PatchSiren

Google CVE debriefs · Page 41

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Google CVE published 2026-05-28

CVE-2026-9905

A use-after-free vulnerability in Google Chrome's Accessibility subsystem on Windows allows a remote attacker who has already compromised the renderer process to potentially escape the browser sandbox. The vulnerability is classified as High severity by Chromium security standards. The issue affects Chrome versions prior to 148.0.7778.216 on Windows platforms. Successful exploitation requires prior compro [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9904

A use-after-free vulnerability in ANGLE, the graphics layer used by Google Chrome, was patched in Chrome 148.0.7778.216. The flaw could allow a remote attacker to potentially escape the browser sandbox via a crafted HTML page. Google rated this vulnerability as High severity. The issue was reported to the Chromium project and fixed in the stable channel release on May 28, 2026.

MEDIUM Google CVE published 2026-05-28

CVE-2026-9903

CVE-2026-9903 is a high-severity Site Isolation bypass in Google Chrome affecting versions prior to 148.0.7778.216. The vulnerability stems from insufficient validation of untrusted input in Chrome's Site Isolation mechanism, allowing a remote attacker who has already compromised the renderer process to bypass site isolation protections via a crafted MHTML page. Site Isolation is a critical security bound [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9902

A use-after-free vulnerability in Google Chrome's Accessibility component, rated High severity by Chromium security, enables sandbox escape from a compromised renderer process. The flaw was addressed in Chrome 148.0.7778.216.

HIGH Google CVE published 2026-05-28

CVE-2026-9901

A use-after-free vulnerability in ANGLE, the graphics translation layer used by Google Chrome, was patched in Chrome 148.0.7778.216. The flaw allowed a remote attacker who had already compromised the renderer process to execute arbitrary code via a crafted HTML page. ANGLE (Almost Native Graphics Layer Engine) translates OpenGL ES API calls to native graphics APIs, making this vulnerability exploitable th [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9900

CVE-2026-9900 is an out-of-bounds write vulnerability in ANGLE, the graphics layer used by Google Chrome. The flaw was present in Chrome versions prior to 148.0.7778.216 and carries a Chromium security severity rating of High. Successful exploitation requires an attacker to have already compromised the renderer process, after which a crafted HTML page could be leveraged to potentially escape the Chrome sa [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9899

A use-after-free vulnerability in ANGLE, the graphics translation layer used by Google Chrome, was addressed in Chrome 148.0.7778.216. The flaw could allow a remote attacker who has already compromised the renderer process to potentially escape the Chrome sandbox via a crafted HTML page. ANGLE (Almost Native Graphics Layer Engine) translates OpenGL ES API calls to native graphics APIs, making this vulnera [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9898

CVE-2026-9898 is a high-severity sandbox escape vulnerability in Google Chrome on Android, affecting versions prior to 148.0.7778.216. The flaw stems from insufficient validation of untrusted input in the GPU component, enabling a remote attacker who has already compromised the renderer process to escape the browser sandbox via a crafted HTML page. This vulnerability was published in the NVD on 2026-05-28 [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9897

A use-after-free vulnerability in the DOM implementation of Google Chrome prior to version 148.0.7778.216 enables remote code execution within the browser sandbox. The flaw, assigned CWE-416 and rated High severity by Chromium, can be triggered by a crafted HTML page. Google addressed this issue in a stable channel update released May 28, 2026.

HIGH Google CVE published 2026-05-28

CVE-2026-9896

CVE-2026-9896 is an out-of-bounds write vulnerability in the V8 JavaScript engine used by Google Chrome. The flaw, rated High severity by Chromium security, affects Chrome versions prior to 148.0.7778.216. A remote attacker can exploit this vulnerability by convincing a user to visit a crafted HTML page, potentially leading to arbitrary code execution within the Chrome sandbox. The vulnerability was discl [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9895

CVE-2026-9895 is an out-of-bounds read vulnerability in the GPU component of Google Chrome, affecting versions prior to 148.0.7778.216. The vulnerability was assigned a High severity rating by the Chromium security team. A remote attacker who has already compromised the renderer process could exploit this flaw to potentially escape the Chrome sandbox via a crafted HTML page. The vulnerability is classifie [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9894

A use-after-free vulnerability in Google Chrome's GPU component, fixed in version 148.0.7778.216, could allow a remote attacker who has already compromised the renderer process to potentially escape the browser sandbox. The vulnerability is classified as High severity by Chromium security standards. The use-after-free weakness (CWE-416) in GPU processing creates a memory corruption condition that can be t [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9893

A critical use-after-free vulnerability in Skia, the 2D graphics library used by Google Chrome, enables sandbox escape from a compromised renderer process. The flaw affects Chrome versions prior to 148.0.7778.216. A remote attacker who has already achieved renderer compromise can leverage this vulnerability to escape the Chrome sandbox via a crafted HTML page. The vulnerability was assigned CWE-416 (Use A [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9892

CVE-2026-9892 is a critical-severity inappropriate implementation vulnerability in Skia, the 2D graphics library used by Google Chrome on Android. The flaw, present in versions prior to 148.0.7778.216, enables a remote attacker who has already compromised the renderer process to potentially escape the Chrome sandbox via a crafted HTML page. This represents a significant elevation of privilege risk, as san [truncated]

