These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
An out-of-bounds read vulnerability in WebGL on Google Chrome for Android prior to version 148.0.7778.216 enables remote attackers to potentially escape the browser sandbox via a crafted HTML page. The Chromium security team has assigned this a Critical severity rating. The vulnerability stems from improper bounds checking in WebGL component code (CWE-125), which could allow memory corruption leading to s [truncated]
A critical use-after-free vulnerability in Dawn, the WebGPU implementation in Google Chrome, enables potential sandbox escape via crafted HTML pages. The flaw was addressed in Chrome 148.0.7778.216. Dawn is Chrome's native WebGPU implementation that provides GPU acceleration for web applications. Use-after-free vulnerabilities in browser GPU subsystems are particularly dangerous as they can bridge the gap [truncated]
A critical use-after-free vulnerability in Google Chrome's Network component, present in versions prior to 148.0.7778.216, enables remote code execution within the browser sandbox when a user visits a malicious HTML page. The vulnerability stems from improper memory management (CWE-416), where a freed memory object is subsequently accessed, potentially allowing an attacker to corrupt memory and execute ar [truncated]
A critical out-of-bounds write vulnerability in the GPU component of Google Chrome on Android, disclosed 2026-05-28, enables remote sandbox escape via crafted HTML. The flaw (CWE-787) affects Chrome versions prior to 148.0.7778.216. No known exploitation in ransomware campaigns has been reported.
Type Confusion in V8 in Google Chrome prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Medium)
CVE-2026-10021 is a medium-severity vulnerability in Google Chrome affecting versions prior to 148.0.7778.216. The flaw stems from insufficient validation of untrusted input in the browser's USB subsystem, enabling remote code execution when a user visits a malicious HTML page. The vulnerability was disclosed on May 28, 2026, with Google releasing a stable channel update to address the issue. The root cau [truncated]
A medium-severity vulnerability in Google Chrome on Android, published 2026-05-28, stems from insufficient validation of untrusted input in the Skia graphics library. A remote attacker who has already compromised the renderer process could leverage this flaw to potentially escape the Chrome sandbox via a crafted HTML page. The vulnerability is classified as CWE-20 (Improper Input Validation) and affects C [truncated]
CVE-2026-10019 is an integer overflow vulnerability in ANGLE, the graphics layer used by Google Chrome, affecting versions prior to 148.0.7778.216. The flaw enables a remote attacker to leak cross-origin data through a crafted HTML page. ANGLE (Almost Native Graphics Layer Engine) translates OpenGL ES API calls to native graphics APIs, making this vulnerability relevant to browser-based graphics processin [truncated]
An integer overflow vulnerability in ANGLE, the graphics layer used by Google Chrome, could allow a remote attacker to extract potentially sensitive information from process memory by tricking a user into visiting a crafted HTML page. The vulnerability was addressed in Chrome version 148.0.7778.216. The Chromium security team rated this issue as Medium severity. The underlying weakness is categorized as C [truncated]
Out-of-bounds read in Google Chrome Headless component prior to version 148.0.7778.216. A remote attacker who has already compromised the renderer process can exploit this vulnerability to potentially escape the Chrome sandbox via a crafted HTML page. The vulnerability is classified as Medium severity by Chromium security. The issue was disclosed on 2026-05-28 with CVE publication and modification timesta [truncated]
A use-after-free vulnerability in Google Chrome's DOM implementation prior to version 148.0.7778.216 allows remote attackers to execute arbitrary code within the browser sandbox via a crafted HTML page. The vulnerability stems from improper memory management in the Document Object Model (DOM), where a freed memory object is subsequently accessed, potentially leading to memory corruption and code execution [truncated]
CVE-2026-10015 is an integer overflow vulnerability in the WTF (Web Template Framework) component of Google Chrome, affecting versions prior to 148.0.7778.216. The vulnerability was assigned a High severity rating by the Chromium security team. An integer overflow in WTF could allow a remote attacker to execute arbitrary code within the Chrome sandbox by enticing a user to visit a crafted HTML page. The v [truncated]
A use-after-free vulnerability in WebMIDI on Google Chrome for Android prior to version 148.0.7778.216 enables sandbox escape from a compromised renderer process. The flaw, classified as CWE-416, carries Chromium's High severity rating. Successful exploitation requires an attacker to first compromise the renderer process, after which a crafted HTML page can trigger the memory corruption to break out of th [truncated]
A use-after-free vulnerability in Google Chrome's WebCodecs API, fixed in version 148.0.7778.216, enables remote code execution within the browser sandbox when processing malicious HTML content. The vulnerability stems from improper memory management in WebCodecs, a browser API for encoding and decoding audio and video. Google has assigned this a High severity rating. No known exploitation in the wild has [truncated]
A use-after-free vulnerability in Skia, the 2D graphics library used by Google Chrome, was addressed in Chrome version 148.0.7778.216. The flaw could allow a remote attacker who has already compromised the renderer process to potentially escape the Chrome sandbox through a crafted HTML page. Google assigned this a High severity rating. The vulnerability was published to the CVE database on May 28, 2026, w [truncated]
