These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-7345 is a High-severity vulnerability in Google Chrome prior to version 147.0.7727.138. It involves insufficient validation of untrusted input in Feedback, potentially allowing a remote attacker to perform a sandbox escape via a crafted HTML page. This vulnerability has significant implications for users of Google Chrome, especially those handling sensitive information or requiring high security [truncated]
CVE-2026-7344 is a high-severity vulnerability in Google Chrome on Windows, caused by a use-after-free issue in the Accessibility component. This vulnerability allows a remote attacker to potentially perform a sandbox escape via a crafted web page. The vulnerability has a CVSS score of 8.8 and is considered Critical by the Chromium security team. Affected users should apply the update to version 147.0.772 [truncated]
CVE-2026-7343 is a high-severity vulnerability in Google Chrome on Windows, allowing a remote attacker to potentially perform a sandbox escape via a crafted web page. The vulnerability is caused by a use-after-free issue in the Views component. This vulnerability has a high impact on users of Google Chrome on Windows, as it could allow an attacker to escape the sandbox and potentially execute arbitrary co [truncated]
CVE-2026-7342 is a use-after-free vulnerability in WebView in Google Chrome on Android prior to 147.0.7727.138. This vulnerability allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability is particularly concerning because it can be exploited by a remote attacker through a crafted HTML page, potentially allowing the attacker to execute code within the [truncated]
CVE-2026-7341 is a high-severity vulnerability in Google Chrome prior to version 147.0.7727.138. The vulnerability is caused by a use-after-free issue in WebRTC, which allows remote attackers to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability has significant operational impact due to its high severity score of 8.8 and potential for remote code execution. Users of Google [truncated]
CVE-2026-7339 is a heap buffer overflow vulnerability in WebRTC in Google Chrome prior to version 147.0.7727.138. This vulnerability could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. The Chromium security severity is rated as Medium. The vulnerability affects users of Google Chrome and developers who use WebRTC in their applications. The CVE record and NVD entry [truncated]
CVE-2026-7338 is a high-severity vulnerability in Google Chrome prior to version 147.0.7727.138. The vulnerability is a use-after-free issue in the Cast component, which could allow an attacker on the local network segment to potentially exploit heap corruption via malicious network traffic. This type of vulnerability occurs when a program attempts to use memory after it has been freed, which can lead to [truncated]
CVE-2026-7337 is a High-severity vulnerability in Google Chrome prior to 147.0.7727.138. The vulnerability is caused by a type confusion in the V8 engine, which allows remote attackers to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability has a high CVSS score of 8.8, indicating a significant risk. Users of Google Chrome prior to version 147.0.7727.138 should update to the [truncated]
CVE-2026-7336 is a use-after-free vulnerability in WebRTC in Google Chrome prior to 147.0.7727.138. This vulnerability allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The Chromium security severity is rated as High with a CVSS score of 8.8. The vulnerability affects Google Chrome users, particularly those handling sensitive data or requiring high security stan [truncated]
CVE-2026-7335 is a high-severity vulnerability in Google Chrome prior to version 147.0.7727.138. It is a use-after-free issue in the media component that allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This type of vulnerability occurs when a program tries to use memory after it has been freed, which can lead to unexpected behavior. The vulnerability has been r [truncated]
CVE-2026-7334 is a high-severity vulnerability in Google Chrome on Mac prior to 147.0.7727.138. The vulnerability is a use-after-free issue in the Views component, which could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This type of vulnerability occurs when a program attempts to access memory that has already been freed or deleted. Users of Google Chrome on Mac [truncated]
CVE-2026-7333 is a high-severity use after free vulnerability in Google Chrome's GPU component. This vulnerability potentially allows remote attackers to escape the sandbox via a crafted HTML page. The Chromium security severity is rated as High. Users of Google Chrome prior to version 147.0.7727.138 should update to the latest version to mitigate this vulnerability. The vulnerability exists due to improp [truncated]
An out-of-bounds read vulnerability in the GPU component of Google Chrome on Android, rated CRITICAL (CVSS 9.6), enables sandbox escape from a compromised renderer process. The flaw was addressed in Chrome 147.0.7727.117, released April 2026. Attack complexity is low, requiring only user interaction with a crafted HTML page. No evidence of active exploitation in the wild or ransomware campaign use has bee [truncated]
A use-after-free vulnerability in Google Chrome's DevTools component allows a remote attacker who has already compromised the renderer process to potentially escape the browser sandbox. The vulnerability exists in Chrome versions prior to 147.0.7727.117 and was assigned a High severity by Chromium security. The CVSS 3.1 score of 9.6 reflects network attack vector, low attack complexity, no privileges requ [truncated]
CVE-2026-6364 is an out-of-bounds read vulnerability in Skia, the 2D graphics library used by Google Chrome. The flaw exists in Chrome versions prior to 147.0.7727.101 and allows a remote attacker to obtain potentially sensitive information from process memory by convincing a user to open a crafted file. The vulnerability was assigned a Medium severity rating by Chromium security with a CVSS 3.1 score of [truncated]