CRITICAL Google CVE published 2026-05-28

CVE-2026-9891

A critical use-after-free vulnerability in Google Chrome's Extensions subsystem allows sandbox escape from a compromised renderer process. The flaw (CWE-416) affects Chrome versions prior to 148.0.7778.216. An attacker who has already achieved renderer compromise can leverage this vulnerability to escape the Chrome sandbox by manipulating extension objects after they have been freed. Google has assigned C [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9890

A critical use-after-free vulnerability in Chrome's XR (Extended Reality) subsystem on Windows enables sandbox escape from a compromised renderer process. The flaw involves improper memory management where freed XR objects remain accessible, allowing attackers to escalate privileges beyond the renderer sandbox. This affects Chrome versions prior to 148.0.7778.216. The vulnerability requires initial render [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9889

A critical-severity out-of-bounds read and write vulnerability in Dawn (WebGPU implementation) in Google Chrome on Android prior to version 148.0.7778.216. The flaw allows a remote attacker to potentially escape the browser sandbox via a crafted HTML page. The vulnerability was published in the NVD on 2026-05-28 and modified on 2026-05-29. Chrome's stable channel update addresses this issue. No known expl [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9888

A critical use-after-free vulnerability in WebView on Google Chrome for Android, disclosed 2026-05-28, enables sandbox escape from a compromised renderer process. The flaw (CWE-416) affects versions prior to 148.0.7778.216. No known exploitation in the wild has been confirmed.

HIGH Google CVE published 2026-05-28

CVE-2026-9887

A critical use-after-free vulnerability in Google Chrome's Proxy component, triggered by crafted PAC (Proxy Auto-Configuration) scripts, enables remote code execution. The flaw resides in how Chrome handles memory management during proxy configuration processing. Attackers can exploit this by delivering malicious PAC scripts through network positioning or compromised infrastructure. The vulnerability affe [truncated]

CRITICAL Google CVE published 2026-05-28

CVE-2026-9886

A use-after-free vulnerability in Google Chrome's Base component on macOS, rated Critical by Chromium security, allows remote attackers to potentially escape the browser sandbox via crafted HTML. The vulnerability was addressed in Chrome 148.0.7778.216. Use-after-free (CWE-416) occurs when memory is accessed after being freed, enabling memory corruption that can subvert security boundaries like the sandbo [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9885

A critical-severity sandbox escape vulnerability in Google Chrome on macOS, caused by insufficient validation of untrusted input in the browser's UI components. The flaw allows a remote attacker who has already compromised the renderer process to escape the Chrome sandbox via a crafted HTML page. This represents a significant elevation of privilege, as the renderer process is designed to run in a restrict [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9884

A critical use-after-free vulnerability in Google Chrome's Browser component on macOS allows remote code execution via crafted HTML. The flaw was patched in Chrome 148.0.7778.216. No known exploitation in ransomware campaigns has been reported.

HIGH Google CVE published 2026-05-28

CVE-2026-9883

A critical use-after-free vulnerability in Google Chrome's Base component, addressed in version 148.0.7778.216, enables remote code execution through crafted HTML pages. The vulnerability stems from improper memory management (CWE-416) where freed memory is subsequently accessed, potentially allowing attackers to execute arbitrary code in the context of the browser process. Chrome's Stable Channel update [truncated]

MEDIUM Google CVE published 2026-05-28

CVE-2026-9882

Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Critical)

CRITICAL Google CVE published 2026-05-28

CVE-2026-9881

A critical use-after-free vulnerability in Google Chrome's Bluetooth subsystem on macOS, fixed in version 148.0.7778.216. The flaw could enable sandbox escape via malicious Chrome extension installation.

HIGH Google CVE published 2026-05-28

CVE-2026-9880

CVE-2026-9880 is a critical-severity vulnerability in Google Chrome's WebGL implementation, disclosed on 2026-05-28. Insufficient validation of untrusted input in WebGL allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The vulnerability was addressed in Chrome version 148.0.7778.216. The Chromium project assigned this issue [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9879

A critical out-of-bounds write vulnerability in ANGLE, the graphics translation layer used by Google Chrome, enables remote code execution through crafted HTML content. ANGLE (Almost Native Graphics Layer Engine) translates OpenGL ES API calls to native graphics APIs, making this vulnerability exploitable during GPU-accelerated rendering operations. The flaw was resolved in Chrome 148.0.7778.216. The Chro [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9878

A use-after-free vulnerability in ANGLE, the graphics rendering layer used by Google Chrome, allows remote code execution within the browser sandbox when processing crafted HTML content. ANGLE (Almost Native Graphics Layer Engine) translates OpenGL ES API calls to native graphics APIs, making this vulnerability reachable through standard web browsing. The use-after-free condition in memory management enab [truncated]

HIGH Google CVE published 2026-05-28

CVE-2026-9877

A critical use-after-free vulnerability in ANGLE, the graphics layer used by Google Chrome, enables sandbox escape from a compromised renderer process. The flaw was addressed in Chrome 148.0.7778.216. No active exploitation in the wild has been confirmed at time of publication.

CRITICAL Google CVE published 2026-05-28

CVE-2026-9876

A critical use-after-free vulnerability in WebGL on Google Chrome for Android prior to version 148.0.7778.216 enables remote attackers to potentially escape the browser sandbox via a crafted HTML page. The vulnerability stems from improper memory management in the WebGL implementation, where a freed memory object is subsequently accessed, leading to memory corruption that can be leveraged for sandbox esca [truncated]