CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2026-11216

    Last Modified: 5 Jun 2026

    Incorrect security UI in File Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

    Published: 4 Jun 2026
    6.5
    Medium

    CVE-2026-11215

    Last Modified: 5 Jun 2026

    Inappropriate implementation in Cronet in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    6.5
    Medium

    CVE-2026-11214

    Last Modified: 5 Jun 2026

    Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    9.6
    Critical

    CVE-2026-11213

    Last Modified: 5 Jun 2026

    Insufficient validation of untrusted input in Reading Mode in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    4.3
    Medium

    CVE-2026-11212

    Last Modified: 6 Jun 2026

    Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    6.5
    Medium

    CVE-2026-11210

    Last Modified: 6 Jun 2026

    Inappropriate implementation in Safe Browsing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access control via a crafted RAR file. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    6.5
    Medium

    CVE-2026-11209

    Last Modified: 6 Jun 2026

    Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    6.5
    Medium

    CVE-2026-11208

    Last Modified: 6 Jun 2026

    Use after free in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    9.6
    Critical

    CVE-2026-11207

    Last Modified: 6 Jun 2026

    Insufficient validation of untrusted input in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    6.5
    Medium

    CVE-2026-11206

    Last Modified: 6 Jun 2026

    Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    6.1
    Medium

    CVE-2026-11205

    Last Modified: 5 Jun 2026

    Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted QR code. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    6.5
    Medium

    CVE-2026-11204

    Last Modified: 6 Jun 2026

    Inappropriate implementation in Signin in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    6.5
    Medium

    CVE-2026-11203

    Last Modified: 6 Jun 2026

    Inappropriate implementation in GPU in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    8.8
    High

    CVE-2026-11202

    Last Modified: 6 Jun 2026

    Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    8.8
    High

    CVE-2026-11201

    Last Modified: 6 Jun 2026

    Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    6.5
    Medium

    CVE-2026-11200

    Last Modified: 5 Jun 2026

    Inappropriate implementation in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    9.6
    Critical

    CVE-2026-11198

    Last Modified: 5 Jun 2026

    Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    6.5
    Medium

    CVE-2026-11197

    Last Modified: 5 Jun 2026

    Insufficient policy enforcement in Workers in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    8.8
    High

    CVE-2026-11188

    Last Modified: 6 Jun 2026

    Use after free in USB in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    6.3
    Medium

    CVE-2026-11187

    Last Modified: 6 Jun 2026

    Inappropriate implementation in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    6.1
    Medium

    CVE-2026-11186

    Last Modified: 6 Jun 2026

    Inappropriate implementation in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    8.1
    High

    CVE-2026-11185

    Last Modified: 5 Jun 2026

    Use after free in V8 in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    6.3
    Medium

    CVE-2026-11184

    Last Modified: 6 Jun 2026

    Insufficient policy enforcement in Actor in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    6.5
    Medium

    CVE-2026-11183

    Last Modified: 6 Jun 2026

    Out of bounds read in GWP-ASan in Google Chrome prior to 149.0.7827.53 allowed a local attacker to obtain potentially sensitive information from process memory via a malicious file. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    7.5
    High

    CVE-2026-11149

    Last Modified: 5 Jun 2026

    Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    9.6
    Critical

    CVE-2026-11113

    Last Modified: 6 Jun 2026

    Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    8.8
    High

    CVE-2026-11102

    Last Modified: 6 Jun 2026

    Inappropriate implementation in Isolated Web Apps in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a malicious file. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    8.7
    High

    CVE-2025-8873

    Last Modified: 5 Jun 2026

    On affected platforms running Arista EOS with IPsec configured, a specially crafted packet can cause the dataplane to stop processing all IPsec traffic. The control plane may detect this condition, and attempt to reset the IPsec processing pipeline. After reset traffic may not resume being processed. There is no impact to non-IPsec traffic or to IPsec traffic not originating or terminating on the system. This issue was reported by an Arista customer.

    Published: 4 Jun 2026
    9.6
    Critical

    CVE-2026-11095

    Last Modified: 5 Jun 2026

    Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    9.6
    Critical

    CVE-2026-11088

    Last Modified: 5 Jun 2026

    Integer overflow in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    9.6
    Critical

    CVE-2026-11066

    Last Modified: 5 Jun 2026

    Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    9.6
    Critical

    CVE-2026-11065

    Last Modified: 5 Jun 2026

    Use after free in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    9.6
    Critical

    CVE-2026-11061

    Last Modified: 5 Jun 2026

    Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    7.5
    High

    CVE-2026-11058

    Last Modified: 6 Jun 2026

    Integer overflow in CredentialProvider in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform OS-level privilege escalation via a crafted HTML page. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    8.8
    High

    CVE-2026-11042

    Last Modified: 5 Jun 2026

    Use after free in Views in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    8.3
    High

    CVE-2026-11040

    Last Modified: 5 Jun 2026

    Use after free in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    6.5
    Medium

    CVE-2026-11038

    Last Modified: 5 Jun 2026

    Insufficient policy enforcement in Subresource Integrity in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via malicious network traffic. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    9.6
    Critical

    CVE-2026-11037

    Last Modified: 5 Jun 2026

    Out of bounds write in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    6.5
    Medium

    CVE-2026-11001

    Last Modified: 6 Jun 2026

    Inappropriate implementation in Payments in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    4
    Medium

    CVE-2026-10998

    Last Modified: 6 Jun 2026

    Out of bounds read in Media in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to perform an out of bounds memory read via malicious network traffic. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    6.5
    Medium

    CVE-2026-10994

    Last Modified: 6 Jun 2026

    Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    6.5
    Medium

    CVE-2026-10993

    Last Modified: 6 Jun 2026

    Heap buffer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    6.5
    Medium

    CVE-2026-10992

    Last Modified: 7 Jun 2026

    Insufficient data validation in Animation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

    Published: 4 Jun 2026
    8.8
    High

    CVE-2026-10989

    Last Modified: 6 Jun 2026

    Inappropriate implementation in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    8.8
    High

    CVE-2026-10988

    Last Modified: 6 Jun 2026

    Use after free in Views in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    6.5
    Medium

    CVE-2026-10985

    Last Modified: 5 Jun 2026

    Out of bounds read in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    5.4
    Medium

    CVE-2026-10984

    Last Modified: 5 Jun 2026

    Inappropriate implementation in Accessibility in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    9.6
    Critical

    CVE-2026-10983

    Last Modified: 5 Jun 2026

    Insufficient validation of untrusted input in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026
    6.5
    Medium

    CVE-2026-10981

    Last Modified: 5 Jun 2026

    Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted video file. (Chromium security severity: High)

    Published: 4 Jun 2026
    6.5
    Medium

    CVE-2026-10980

    Last Modified: 5 Jun 2026

    Insufficient validation of untrusted input in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

    Published: 4 Jun 2026