A use-after-free vulnerability in Google Chrome's media codecs allows remote attackers to potentially perform out-of-bounds memory access via crafted video files. The vulnerability affects Chrome versions prior to 147.0.7727.101 and was assigned a High severity by Chromium security. The CVSS 3.1 score of 4.3 (Medium) reflects network attack vector with user interaction required. The weakness is categorize [truncated]
A heap buffer overflow vulnerability in PDFium, the PDF rendering engine used by Google Chrome, affects Chrome on Windows versions prior to 147.0.7727.101. The vulnerability requires user interaction through specific UI gestures to trigger exploitation via a crafted PDF file. Successful exploitation allows arbitrary code execution within Chrome's sandboxed renderer process. The Chromium project has assign [truncated]
A use-after-free vulnerability in Google Chrome's FileSystem component, rated High severity by Chromium security, allows remote attackers to potentially exploit object corruption via crafted HTML pages. The vulnerability affects Chrome versions prior to 147.0.7727.101. The use-after-free condition (CWE-416) in browser FileSystem handling presents significant risk as it could enable code execution in the c [truncated]
A use-after-free vulnerability in the Cast component of Google Chrome prior to version 147.0.7727.101 enables remote code execution when a user visits a malicious HTML page. The vulnerability stems from improper memory management in the Cast implementation, where a freed object is subsequently accessed, potentially allowing an attacker to corrupt memory and execute arbitrary code within the browser proces [truncated]
A use-after-free vulnerability in the Permissions component of Google Chrome on Android allows remote code execution through crafted HTML pages when users perform specific UI gestures. The vulnerability affects Chrome versions prior to 147.0.7727.101 on Android devices. Google has assigned this a High severity rating, with a CVSS 3.1 score of 8.8. The issue was initially published on April 15, 2026, and t [truncated]
CVE-2026-6314 is a high-severity out-of-bounds write vulnerability in the GPU component of Google Chrome, affecting versions prior to 147.0.7727.101. The vulnerability was published on April 15, 2026, and last modified on May 26, 2026. A remote attacker who has already compromised the GPU process could exploit this flaw to potentially escape the Chrome sandbox via a crafted HTML page. The Chromium securit [truncated]
A use-after-free vulnerability in Google Chrome's Viz compositor (CVE-2026-6309) enables sandbox escape from a compromised renderer process. The flaw was patched in Chrome 147.0.7727.101, released April 15, 2026. No known exploitation in the wild has been confirmed, and the vulnerability is not listed in CISA KEV.
CVE-2026-6308 is a high-severity out-of-bounds read vulnerability in Google Chrome's Media component, rated CVSS 7.5. The flaw exists in Chrome versions prior to 147.0.7727.101 and requires user interaction through specific UI gestures to trigger. A remote attacker could exploit this via a crafted HTML page to achieve arbitrary code execution. The vulnerability was disclosed on April 15, 2026, with the NV [truncated]
A heap buffer overflow vulnerability in PDFium, the PDF rendering engine used by Google Chrome, allows remote code execution via crafted PDF files. The vulnerability affects Chrome versions prior to 147.0.7727.101 and carries a High severity rating from the Chromium security team. The CVSS 3.1 score of 8.8 reflects network attack vector, low attack complexity, no privileges required, and high impacts to c [truncated]
A use-after-free vulnerability in the Graphite font rendering library within Google Chrome enables sandbox escape from a compromised renderer process. The flaw was addressed in Chrome 147.0.7727.101, released April 2026. The CVSS 3.1 score of 8.3 reflects high impact across confidentiality, integrity, and availability, with attack complexity rated as high due to the prerequisite renderer compromise. No kn [truncated]
A use-after-free vulnerability in Google Chrome's Video component prior to version 147.0.7727.101 enables remote code execution within the browser sandbox. The flaw, assigned CVSS 3.1 score 8.8 (High), can be triggered when a victim visits a maliciously crafted HTML page. The vulnerability was disclosed by Google on April 15, 2026, with the NVD record subsequently modified on May 26, 2026. No known exploi [truncated]
A type confusion vulnerability in Google Chrome's Turbofan JavaScript compiler engine allows remote code execution via malicious HTML pages. The flaw affects Chrome versions prior to 147.0.7727.101 and carries a High severity rating from Chromium security. Type confusion in JIT compilers typically occurs when the engine incorrectly handles object types during optimization passes, leading to out-of-bounds [truncated]
A use-after-free vulnerability in the CSS processing component of Google Chrome versions prior to 147.0.7727.101 enables remote code execution within the browser sandbox. The flaw, assigned CVSS 3.1 score 8.8 (High), can be triggered when a victim renders a maliciously crafted HTML page. The vulnerability was disclosed by Google on April 15, 2026, with the NVD record subsequently modified on May 26, 2026. [truncated]
A use-after-free vulnerability in Google Chrome's Prerender feature allows remote code execution via crafted HTML pages. The vulnerability affects Chrome versions prior to 147.0.7727.101 and carries a Critical severity rating from Chromium security. The use-after-free condition (CWE-416) in the Prerender component could enable an attacker to corrupt memory and execute arbitrary code in the context of the [truncated]
A critical heap buffer overflow vulnerability in ANGLE, the graphics layer used by Google Chrome, enables remote attackers to potentially escape the browser sandbox through malicious HTML content. The flaw resides in Chrome versions prior to 147.0.7727.101 and carries a CVSS 3.1 score of 9.6, reflecting severe impact across confidentiality, integrity, and availability with low attack complexity. ANGLE (Al [truncated]