These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-8536 is a site isolation bypass vulnerability in Google Chrome's ReadingMode feature on macOS. The flaw stems from insufficient validation of untrusted input, allowing a remote attacker who has already compromised the renderer process to bypass site isolation protections via a crafted HTML page. The vulnerability was assigned a High severity by Chromium security team but received a CVSS 3.1 score [truncated]
CVE-2026-8535 is an out-of-bounds read vulnerability in Google Chrome's media processing component affecting Linux and ChromeOS platforms. The flaw, present in versions prior to 148.0.7778.168, enables a remote attacker who has already compromised the renderer process to extract potentially sensitive information from process memory by supplying a crafted JPEG file. The vulnerability carries a Chromium sec [truncated]
A high-severity integer overflow vulnerability in Google Chrome's GPU component affects Linux and ChromeOS platforms. The flaw, present in versions prior to 148.0.7778.168, enables a sandbox escape when exploited by an attacker who has already compromised the renderer process. The vulnerability requires user interaction and has high attack complexity, but successful exploitation yields complete confidenti [truncated]
CVE-2026-8533 is a use-after-free vulnerability in Google Chrome's Accessibility component, rated HIGH severity (CVSS 8.3). The flaw exists in Chrome versions prior to 148.0.7778.168 and enables a remote attacker who has already compromised the renderer process to potentially escape the browser sandbox via a crafted HTML page. The vulnerability was published on May 14, 2026, with the NVD record last modif [truncated]
## Summary CVE-2026-8532 is a high-severity integer overflow vulnerability in Google Chrome's XML parsing engine. The flaw, present in versions prior to 148.0.7778.168, enables remote code execution within Chrome's sandbox through a crafted HTML page. Google assigned this a Chromium security severity of High and patched it in the May 2026 stable channel update. ## Technical Details The vulnerability stems [truncated]
CVE-2026-8531 is a heap buffer overflow vulnerability in WebML (Web Machine Learning) in Google Chrome on Windows, rated High severity by Chromium with a CVSS 3.1 score of 8.8. The vulnerability affects Chrome versions prior to 148.0.7778.168 and allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. The issue was published on May 14, 2026, and last modified on May 19, 20 [truncated]
Use after free in Network in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
A heap buffer overflow vulnerability in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome on macOS allows remote attackers to potentially escape the browser sandbox via a crafted HTML page. ANGLE is the graphics abstraction layer used by Chrome to translate OpenGL ES API calls to native graphics APIs. The vulnerability was fixed in Chrome version 148.0.7778.168. The CVSS 3.1 score of 8.3 re [truncated]
A use-after-free vulnerability in Google Chrome's Downloads component on macOS allows remote code execution via crafted HTML pages. The vulnerability was assigned Critical severity by Chromium and carries a CVSS 3.1 score of 8.8 (HIGH). The flaw affects Chrome versions prior to 148.0.7778.168 on macOS. Use-after-free vulnerabilities in browser download handling can be triggered when malicious web content [truncated]
CVE-2026-8517 is a critical object lifecycle vulnerability in Google Chrome's WebShare feature on macOS, rated CVSS 8.8 (HIGH). The flaw, published 2026-05-14 and last modified 2026-05-19, allows remote code execution when a user is tricked into performing specific UI gestures on a malicious HTML page. The vulnerability stems from improper resource lifecycle management (CWE-664) in the WebShare implementa [truncated]
A use-after-free vulnerability in the Input component of Google Chrome on Android allows a remote attacker who has already compromised the renderer process to potentially escape the browser sandbox. The vulnerability is classified as Critical severity by Chromium security and carries a CVSS 3.1 score of 8.3 (HIGH). The flaw affects Chrome versions prior to 148.0.7778.168 on Android. Successful exploitatio [truncated]
CVE-2026-2725 is a medium-severity vulnerability in Gerrit, a code review system developed by Google. The vulnerability is caused by incorrect authorization in the 'submitted together' feature, which allows an authenticated attacker with force push permissions on a secondary branch to bypass code review and forcefully submit code to restricted branches. This can be done by crafting a submission that match [truncated]
CVE-2026-7915 is a browser-security issue in Google Chrome described as insufficient data validation in DevTools that could let a remote attacker bypass navigation restrictions using a crafted HTML page. The CVE record was published on 2026-05-06 and later modified on 2026-05-10. Google’s advisory points to a fix in Chrome 148.0.7778.96, and the NVD entry classifies the issue as CVSS 4.3 (Medium) with use [truncated]
CVE-2025-71256 is a high-severity Android issue in the nr modem path where improper input validation can let a remote attacker crash or disrupt service. NVD rates the issue AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, which means it is network-reachable, requires no privileges or user interaction, and can significantly impact availability. The NVD record lists affected Android versions 13 through 16 and points to [truncated]
CVE-2026-7363 is a high-severity vulnerability in Google Chrome on Linux and ChromeOS, caused by a use-after-free issue in the Canvas component. This allows remote code execution via a crafted HTML page. The Chromium security severity is Critical, with a CVSS score of 8.8. Users of Google Chrome on Linux and ChromeOS, particularly those who browse the web and may encounter crafted HTML pages, should be aw [truncated]
