PatchSiren

Google CVE debriefs · Page 44

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Google CVE published 2026-05-14

CVE-2026-8569

CVE-2026-8569 is an out-of-bounds write flaw in Chrome’s code handling on macOS that could let a remote attacker potentially escape the browser sandbox by getting a victim to open a crafted video file. The issue is assigned Chromium security severity Medium, but the NVD-assigned CVSS score is 8.3 (High), so it should be treated as a priority patch for managed Chrome deployments on Mac.

LOW Google CVE published 2026-05-14

CVE-2026-8568

CVE-2026-8568 is a Site Isolation bypass vulnerability in Google Chrome's AI features, rated Low severity (CVSS 3.1). The flaw stems from insufficient policy enforcement that could allow a remote attacker who has already compromised the renderer process to bypass Site Isolation protections using a crafted HTML page. Google has addressed this in Chrome 148.0.7778.168. The vulnerability was published on May [truncated]

MEDIUM Google CVE published 2026-05-14

CVE-2026-8567

CVE-2026-8567 is an integer overflow vulnerability in ANGLE, the graphics layer used by Google Chrome on Windows. The flaw, rated Medium severity with a CVSS score of 4.3, could allow a remote attacker to perform an out-of-bounds memory write by enticing a user to visit a crafted HTML page. The vulnerability was addressed in Chrome version 148.0.7778.168, released on May 12, 2026. The issue was tracked in [truncated]

MEDIUM Google CVE published 2026-05-14

CVE-2026-8566

A medium-severity vulnerability in Google Chrome on Android allows remote attackers to bypass discretionary access controls in the Payments component via a crafted HTML page. The flaw stems from insufficient policy enforcement and affects Chrome versions prior to 148.0.7778.168 on Android. Google has released a stable channel update to address this issue. The vulnerability was published on May 14, 2026, a [truncated]

MEDIUM Google CVE published 2026-05-14

CVE-2026-8565

CVE-2026-8565 is a Medium-severity Chrome issue affecting Mac users running Google Chrome before 148.0.7778.168. According to the CVE description, an attacker who first convinces a user to install a malicious extension may be able to trigger UI spoofing through a crafted Chrome Extension. The CVSS v3.1 vector supplied by NVD is AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:L, which reflects a user-interaction-depende [truncated]

MEDIUM Google CVE published 2026-05-14

CVE-2026-8564

CVE-2026-8564 is a medium-severity Google Chrome flaw that could let a remote attacker use a crafted HTML page to spoof the Downloads security UI in Chrome on Android and Mac. The practical risk is user deception: an attacker may be able to make browser UI appear trustworthy or misleading during download-related interactions. Google addressed the issue in Chrome 148.0.7778.168 and later.

MEDIUM Google CVE published 2026-05-14

CVE-2026-8563

CVE-2026-8563 describes an insufficient policy enforcement issue in Google Chrome’s IFrame Sandbox. A remote attacker could use a crafted HTML page to bypass navigation restrictions, affecting Chrome versions before 148.0.7778.168. Chromium rated the issue Medium, and the CVSS vector indicates network attack, low complexity, no privileges, and user interaction required.

MEDIUM Google CVE published 2026-05-14

CVE-2026-8560

A heap buffer overflow vulnerability in SwiftShader, Google's software-based graphics rendering library used in Chrome, could allow remote attackers to perform out-of-bounds memory reads via crafted HTML pages. The vulnerability affects Google Chrome on macOS and iOS platforms prior to version 148.0.7778.168. SwiftShader serves as a fallback graphics renderer when hardware acceleration is unavailable, mak [truncated]

MEDIUM Google CVE published 2026-05-14

CVE-2026-8559

CVE-2026-8559 is a high-severity integer overflow vulnerability in Google Chrome's Internationalization component on Windows, disclosed by Google on May 14, 2026. The flaw allows remote attackers to perform out-of-bounds memory writes via crafted HTML pages, potentially enabling code execution or browser compromise. Google rated this Chromium security severity as High, though NVD-assigned CVSS 3.1 scoring [truncated]

HIGH Google CVE published 2026-05-14

CVE-2026-8557

CVE-2026-8557 is a use-after-free vulnerability in Google Chrome's Accessibility component, rated High severity by Chromium. The flaw exists in versions prior to 148.0.7778.168 and enables privilege escalation for attackers who have already compromised the renderer process. The vulnerability was published on May 14, 2026, with the NVD record last modified on May 19, 2026. Google addressed this issue in a [truncated]

