These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-5919 is a vulnerability in Google Chrome prior to version 147.0.7727.55, caused by insufficient validation of untrusted input in WebSockets. This allows a remote attacker who has compromised the renderer process to bypass same origin policy via a crafted HTML page. The Chromium security severity is rated as Low, with a CVSS score of 6.5 and a MEDIUM severity rating. The vulnerability affects user [truncated]
CVE-2026-5918 is a low-severity vulnerability in Google Chrome's Navigation feature. It allows a remote attacker who has compromised the renderer process to leak cross-origin data via a crafted HTML page. This vulnerability was addressed in Google Chrome version 147.0.7727.55. The affected product is Google Chrome, and the vulnerability class is related to inappropriate implementation in the Navigation fe [truncated]
CVE-2026-5915 is an out of bounds memory write vulnerability in Google Chrome prior to 147.0.7727.55. The issue is due to insufficient validation of untrusted input in WebML. A remote attacker can exploit this vulnerability via a crafted HTML page. This vulnerability has a CVSS score of 8.1 and is classified as HIGH severity. Users of Google Chrome prior to version 147.0.7727.55 should update to the lates [truncated]
CVE-2026-5914 is a HIGH severity vulnerability in Google Chrome prior to 147.0.7727.55. This Type Confusion in CSS vulnerability allows an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. The Chromium security severity is rated as Low, but the CVSS score is 8.8, indicating a HIGH severity vulnerability. The vulnerability [truncated]
CVE-2026-5913 is an out-of-bounds read vulnerability in Blink, a browser engine used in Google Chrome. The vulnerability was patched in Google Chrome version 147.0.7727.55. An attacker could exploit this vulnerability by providing a crafted HTML page that triggers an out-of-bounds memory read. This vulnerability has a CVSS score of 8.1 and is considered High severity. Users of Google Chrome prior to versi [truncated]
CVE-2026-5912 is an integer overflow vulnerability in WebRTC in Google Chrome prior to 147.0.7727.55. This vulnerability allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. The Chromium security severity is rated as Low. The vulnerability affects the WebRTC component used for real-time communication in Google Chrome. This type of vulnerability could potentially be u [truncated]
CVE-2026-5910 is an integer overflow vulnerability in Google Chrome's Media component prior to version 147.0.7727.55. This vulnerability could potentially allow a remote attacker to exploit heap corruption via a crafted video file. The Chromium security severity of this issue is rated as Low. The vulnerability affects Google Chrome users who have not updated to the latest version. Organizations and indivi [truncated]
CVE-2026-5909 is an integer overflow vulnerability in the Media component of Google Chrome. This issue, which was reported as having a low severity by Chromium, could allow a remote attacker to potentially exploit heap corruption via a specially crafted video file. The vulnerability was addressed in Google Chrome version 147.0.7727.55. The vulnerability affects users who handle video files from untrusted [truncated]
CVE-2026-5908 is an integer overflow vulnerability in the Media component of Google Chrome. This issue, which was reported as having a low severity by Chromium, could allow a remote attacker to potentially exploit heap corruption via a specially crafted video file. The vulnerability was addressed in Google Chrome version 147.0.7727.55. This vulnerability affects users who handle video files from untrusted [truncated]
CVE-2026-5907 is a vulnerability in Google Chrome prior to version 147.0.7727.55, where insufficient data validation in Media allowed a remote attacker to perform an out of bounds memory read via a crafted video file. This vulnerability has a high CVSS score of 8.1 and is categorized as having a Low severity by Chromium. The vulnerability affects users who handle video files from untrusted sources, and th [truncated]
CVE-2026-5906 is a MEDIUM severity vulnerability in Google Chrome on Android prior to 147.0.7727.55, allowing a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. This vulnerability has a CVSS score of 4.3 and is caused by incorrect security UI in the Omnibox. The vulnerability requires user interaction to exploit and has a moderate impact on affected systems. Users of [truncated]
CVE-2026-5905 is a MEDIUM severity vulnerability in Google Chrome on Windows, allowing domain spoofing via a crafted HTML page. The vulnerability is due to incorrect security UI in Permissions. This issue affects users who have not updated Google Chrome to version 147.0.7727.55 or later. The vulnerability has a CVSS score of 6.5 and is considered a Low severity by Chromium. The CVE record was published on [truncated]
CVE-2026-5903 is a policy bypass vulnerability in IFrameSandbox in Google Chrome prior to 147.0.7727.55. An attacker could convince a user to engage in specific UI gestures to bypass navigation restrictions via a crafted HTML page. The Chromium security severity is rated as Low. This vulnerability requires user interaction and is related to navigation restrictions bypass.
CVE-2026-5902 is a race condition vulnerability in the Media component of Google Chrome on Android prior to version 147.0.7727.55. This vulnerability allows a remote attacker who has compromised the renderer process to corrupt media stream metadata via a crafted HTML page. The Chromium security severity is rated as Low. The vulnerability affects users of Google Chrome on Android, and it is crucial for the [truncated]
CVE-2026-5901 is a MEDIUM severity vulnerability in Google Chrome's DevTools, which allowed an attacker to bypass enterprise host restrictions for cookie modification via a crafted Chrome Extension. The vulnerability was patched in Chrome version 147.0.7727.55. Enterprises should prioritize patching to prevent potential cookie modification attacks. The vulnerability has a Low severity rating by Chromium.
