|
501
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity:…
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-11259
|
2026-06-8 23:19 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
502
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: L…
Update
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-11260
|
2026-06-8 23:19 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
503
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in PDF in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromiu…
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-11261
|
2026-06-8 23:19 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
504
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Policy bypass in Content Security Policy in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
Update
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-11264
|
2026-06-8 23:18 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
505
|
7.5 |
HIGH
Network
|
google
|
chrome
|
Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Update
|
CWE-352
Origin Validation Error
|
CVE-2026-11265
|
2026-06-8 23:18 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
506
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in SafeBrowsing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass Safe Browsing via a malicious file. (Chromium security severity: Low)
Update
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-11266
|
2026-06-8 23:18 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
507
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a…
Update
|
CWE-602
Client-Side Enforcement of Server-Side Security
|
CVE-2026-11267
|
2026-06-8 23:18 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
508
|
7.1 |
HIGH
Adjacent
|
google
|
chrome
|
Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker in a privileged network position to execute arbitrary code inside a sandbox via a crafted Chrome…
Update
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2026-11269
|
2026-06-8 23:18 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
509
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a craf…
Update
|
CWE-200
Information Exposure
|
CVE-2026-11271
|
2026-06-8 23:17 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
510
|
6.1 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scri…
Update
|
CWE-20 CWE-79
Improper Input Validation Cross-site Scripting
|
CVE-2026-11273
|
2026-06-8 23:17 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|