LOW Google CVE published 2026-05-14

CVE-2026-8556

CVE-2026-8556 is a cross-origin data leak vulnerability in Google Chrome on Windows, stemming from inappropriate implementation in ANGLE (Almost Native Graphics Layer Engine). The flaw allows a remote attacker who has already compromised the renderer process to exfiltrate cross-origin data via a crafted HTML page. Google has assigned this a High severity rating within Chromium's security framework, though [truncated]

HIGH Google CVE published 2026-05-14

CVE-2026-8555

A use-after-free vulnerability in GTK (GIMP Toolkit) within Google Chrome on Windows allows remote code execution via crafted HTML pages. The vulnerability affects Chrome versions prior to 148.0.7778.168. Google has assigned this a High severity rating. The flaw was published by NVD on May 14, 2026, with the record last modified on May 19, 2026. No known exploitation in ransomware campaigns has been docum [truncated]

LOW Google CVE published 2026-05-14

CVE-2026-8554

CVE-2026-8554 is a type confusion vulnerability in ANGLE, the graphics layer used by Google Chrome on Windows. The flaw, rated High severity by Chromium security, allows a remote attacker who has already compromised the renderer process to perform an out-of-bounds memory write via a crafted HTML page. The vulnerability affects Chrome versions prior to 148.0.7778.168 on Windows. The CVSS 3.1 score of 3.1 ( [truncated]

LOW Google CVE published 2026-05-14

CVE-2026-8553

CVE-2026-8553 is a use-after-free vulnerability in the GPU component of Google Chrome, rated High severity by Chromium with a CVSS 3.1 score of 3.1 (Low). The vulnerability affects Chrome versions prior to 148.0.7778.168. A remote attacker who has already compromised the renderer process can exploit this flaw to perform an out-of-bounds memory write via a crafted HTML page. The use-after-free condition (C [truncated]

MEDIUM Google CVE published 2026-05-14

CVE-2026-8552

A heap buffer overflow vulnerability in the GPU component of Google Chrome on Android allows remote attackers to perform out-of-bounds memory writes via crafted HTML pages. The vulnerability, classified with High severity by Chromium security, affects Chrome versions prior to 148.0.7778.168 on Android. The CVSS 3.1 score of 4.3 (Medium) reflects network attack vector with low attack complexity, requiring [truncated]

HIGH Google CVE published 2026-05-14

CVE-2026-8551

Use-after-free vulnerability in Google Chrome's Downloads component enables remote code execution through crafted HTML pages and user interaction.

MEDIUM Google CVE published 2026-05-14

CVE-2026-8550

A use-after-free vulnerability in Google Lens within Google Chrome versions prior to 148.0.7778.168 enables information disclosure from process memory. The flaw requires an attacker to first compromise the renderer process, after which a crafted HTML page can be leveraged to extract potentially sensitive data. The vulnerability is classified as High severity by Chromium and has a CVSS 3.1 score of 6.5 (Me [truncated]

HIGH Google CVE published 2026-05-14

CVE-2026-8549

CVE-2026-8549 is a use-after-free vulnerability in Google Chrome's Media component, rated High severity by Chromium with a CVSS 3.1 score of 8.8. The flaw exists in Chrome versions prior to 148.0.7778.168 and allows a remote attacker to execute arbitrary code within the browser sandbox via a crafted HTML page. The vulnerability was published on May 14, 2026, and last modified on May 19, 2026. The underlyi [truncated]

HIGH Google CVE published 2026-05-14

CVE-2026-8548

## Summary CVE-2026-8548 is a high-severity out-of-bounds write vulnerability in Google Chrome's Media component, affecting versions prior to 148.0.7778.168. A remote attacker who has already compromised the renderer process can exploit this flaw to potentially escape the Chrome sandbox via a crafted HTML page. The vulnerability was published on 2026-05-14 and last modified on 2026-05-19. Google has assig [truncated]

HIGH Google CVE published 2026-05-14

CVE-2026-8547

A high-severity privilege escalation vulnerability in Google Chrome on Windows, published 2026-05-14 and last modified 2026-05-19. Insufficient policy enforcement in the Passwords component allows a remote attacker who has already compromised the renderer process to escalate privileges via a crafted HTML page. Affected versions are prior to 148.0.7778.168 on Windows. The CVSS 3.1 score of 7.5 reflects net [truncated]