## Summary CVE-2026-10011 is a High-severity inappropriate implementation vulnerability in Skia, the 2D graphics library used by Google Chrome. The flaw, present in Chrome versions prior to 148.0.7778.216, enables a remote attacker who has already compromised the renderer process to leak cross-origin data through a crafted HTML page. The vulnerability was published on 2026-05-28. ## Technical Details The [truncated]
CVE-2026-10010 is a site isolation bypass vulnerability in Google Chrome on Android, published 2026-05-28. The flaw stems from inappropriate implementation in Input handling, allowing a remote attacker who has already compromised the renderer process to bypass site isolation protections via a crafted HTML page. Google has assigned this a High severity rating. The vulnerability affects Chrome on Android ve [truncated]
An integer overflow vulnerability in Skia, the 2D graphics library used by Google Chrome, could allow a remote attacker who has already compromised the renderer process to execute arbitrary code within the Chrome sandbox. The vulnerability was present in Chrome versions prior to 148.0.7778.216. Google has assigned this a High severity rating per Chromium security guidelines. The attack vector requires a c [truncated]
A high-severity uninitialized memory vulnerability in Google Chrome's GPU component on Android allows remote attackers to extract potentially sensitive information from process memory via a crafted HTML page. The flaw, classified as CWE-457 (Use of Uninitialized Variable), affects Chrome versions prior to 148.0.7778.216 on Android. The vulnerability was disclosed on May 28, 2026, with fixes available in t [truncated]
A use-after-free vulnerability in SVG processing within Google Chrome versions prior to 148.0.7778.216 enables remote code execution inside the browser sandbox. The flaw, rated High severity by Chromium security, can be triggered when a victim visits a malicious HTML page containing crafted SVG content. Use-after-free conditions occur when memory is freed but a pointer continues to reference it, allowing [truncated]
A race condition vulnerability in WebAudio within Google Chrome versions prior to 148.0.7778.216 enables remote code execution inside the browser sandbox. The flaw stems from concurrent access to shared WebAudio resources without proper synchronization, classified as CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization). Google has rated this vulnerability as High severity. Th [truncated]
A use-after-free vulnerability in Google Chrome's WebAppInstalls component on macOS allows remote code execution through crafted HTML pages when users perform specific UI gestures. The vulnerability affects Chrome versions prior to 148.0.7778.216 and has been assigned a High severity rating by the Chromium security team. Use-after-free vulnerabilities occur when a program continues to use a pointer after [truncated]
CVE-2026-10004 is a high-severity UI spoofing vulnerability in Google Chrome's Passwords feature, affecting versions prior to 148.0.7778.216. The flaw stems from insufficient validation of untrusted input (CWE-20), allowing a remote attacker to craft a malicious HTML page that can spoof the browser's password interface. This could potentially deceive users into entering credentials into attacker-controlle [truncated]
A use-after-free vulnerability in Google Chrome's Views component, addressed in version 148.0.7778.216. The flaw could allow remote code execution when a user performs specific UI gestures on a malicious HTML page. Google has rated this as High severity. The vulnerability was disclosed on May 28, 2026, with Chrome's stable channel update.
A use-after-free vulnerability in PDFium, the PDF rendering engine embedded in Google Chrome, was patched in Chrome version 148.0.7778.216. The flaw, rated High severity by Chromium security, could allow remote attackers to trigger heap corruption through a maliciously crafted PDF document. Use-after-free conditions in browser engines typically enable memory corruption that can lead to arbitrary code exec [truncated]
A use-after-free vulnerability in Google Chrome's PerformanceManager component, present in versions prior to 148.0.7778.216, enables a remote attacker who has already compromised the renderer process to potentially escape the browser sandbox. The vulnerability was assigned a High severity rating by the Chromium security team. The use-after-free condition (CWE-416) occurs when memory is accessed after it h [truncated]
A use-after-free vulnerability in Google Chrome's Passwords component on Windows, fixed in version 148.0.7778.216, could allow a remote attacker with renderer process compromise to potentially escape the sandbox. The Chromium project rates this as High severity. The vulnerability stems from improper memory management (CWE-416) in the password handling code, where freed memory may be accessed, enabling fur [truncated]
CVE-2026-9739 is a critical DNS rebinding vulnerability affecting the MCP Toolbox SSE implementation. The issue stems from a hardcoded `Access-Control-Allow-Origin: *` header that was inadvertently retained during beta-phase security hardening, despite the introduction of `allowed-origins` and `allowed-hosts` flags intended to align with MCP security guidelines. This vulnerability specifically impacts use [truncated]
CVE-2026-9126 is a Google Chrome browser vulnerability in the DOM that can be triggered by a crafted HTML page. The issue is a use-after-free (CWE-416) and was fixed in Chrome 148.0.7778.179 and later. The CVE metadata assigns a high CVSS score (8.8) with network access and user interaction required, and the Chromium severity note is Medium. Because the flaw can lead to arbitrary code execution inside the [truncated]
CVE-2026-9124 is a Medium-severity Google Chrome issue involving insufficient validation of untrusted input in Input. According to the CVE description, a remote attacker who had already compromised the renderer process could use a crafted HTML page to leak cross-origin data. The issue is reported as fixed in Chrome 148.0.7778.179 and earlier versions are affected.