CVE-2026-7361 is a high-severity vulnerability in Google Chrome for iOS, allowing remote attackers to potentially exploit heap corruption via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and is classified as HIGH. It is a use-after-free issue in the iOS version of Google Chrome, specifically prior to version 147.0.7727.138. This type of vulnerability occurs when the program attempts to u [truncated]
CVE-2026-7360 is a vulnerability in Google Chrome prior to 147.0.7727.138. Insufficient validation of untrusted input in Compositing allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. This vulnerability has a High severity rating according to Chromium. The affected product is Google Chrome, and the vulnerability class is related to input va [truncated]
CVE-2026-7359 is a high-severity vulnerability in Google Chrome prior to version 147.0.7727.138. The vulnerability is a use-after-free issue in ANGLE, which could allow a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects users of Google Chrome prior to version 147.0.7727.138. It is recommended that users upd [truncated]
CVE-2026-7358 is a high-severity vulnerability in Google Chrome prior to version 147.0.7727.138. The vulnerability is a use-after-free issue in the Animation component, which could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This type of vulnerability typically occurs when the browser attempts to access memory that has already been freed, allowing an attacke [truncated]
CVE-2026-7357 is a high-severity vulnerability in Google Chrome prior to version 147.0.7727.138. The vulnerability is caused by a use-after-free issue in the GPU, which could allow a remote attacker who has compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. This type of vulnerability can lead to significant security risks, including potential data breaches and [truncated]
CVE-2026-7356 is a high-severity vulnerability in Google Chrome prior to version 147.0.7727.138. The vulnerability is caused by a use-after-free issue in the Navigation component, which can be exploited by a remote attacker to execute arbitrary code via a crafted HTML page. This vulnerability affects users of Google Chrome prior to version 147.0.7727.138. Successful exploitation could allow an attacker to [truncated]
CVE-2026-7355 is a use-after-free vulnerability in the Media component of Google Chrome prior to version 147.0.7727.138. This vulnerability could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and a HIGH severity rating. Users of Google Chrome should update to the latest version to mitigate this vulnerability. The vulne [truncated]
CVE-2026-7354 is a vulnerability in Google Chrome prior to version 147.0.7727.138, allowing an out of bounds read and write in Angle, which could enable a remote attacker to potentially perform a sandbox escape via a crafted HTML page. This issue has a high CVSS score of 8.8, indicating significant risk. Users of Google Chrome should update to the latest version to mitigate this vulnerability.
CVE-2026-7353 is a high-severity vulnerability in Google Chrome prior to version 147.0.7727.138. The vulnerability is a heap buffer overflow in Skia, which could allow a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects users of Google Chrome prior to version 147.0.7727.138. The CVSS score for this vulnerabi [truncated]
CVE-2026-7352 is a high-severity vulnerability in Google Chrome on Android prior to 147.0.7727.138. The vulnerability is a use after free in Media, which allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. This type of vulnerability typically occurs when the program attempts to access memory that has already been freed, which [truncated]
CVE-2026-7351 is a race condition vulnerability in MHTML in Google Chrome prior to 147.0.7727.138. An attacker could exploit this vulnerability to leak cross-origin data via a crafted Chrome Extension. The vulnerability has a CVSS score of 3.1 and is considered Low severity. This vulnerability affects users who have installed extensions, particularly those from untrusted sources. Users of Google Chrome pr [truncated]
CVE-2026-7350 is a high-severity vulnerability in Google Chrome prior to version 147.0.7727.138. The vulnerability is a use-after-free issue in WebMIDI, which could allow a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects users of Google Chrome prior to version 147.0.7727.138, and it is recommended that use [truncated]
CVE-2026-7349 is a high-severity vulnerability in Google Chrome prior to version 147.0.7727.138. The vulnerability is a use-after-free issue in the Cast component, which could allow an attacker on the local network segment to execute arbitrary code inside a sandbox via malicious network traffic. The Chromium security severity of this vulnerability is High, with a CVSS score of 7.5. This type of vulnerabil [truncated]
CVE-2026-7348 is a high-severity vulnerability in Google Chrome prior to version 147.0.7727.138. It is caused by a use after free in Codecs, which allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability has significant implications for users of Google Chrome, particularly in environments where the browser is used for critical tasks or handles sensiti [truncated]
CVE-2026-7347 is a high-severity vulnerability in Google Chrome prior to version 147.0.7727.138. The vulnerability is caused by a use after free in Chromoting, which allows a remote attacker to execute arbitrary code via malicious network traffic. This vulnerability has significant implications for users of Google Chrome, particularly in environments where the browser is used for sensitive activities. The [truncated]