google Chrome for Android prior to version 148.0.7778.216 enables remote attackers to leak cross-origin data through a crafted HTML page. The flaw stems from improper handling of WebGL operations that violate same-origin policy protections. This vulnerability was disclosed by Google on May 28, 2026, with an update issued the following [truncated]
An out-of-bounds read vulnerability in ANGLE, the graphics translation layer used by Google Chrome on Windows, enables remote code execution when a user visits a crafted HTML page. The flaw carries a High severity rating from the Chromium security team and an 8.8 CVSS v3.1 score, reflecting network attackability with low complexity and no privileges required, though user interaction is needed. The vulnera [truncated]
A use-after-free vulnerability in ANGLE, the graphics layer used by Google Chrome, was addressed in Chrome version 148.0.7778.216. The flaw could allow a remote attacker to execute arbitrary code within the browser sandbox by enticing a user to visit a crafted HTML page. Google has rated this vulnerability as High severity. The underlying weakness is CWE-416 (Use After Free). Organizations should prioriti [truncated]
A heap buffer overflow vulnerability in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome versions prior to 148.0.7778.216 enables sandbox escape from a compromised renderer process. ANGLE is Chrome's graphics translation layer that converts OpenGL ES API calls to native graphics APIs (Direct3D, Metal, Vulkan, or desktop OpenGL). The vulnerability requires prior compromise of the renderer p [truncated]
A use-after-free vulnerability in ANGLE, the graphics translation layer used by Google Chrome, could allow a remote attacker who has already compromised the renderer process to potentially escape the browser sandbox. The vulnerability affects Chrome versions prior to 148.0.7778.216. ANGLE (Almost Native Graphics Layer Engine) translates OpenGL ES API calls to native graphics APIs, making this a critical c [truncated]
A heap buffer overflow vulnerability in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome on Windows could enable a remote attacker who has already compromised the renderer process to potentially escape the Chrome sandbox. The vulnerability was addressed in Chrome stable channel version 148.0.7778.216, released May 28, 2026. ANGLE is a graphics abstraction layer used by Chrome to translate [truncated]
A use-after-free vulnerability in Skia, the 2D graphics library used by Google Chrome, could allow remote attackers to exploit heap corruption via a crafted HTML page. The vulnerability was assigned High severity by the Chromium security team and affects Chrome versions prior to 148.0.7778.216. The flaw resides in Skia's memory management, where a freed object may be accessed, leading to potential code ex [truncated]
A use-after-free vulnerability in the GPU component of Google Chrome on macOS, fixed in version 148.0.7778.216. The flaw allowed a remote attacker who had already compromised the renderer process to execute arbitrary code via a crafted HTML page. The vulnerability carries a High severity rating per Chromium's security classification. The underlying weakness is CWE-416 (Use After Free), a memory safety iss [truncated]
CVE-2026-9921 is a high-severity uninitialized use vulnerability in WebGL affecting Google Chrome on Android versions prior to 148.0.7778.216. The flaw allows a remote attacker to leak cross-origin information through a crafted HTML page. The vulnerability stems from improper initialization of memory in the WebGL implementation (CWE-457), which can be exploited to read uninitialized data that may contain [truncated]
A high-severity uninitialized memory vulnerability in Google Chrome's GPU component on Android enables cross-origin data leakage from a compromised renderer process. The flaw stems from use of uninitialized memory (CWE-457) in GPU operations, allowing an attacker who has already achieved renderer compromise to exfiltrate data from other origins. This vulnerability is specific to Chrome on Android versions [truncated]
CVE-2026-9919 is an out-of-bounds read vulnerability in WebGL affecting Google Chrome on Android versions prior to 148.0.7778.216. The vulnerability allows a remote attacker to leak cross-origin data through a crafted HTML page. Google has assigned this a High severity rating. The issue was published to the CVE database on May 28, 2026, with a subsequent modification on May 29, 2026. The vulnerability is [truncated]
A sandbox escape vulnerability in Google Chrome's Tint component, rated High severity by Chromium security, was disclosed on May 28, 2026. The flaw stems from inappropriate implementation in Tint and could allow a remote attacker to escape the browser sandbox via a crafted HTML page. Chrome versions prior to 148.0.7778.216 are affected. The vulnerability was addressed in the stable channel update released [truncated]