CVE-2026-5899 is a Medium severity vulnerability in Google Chrome prior to 147.0.7727.55. It is caused by insufficient policy enforcement in History Navigation, which allows a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page when a user engages in specific UI gestures. This vulnerability can lead to potential UXSS attacks if not addressed. Users of Google Chrome prior to [truncated]
CVE-2026-5898 is a Medium severity vulnerability in Google Chrome on iOS, allowing remote attackers to perform UI spoofing via a crafted HTML page. The vulnerability has a CVSS score of 4.3 and a severity of Medium. The CVE record was published on 2026-04-08T22:16:29.690Z and has not been modified since then. The vulnerability affects Google Chrome on iOS prior to version 147.0.7727.55. The incorrect secu [truncated]
CVE-2026-5897 is a MEDIUM severity vulnerability in Google Chrome prior to 147.0.7727.55, caused by incorrect security UI in Downloads. This allows a remote attacker who convinces a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. The vulnerability has a CVSS score of 4.3 and a Chromium security severity of Low. Users of Google Chrome prior to version 147.0.7727.55 sh [truncated]
CVE-2026-5896 is a policy bypass vulnerability in the Audio component of Google Chrome prior to version 147.0.7727.55. The vulnerability allowed a remote attacker to bypass sandbox download restrictions via a crafted HTML page by convincing a user to engage in specific UI gestures. This issue was rated as Low severity by the Chromium security team. The CVSS v3.1 score for this vulnerability is 6.1. Users [truncated]
CVE-2026-5895 is a MEDIUM severity vulnerability in Google Chrome on iOS, allowing a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. The vulnerability is caused by incorrect security UI in Omnibox. It has a CVSS score of 5.4. The potential impact of URL spoofing can be significant, especially if attackers can deceive users into visiting malicious websites. Users s [truncated]
CVE-2026-5894 is a vulnerability in Google Chrome's PDF implementation that could allow a remote attacker to bypass navigation restrictions. The CVE record was published on 2026-04-08T22:16:29.290Z and has not been modified since then. This vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. Affected users should update to the latest version of Google Chrome to mitigate this vulnerability. The [truncated]
CVE-2026-5893 is a Medium severity vulnerability in Google Chrome prior to version 147.0.7727.55. The vulnerability is caused by a race condition in the V8 engine, which could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability has a CVSS score of 6.8 and a Medium severity level. Users of Google Chrome prior to version 147.0.7727.55 should update to t [truncated]
CVE-2026-5892 is a Medium severity vulnerability in Google Chrome, specifically in its handling of Progressive Web Apps (PWAs). Insufficient policy enforcement in PWAs allowed a remote attacker, who had compromised the renderer process, to install a PWA without user consent via a crafted HTML page. This vulnerability has a CVSS score of 6.6 and is considered Medium priority. Users of Google Chrome prior t [truncated]
CVE-2026-5891 is a Medium severity vulnerability in Google Chrome prior to version 147.0.7727.55. It involves insufficient policy enforcement in browser UI, allowing a remote attacker who has compromised the renderer process to perform UI spoofing via a crafted HTML page. This type of vulnerability can lead to user interface deception, potentially tricking users into performing unintended actions. The vul [truncated]
CVE-2026-5888 is a Medium-severity vulnerability in Google Chrome's WebCodecs feature. This issue, caused by an uninitialized use, could allow a remote attacker to access potentially sensitive information from process memory. The vulnerability was addressed in Google Chrome version 147.0.7727.55. Users of Google Chrome, especially those who handle sensitive information or require high security standards, [truncated]
CVE-2026-5887 is a Medium severity vulnerability in Google Chrome on Windows, allowing a remote attacker to bypass download restrictions via a crafted HTML page. The vulnerability has a CVSS score of 4.3 and is classified as CWE-20. Affected product is Google Chrome on Windows prior to version 147.0.7727.55. Likely operational impact includes unauthorized downloads. Source confidence is high based on CVE. [truncated]
CVE-2026-5886 is an out-of-bounds read vulnerability in WebAudio in Google Chrome on Mac prior to 147.0.7727.55. This vulnerability allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. The Chromium security severity is rated as Medium. The vulnerability affects users of Google Chrome on Mac operating systems, specifically versions prior to 147. [truncated]
CVE-2026-5885 is a Medium severity vulnerability in Google Chrome on Windows, specifically in the WebML component. Insufficient validation of untrusted input allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. This vulnerability has the potential to disclose sensitive information and should be addressed promptly. Users of Google Chrome on Wind [truncated]
CVE-2026-5884 is a vulnerability in Google Chrome prior to version 147.0.7727.55, caused by insufficient validation of untrusted input in the Media component. This allows a remote attacker who has compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. The issue was addressed by updating Google Chrome to version 147.0.7727.55 or later. This vulnerability has a [truncated]
CVE-2026-5882 is a medium-severity vulnerability in Google Chrome prior to version 147.0.7727.55. It allows remote attackers to perform UI spoofing via a crafted HTML page. The vulnerability is caused by incorrect security UI in Fullscreen. Users should update Google Chrome to version 147.0.7727.55 or later to mitigate this vulnerability. This vulnerability could allow attackers to deceive users into perf [truncated]