CVE-2026-11666
- EPSS 0.21%
- Veröffentlicht 08.06.2026 23:27:42
- Zuletzt bearbeitet 23.07.2026 08:10:00
Insufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)
CVE-2026-11663
- EPSS 0.22%
- Veröffentlicht 08.06.2026 23:27:41
- Zuletzt bearbeitet 23.07.2026 08:10:00
Use after free in Skia in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVE-2026-11664
- EPSS 0.25%
- Veröffentlicht 08.06.2026 23:27:41
- Zuletzt bearbeitet 23.07.2026 08:10:00
Use after free in Payments in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2026-11662
- EPSS 0.36%
- Veröffentlicht 08.06.2026 23:27:40
- Zuletzt bearbeitet 23.07.2026 08:10:00
Type Confusion in Bindings in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-11660
- EPSS 0.26%
- Veröffentlicht 08.06.2026 23:27:39
- Zuletzt bearbeitet 23.07.2026 08:10:00
Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security...
CVE-2026-11661
- EPSS 0.24%
- Veröffentlicht 08.06.2026 23:27:39
- Zuletzt bearbeitet 23.07.2026 08:10:00
Use after free in Views in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVE-2026-11658
- EPSS 0.23%
- Veröffentlicht 08.06.2026 23:27:38
- Zuletzt bearbeitet 23.07.2026 08:10:00
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
CVE-2026-11659
- EPSS 0.25%
- Veröffentlicht 08.06.2026 23:27:38
- Zuletzt bearbeitet 23.07.2026 08:10:00
Integer overflow in UI in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVE-2026-11656
- EPSS 0.17%
- Veröffentlicht 08.06.2026 23:27:37
- Zuletzt bearbeitet 23.07.2026 08:10:00
Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: Hi...
CVE-2026-11657
- EPSS 0.25%
- Veröffentlicht 08.06.2026 23:27:37
- Zuletzt bearbeitet 23.07.2026 08:10:00
Use after free in Payments in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)