CVE Feed

    Dashboard / CVE

    9.6
    Critical

    CVE-2026-11131

    Last Modified: 8 Jun 2026

    Use after free in Autofill in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11127

    Last Modified: 9 Jun 2026

    Inappropriate implementation in WebAPKs in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted WebAPK. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11133

    Last Modified: 8 Jun 2026

    Insufficient policy enforcement in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11138

    Last Modified: 8 Jun 2026

    Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11142

    Last Modified: 8 Jun 2026

    Insufficient policy enforcement in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11148

    Last Modified: 8 Jun 2026

    Inappropriate implementation in Payments in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    7.5
    High

    CVE-2026-11154

    Last Modified: 8 Jun 2026

    Use after free in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    4.3
    Medium

    CVE-2026-11156

    Last Modified: 8 Jun 2026

    Inappropriate implementation in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    5.4
    Medium

    CVE-2026-11157

    Last Modified: 8 Jun 2026

    Script injection in Accessibility in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts or HTML (UXSS) via a crafted Chrome Extension. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    9.6
    Critical

    CVE-2026-11165

    Last Modified: 9 Jun 2026

    Use after free in WebMIDI in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11171

    Last Modified: 6 Jun 2026

    Integer overflow in Blink in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11182

    Last Modified: 10 Jun 2026

    Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    4.3
    Medium

    CVE-2026-11192

    Last Modified: 9 Jun 2026

    Insufficient validation of untrusted input in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11217

    Last Modified: 5 Jun 2026

    Inappropriate implementation in Fenced Frames in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    4.3
    Medium

    CVE-2026-11228

    Last Modified: 10 Jun 2026

    Inappropriate implementation in File Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11305

    Last Modified: 8 Jun 2026

    Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)

    Published: 2 Jun 2026
    4.3
    Medium

    CVE-2026-11286

    Last Modified: 9 Jun 2026

    Insufficient validation of untrusted input in Wallet in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11016

    Last Modified: 8 Jun 2026

    Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    9.6
    Critical

    CVE-2026-11021

    Last Modified: 8 Jun 2026

    Insufficient validation of untrusted input in GPU in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11064

    Last Modified: 8 Jun 2026

    Race in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11124

    Last Modified: 9 Jun 2026

    Integer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11140

    Last Modified: 8 Jun 2026

    Out of bounds read in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    9.6
    Critical

    CVE-2026-11146

    Last Modified: 8 Jun 2026

    Insufficient validation of untrusted input in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.1
    Medium

    CVE-2026-11150

    Last Modified: 8 Jun 2026

    Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11175

    Last Modified: 8 Jun 2026

    Incorrect security UI in Messages in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11193

    Last Modified: 9 Jun 2026

    Insufficient policy enforcement in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    4.3
    Medium

    CVE-2026-11234

    Last Modified: 9 Jun 2026

    Inappropriate implementation in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11079

    Last Modified: 8 Jun 2026

    Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory write via a crafted video file. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11075

    Last Modified: 8 Jun 2026

    Out of bounds read in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11078

    Last Modified: 8 Jun 2026

    Inappropriate implementation in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-10991

    Last Modified: 6 Jun 2026

    Use after free in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    7.3
    High

    CVE-2026-11115

    Last Modified: 8 Jun 2026

    Use after free in Updater in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    5.9
    Medium

    CVE-2026-11199

    Last Modified: 6 Jun 2026

    Inappropriate implementation in WebRTC in Google Chrome prior to 149.0.7827.53 allowed an attacker in a privileged network position to leak cross-origin data via malicious network traffic. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11211

    Last Modified: 8 Jun 2026

    Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    9.6
    Critical

    CVE-2026-11009

    Last Modified: 8 Jun 2026

    Use after free in USB in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    5.3
    Medium

    CVE-2026-11174

    Last Modified: 8 Jun 2026

    Inappropriate implementation in Site Isolation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11176

    Last Modified: 8 Jun 2026

    Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11177

    Last Modified: 8 Jun 2026

    Use after free in Omnibox in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    4.3
    Medium

    CVE-2026-11178

    Last Modified: 8 Jun 2026

    Insufficient policy enforcement in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11179

    Last Modified: 8 Jun 2026

    Inappropriate implementation in ORB in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11258

    Last Modified: 8 Jun 2026

    Inappropriate implementation in File System Access in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    4.3
    Medium

    CVE-2026-11259

    Last Modified: 8 Jun 2026

    Insufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    4.3
    Medium

    CVE-2026-11260

    Last Modified: 8 Jun 2026

    Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    4.3
    Medium

    CVE-2026-11261

    Last Modified: 8 Jun 2026

    Inappropriate implementation in PDF in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11263

    Last Modified: 8 Jun 2026

    Insufficient policy enforcement in WebAuthentication in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    4.3
    Medium

    CVE-2026-11267

    Last Modified: 8 Jun 2026

    Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension. (Chromium security severity: Low)

    Published: 2 Jun 2026
    7.1
    High

    CVE-2026-11269

    Last Modified: 8 Jun 2026

    Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker in a privileged network position to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Low)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11275

    Last Modified: 8 Jun 2026

    Inappropriate implementation in Page Info in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    7.8
    High

    CVE-2026-10942

    Last Modified: 8 Jun 2026

    Inappropriate implementation in UI in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: High)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11045

    Last Modified: 8 Jun 2026

    Insufficient validation of untrusted input in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026