MEDIUM Google CVE published 2026-05-14

CVE-2026-8546

CVE-2026-8546 is an out-of-bounds read vulnerability in the GPU component of Google Chrome affecting macOS and Windows platforms. The flaw, rated High severity by Chromium with a CVSS 3.1 score of 5.3 (Medium), was published on 2026-05-14 and last modified on 2026-05-19. The vulnerability allows a remote attacker who has already compromised the renderer process to obtain potentially sensitive information [truncated]

LOW Google CVE published 2026-05-14

CVE-2026-8545

This CVE addresses an object corruption vulnerability in the Compositing component of Google Chrome. The flaw, present in versions prior to 148.0.7778.168, could allow a remote attacker who has already compromised the renderer process to leak cross-origin data through a crafted HTML page. The vulnerability was assigned a High severity rating by Chromium security but received a CVSS 3.1 score of 3.1 (Low) [truncated]

HIGH Google CVE published 2026-05-14

CVE-2026-8544

A use-after-free vulnerability in Google Chrome's Media component, present in versions prior to 148.0.7778.168, enables remote code execution within the browser sandbox. The flaw (CWE-416) can be triggered via a crafted HTML page, with successful exploitation granting an attacker high-impact capabilities across confidentiality, integrity, and availability dimensions. Google has assigned this a High severi [truncated]

MEDIUM Google CVE published 2026-05-14

CVE-2026-8543

CVE-2026-8543 is an out-of-bounds read vulnerability in the FileSystem component of Google Chrome on macOS. The flaw, rated High severity by Chromium security with a CVSS 3.1 score of 5.3 (Medium), was present in versions prior to 148.0.7778.168. A remote attacker could exploit this vulnerability by convincing a user to perform specific UI gestures, potentially allowing extraction of sensitive information [truncated]

HIGH Google CVE published 2026-05-14

CVE-2026-8542

A use-after-free vulnerability in Google Chrome's Core component on Windows allows a remote attacker who has already compromised the renderer process to potentially escape the browser sandbox. The vulnerability stems from improper memory management where freed memory is subsequently accessed, enabling privilege escalation from the renderer process to the host system. This represents a significant security [truncated]

MEDIUM Google CVE published 2026-05-14

CVE-2026-8541

An out-of-bounds read vulnerability in Google Chrome's UI component, present in versions prior to 148.0.7778.168, enables information disclosure from process memory. The vulnerability requires a compromised renderer process and user interaction with a crafted HTML page. Google has assigned this a High severity rating. The vendor field in source data incorrectly lists Apple; the affected product is Google [truncated]

HIGH Google CVE published 2026-05-14

CVE-2026-8540

A type confusion vulnerability in Google Chrome's V8 JavaScript engine, fixed in version 148.0.7778.168, enables remote code execution within the browser sandbox when a user visits a malicious HTML page. The vulnerability carries a CVSS 3.1 score of 8.8 (High severity) and was published by NVD on May 14, 2026, with a subsequent modification on May 19, 2026. The root cause is classified under CWE-843 (Type [truncated]

MEDIUM Google CVE published 2026-05-14

CVE-2026-8539

A Universal Cross-Site Scripting (UXSS) vulnerability in Google Chrome on Android, specifically within the SanitizerAPI component, allowed remote attackers to inject arbitrary scripts or HTML via a crafted HTML page. The vulnerability was present in versions prior to 148.0.7778.168 and has been assigned a High severity rating by Chromium security with a CVSS 3.1 score of 5.4 (MEDIUM). The flaw was publish [truncated]

MEDIUM Google CVE published 2026-05-14

CVE-2026-8538

CVE-2026-8538 is a medium-severity vulnerability in Google Chrome affecting versions prior to 148.0.7778.168. The issue stems from insufficient validation of untrusted input in the GPU component, which could allow a remote attacker who has already compromised the renderer process to cause a denial of service condition through a crafted HTML page. The vulnerability was assigned a CVSS 3.1 score of 5.3 (Med [truncated]

MEDIUM Google CVE published 2026-05-14

CVE-2026-8537

CVE-2026-8537 is a Google Chrome issue in ViewTransitions that could let a remote attacker leak cross-origin data using a crafted HTML page. Google patched the flaw in Chrome 148.0.7778.168 and later. The NVD record lists the issue as CVSS 4.3 (Medium), while Chromium’s referenced security severity is High, so defenders should treat it as a meaningful browser privacy and data-exposure risk even though the [truncated]