PatchSiren

Google CVE debriefs · Page 8

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Google CVE published 2026-08-25

CVE-2026-79259

The CVE-2026-79259 vulnerability is caused by improper input validation in Safebrowsing in Google Chrome prior to version 152.0.7977.65. This allows a remote attacker to bypass system access restrictions via a crafted file. The vulnerability has a CVSS score of 4.3 and is rated as Medium severity by Chromium. Users and administrators of Google Chrome should be aware of this vulnerability and take immediat [truncated]

MEDIUM Google CVE published 2026-08-25

CVE-2026-79258

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T21:18:20.340Z and has not been modified since then. CVE-2026-79258 is a Medium severity vulnerability in Google Chrome prior to version 152.0.7977.65, caused by incorrect authorization in WebXR. This allows a remote attacker to obtain cross-origin data via a crafted HTML page, leveraging social e [truncated]

CRITICAL Google CVE published 2026-08-25

CVE-2026-79257

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T21:18:20.230Z and has not been modified since then. The CVE-2026-79257 vulnerability is a use-after-free issue in the Views component of Google Chrome prior to version 152.0.7977.65. This vulnerability allows a remote attacker to execute arbitrary code outside the sandbox by providing a crafted H [truncated]

HIGH Google CVE published 2026-08-25

CVE-2026-79245

A use-after-free vulnerability was reported in the UI of Google Chrome prior to version 152.0.7977.65. This vulnerability could allow a local attacker, who had compromised the renderer process, to execute arbitrary code outside the sandbox via a local program. The Chromium security team classified this issue as Medium severity. The vulnerability affects Google Chrome users, particularly those in environme [truncated]

MEDIUM Google CVE published 2026-08-25

CVE-2026-79241

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T21:18:18.397Z and has not been modified since then. The NVD entry is currently Analyzed. This out-of-bounds read vulnerability in Google Chrome's GPU on Android, prior to version 152.0.7977.65, allows remote attackers to read memory outside the sandbox via crafted HTML pages. The Chromium securit [truncated]

CRITICAL Google CVE published 2026-08-25

CVE-2026-79232

A use-after-free vulnerability exists in the Aura component of Google Chrome prior to version 152.0.7977.65. This vulnerability, tracked as CVE-2026-79232, could allow a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. The CVE record was published on 2026-08-25T21:18:17.413Z and has not been modified since then. The NVD entry is currently Analyzed. Adminis [truncated]

HIGH Google CVE published 2026-08-25

CVE-2026-79231

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T21:18:17.297Z and has not been modified since then. The CVE-2026-79231 vulnerability is a buffer overflow issue in the Media component of Google Chrome. This vulnerability can be exploited by a remote attacker to execute arbitrary code inside the sandbox via a specially crafted HTML page. The vul [truncated]

HIGH Google CVE published 2026-08-25

CVE-2026-79230

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T21:18:17.183Z and has not been modified since then. This CVE-2026-79230 vulnerability involves improper input validation in ANGLE of Google Chrome on Mac prior to version 152.0.7977.65, allowing remote attackers to potentially execute arbitrary code outside the sandbox via a crafted HTML page. Th [truncated]

MEDIUM Google CVE published 2026-08-25

CVE-2026-79229

The CVE-2026-79229 vulnerability is caused by an uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65. This issue allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. The vulnerability has been classified as Medium severity by Chromium, with a CVSS score of 6.5. Users of Google Chrome, especially those who handle [truncated]

HIGH Google CVE published 2026-08-25

CVE-2026-79226

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T21:18:16.743Z and has not been modified since then. This Medium severity vulnerability, CVE-2026-79226, involves improper privilege management in Regional Capabilities in Google Chrome prior to 152.0.7977.65. It allows a remote attacker leveraging social engineering to bypass system access restri [truncated]

MEDIUM Google CVE published 2026-08-25

CVE-2026-79221

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T21:18:16.197Z and has not been modified since then. The CVE-2026-79221 vulnerability is caused by an uninitialized resource in Dawn within Google Chrome prior to version 152.0.7977.65. This issue allows a remote attacker to potentially read memory inside the sandbox via a crafted HTML page, class [truncated]

MEDIUM Google CVE published 2026-08-25

CVE-2026-79217

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T21:18:15.760Z and has not been modified since then. The CVE-2026-79217 vulnerability is a Medium severity vulnerability in Google Chrome on iOS, allowing remote attackers to bypass system access restrictions via a crafted HTML page. The CVSS score of 4.3 indicates a moderate level of severity, an [truncated]

MEDIUM Google CVE published 2026-08-25

CVE-2026-79211

The CVE-2026-79211 vulnerability is related to incorrect authorization in USB in Google Chrome prior to version 152.0.7977.65. This vulnerability allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. The vulnerability has a Medium severity and is associated with Chromium security severity: Medium. Users of Google Chrome prior to version 152.0 [truncated]

HIGH Google CVE published 2026-08-25

CVE-2026-79202

A use-after-free vulnerability was reported in Google Chrome's Chromecast feature prior to version 152.0.7977.65. This issue could allow a remote attacker to execute arbitrary code within the sandbox by providing a crafted HTML page. The vulnerability has been identified as having a high severity rating. The vulnerability affects Google Chrome's Chromecast feature, which is a key component for streaming c [truncated]

CRITICAL Google CVE published 2026-08-25

CVE-2026-79200

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T21:18:13.827Z and has not been modified since then. The NVD entry is currently Analyzed. This critical use-after-free vulnerability in Google Chrome's Aura component, prior to version 152.0.7977.65, allows a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. Th [truncated]