CVE-2026-9917 is a high-severity uninitialized use vulnerability in WebGL affecting Google Chrome on Android versions prior to 148.0.7778.216. The flaw allows a remote attacker to extract potentially sensitive information from process memory by tricking a user into visiting a crafted HTML page. The vulnerability stems from improper initialization of memory in the WebGL implementation (CWE-457), which can [truncated]
CVE-2026-9916 is an out-of-bounds write vulnerability in ANGLE, the graphics layer used by Google Chrome. The flaw exists in versions prior to 148.0.7778.216 and was assigned High severity by the Chromium security team. A remote attacker who has already compromised the renderer process can exploit this vulnerability to potentially escape the Chrome sandbox via a crafted HTML page. The vulnerability was pu [truncated]
A heap buffer overflow vulnerability in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome versions prior to 148.0.7778.216 enables sandbox escape from a compromised renderer process. ANGLE is the graphics translation layer that converts OpenGL ES API calls to native graphics APIs (DirectX, Metal, Vulkan) on Windows, macOS, and Linux. The vulnerability requires prior compromise of the render [truncated]
A sandbox escape vulnerability in Google Chrome's ANGLE graphics layer, rated High severity by Chromium. The flaw stems from insufficient validation of untrusted input, enabling a remote attacker who has already compromised the renderer process to escape the sandbox via a crafted HTML page. The vulnerability was addressed in Chrome 148.0.7778.216.
A vulnerability in Google Chrome's ANGLE graphics layer could allow remote attackers to trigger out-of-bounds memory access through malicious HTML content. ANGLE (Almost Native Graphics Layer Engine) translates OpenGL ES API calls to platform-native graphics APIs, making this a browser rendering pipeline issue. The flaw was addressed in Chrome 148.0.7778.216. The Chromium security team rated this High sev [truncated]
CVE-2026-9912 is an information disclosure vulnerability in Google Chrome on Android, rated High severity by Chromium. The flaw stems from inappropriate implementation in the GPU component, allowing a remote attacker to extract potentially sensitive information from process memory by enticing a user to visit a crafted HTML page. The vulnerability affects Chrome on Android versions prior to 148.0.7778.216. [truncated]
Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
CVE-2026-9910 is a high-severity out-of-bounds memory access vulnerability in ANGLE, the graphics layer used by Google Chrome. The flaw affects Chrome versions prior to 148.0.7778.216 and enables remote code execution within the browser sandbox when a user visits a malicious HTML page. ANGLE (Almost Native Graphics Layer Engine) translates OpenGL ES API calls to native graphics APIs, making this vulnerabi [truncated]
Integer overflow in Skia graphics library within Google Chrome versions prior to 148.0.7778.216 enables arbitrary code execution inside the sandbox from a compromised renderer process. The vulnerability is triggered via a crafted HTML page. Google has assigned High severity. The fix was released in the Stable channel update for desktop on May 28, 2026. No known exploitation in ransomware campaigns has been reported.
CVE-2026-9908 is an out-of-bounds read vulnerability in ANGLE, the graphics layer used by Google Chrome. The flaw exists in Chrome versions prior to 148.0.7778.216 and allows a remote attacker to extract potentially sensitive information from process memory by convincing a user to visit a crafted HTML page. The Chromium security team has assigned this a High severity rating. The vulnerability was disclose [truncated]
An out-of-bounds read vulnerability in Dawn, the WebGPU implementation in Google Chrome on Windows, enables remote attackers to leak cross-origin data through a crafted HTML page. The vulnerability was assigned High severity by the Chromium security team and affects Chrome versions prior to 148.0.7778.216. The root cause is an out-of-bounds read condition (CWE-125) in the Dawn graphics subsystem, which co [truncated]
CVE-2026-9906 is an out-of-bounds write vulnerability in the GPU component of Google Chrome, affecting versions prior to 148.0.7778.216. The vulnerability was assigned a High severity rating by Chromium security. The flaw allows a remote attacker who has already compromised the renderer process to potentially escape the Chrome sandbox through a crafted HTML page. This represents a significant security con [truncated]