汇总 Google — Chrome, Android & Chromium Security Issues 相关全部产品的 CVE 与安全漏洞情报,包括 CVSS、EPSS、公开时间与漏洞情报数据。
已披露问题常与 缓冲区溢出、输入验证问题与路径处理缺陷 相关,可能在 系统组件与服务器部署 场景中带来 异常行为与文件覆盖 等暴露风险。
相关漏洞数据主要来源于公开漏洞披露与安全公告,可用于评估历史漏洞暴露面与修复优先级。
| CVE | 摘要 | 来源 | 最高 CVSS | EPSS % | 公开时间 | 更新时间 |
|---|---|---|---|---|---|---|
| CVE-2026-11701 | Inappropriate implementation in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | [email protected] | 5.4 | 0.06% | 2026-06-09 | 2026-06-09 |
| CVE-2026-11700 | Use after free in Tracing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | [email protected] | 8.3 | 0.07% | 2026-06-09 | 2026-06-09 |
| CVE-2026-11699 | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | [email protected] | 8.8 | 0.07% | 2026-06-09 | 2026-06-09 |
| CVE-2026-11698 | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | [email protected] | 8.8 | 0.07% | 2026-06-09 | 2026-06-09 |
| CVE-2026-11697 | Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | [email protected] | 9.6 | 0.07% | 2026-06-09 | 2026-06-09 |
| CVE-2026-11696 | Uninitialized Use in Video in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) | [email protected] | 5.3 | 0.03% | 2026-06-09 | 2026-06-09 |
| CVE-2026-11695 | Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | [email protected] | 4.3 | 0.03% | 2026-06-09 | 2026-06-09 |
| CVE-2026-11694 | Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | [email protected] | 7.5 | 0.08% | 2026-06-09 | 2026-06-09 |
| CVE-2026-11693 | Inappropriate implementation in Plugins in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High) | [email protected] | 8.1 | 0.02% | 2026-06-09 | 2026-06-09 |
| CVE-2026-11692 | Use after free in Read Anything in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | [email protected] | 8.3 | 0.07% | 2026-06-09 | 2026-06-09 |
| CVE-2026-11691 | Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | [email protected] | 3.1 | 0.02% | 2026-06-09 | 2026-06-09 |
| CVE-2026-11690 | Out of bounds read and write in Media in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | [email protected] | 7.5 | 0.08% | 2026-06-09 | 2026-06-09 |
| CVE-2026-11689 | Insufficient policy enforcement in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High) | [email protected] | 8.1 | 0.02% | 2026-06-09 | 2026-06-10 |
| CVE-2026-11688 | Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | [email protected] | 8.8 | 0.08% | 2026-06-09 | 2026-06-09 |
| CVE-2026-11687 | Use after free in Dawn in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | [email protected] | 8.8 | 0.07% | 2026-06-09 | 2026-06-09 |
| CVE-2026-11686 | Insufficient validation of untrusted input in Dawn in Google Chrome on macOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | [email protected] | 3.1 | 0.02% | 2026-06-09 | 2026-06-09 |
| CVE-2026-11685 | Inappropriate implementation in MediaCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | [email protected] | 4.3 | 0.02% | 2026-06-09 | 2026-06-09 |
| CVE-2026-11684 | Insufficient policy enforcement in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the utility process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | [email protected] | 3.1 | 0.03% | 2026-06-09 | 2026-06-09 |
| CVE-2026-11683 | Use after free in WebCodecs in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | [email protected] | 8.8 | 0.07% | 2026-06-09 | 2026-06-09 |
| CVE-2026-11682 | Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | [email protected] | 8.3 | 0.07% | 2026-06-09 | 2026-06-10 |