MEDIUM Google CVE published 2026-08-25

CVE-2026-79199

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T21:18:13.713Z and has not been modified since then. The CVE-2026-79199 vulnerability is caused by incorrect authorization in the Network component of Google Chrome prior to version 152.0.7977.65. This allows a remote attacker to bypass system access restrictions via a crafted HTML page. The vulne [truncated]

HIGH Google CVE published 2026-08-25

CVE-2026-79198

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T21:18:13.603Z and has not been modified since then. The NVD entry is currently Analyzed. This CVE-2026-79198 vulnerability is a use-after-free issue in the Platform component of Google Chrome prior to version 152.0.7977.65. The vulnerability could allow a remote attacker to execute arbitrary code [truncated]

LOW Google CVE published 2026-08-25

CVE-2026-79186

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T21:18:12.267Z and has not been modified since then. The CVE-2026-79186 vulnerability is related to incorrect authorization in the Network component of Google Chrome. This issue allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. The [truncated]

MEDIUM Google CVE published 2026-08-25

CVE-2026-79151

The CVE-2026-79151 vulnerability is caused by improper input validation in Safebrowsing in Google Chrome prior to 152.0.7977.65. This allows a remote attacker to bypass system access restrictions via a crafted file. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. Affected users should apply the official patch to update Google Chrome to version 152.0.7977.65 or later. The vulnerability [truncated]

CRITICAL Google CVE published 2026-08-25

CVE-2026-79148

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T21:18:10.043Z and has not been modified since then. The CVE-2026-79148 vulnerability is an off-by-one error in DevTools in Google Chrome prior to 152.0.7977.65. This issue allows a remote attacker to potentially read memory inside the sandbox via a crafted Chrome extension, leveraging social engi [truncated]

MEDIUM Google CVE published 2026-08-25

CVE-2026-79147

Information leak in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain sensitive information via a crafted HTML page. This vulnerability, with a medium severity score of 5.3, is considered a low-severity issue by Chromium and impacts Google Chrome users. The vulnerability affects the graphics library used in Google Chrome, [truncated]

MEDIUM Google CVE published 2026-08-25

CVE-2026-79146

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T21:18:09.820Z and has not been modified since then. The CVE-2026-79146 vulnerability is an information leak in CustomTabs in Google Chrome on Android prior to version 152.0.7977.65. It allowed a local attacker to obtain cross-origin data via a co-installed app. The vulnerability has a CVSS score [truncated]

MEDIUM Google CVE published 2026-08-25

CVE-2026-79144

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T21:18:09.717Z and has not been modified since then. The CVE-2026-79144 vulnerability is an information leak in Skia in Google Chrome prior to 152.0.7977.65. It allowed a remote attacker to obtain cross-origin data via a crafted HTML page. The vulnerability has a CVSS score of 4.3 and a severity o [truncated]

MEDIUM Google CVE published 2026-08-25

CVE-2026-79143

CVE-2026-79143 is a Medium severity vulnerability in Google Chrome prior to 152.0.7977.65, allowing a remote attacker to bypass system access restrictions via a crafted HTML page, leveraging social engineering. This issue affects users of Google Chrome prior to version 152.0.7977.65. The vulnerability was published on 2026-08-25T21:18:09.607Z and has not been modified since then. The CVE record and NVD de [truncated]

MEDIUM Google CVE published 2026-08-25

CVE-2026-79141

CVE-2026-79141 is a Medium severity vulnerability in Google Chrome prior to version 152.0.7977.65. The issue involves incorrect authorization, allowing a remote attacker to bypass web origin policy via a crafted HTML page. This vulnerability was reported by an external researcher and patched by Google. The affected product is Google Chrome, and the vulnerability class is related to web origin policy bypas [truncated]

MEDIUM Google CVE published 2026-08-25

CVE-2026-79136

The CVE-2026-79136 vulnerability is caused by incorrect authorization in ServiceWorker in Google Chrome prior to 152.0.7977.65. This allows a remote attacker to bypass web origin policy via a crafted HTML page, potentially leading to security issues. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. Administrators and users of Google Chrome, especially those in environments where securit [truncated]

HIGH Google CVE published 2026-08-25

CVE-2026-79127

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T21:18:07.873Z and has not been modified since then. The vulnerability, CVE-2026-79127, is an out-of-bounds write issue in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. This vulnerability exists in versions prior to 152.0.7977.65 and allows a remote attacker to execut [truncated]

MEDIUM Google CVE published 2026-08-25

CVE-2026-79120

The CVE-2026-79120 vulnerability is caused by an uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65. This allows a remote attacker to potentially obtain cross-origin data via a crafted HTML page. The vulnerability has a CVSS score of 6.5 and a Chromium security severity of Medium. Google Chrome users and administrators should be aware of this vulnerability and take immediate action to [truncated]

MEDIUM Google CVE published 2026-08-25

CVE-2026-79118

The CVE-2026-79118 vulnerability is caused by an uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65. This allows a remote attacker to obtain cross-origin data via a crafted HTML page. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. Google Chrome users should apply the latest update to prevent potential cross-origin data exposure. The vulnerability affects Google Ch [truncated]

MEDIUM Google CVE published 2026-08-25

CVE-2026-79116

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T21:18:06.657Z and has not been modified since then. The CVE-2026-79116 vulnerability involves missing authorization in Viz in Google Chrome prior to version 152.0.7977.65. This allows a remote attacker who has compromised the renderer process to bypass web origin policy via a crafted HTML page. T [truncated]