CVE-2026-11044
Integer overflow in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive informati
CVSS
6.5
Medium
EPSS
0.3%
p21
KEV
—
Exploit Today
6
0-100
Published: Jun 4, 2026 · Last modified: Jul 23, 2026 · CWE-472 · CWE-190
0.3%EPSS · 30 days0.3%
2026-08-092026-09-05
Integer overflow in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-861396.9 MED1.3%
——0In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.2dCVE-2026-861386.9 MED2.0%
——1In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.2dCVE-2026-180784.3 MED17.4%
——5IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to an integer overflow.2dCVE-2026-816666.5 MED19.0%
——6An integer overflow was found in Corosync's handling of membership commit token messages. The length-validation check for these messages can be bypassed on 32-bit systems due to an integer overflow in the calculation of the expected message length, allowing a crafted network packet to trigger an out-of-bounds memory access that crashes the Corosync daemon. This results in a denial of service for the affected cluster node. The overflow does not occur on 64-bit systems, where the length calculation is correctly performed in 64-bit arithmetic.3dCVE-2026-854389.8 CRI40.0%
——12MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability in StringToIvPFunction() where dimension, piece, and degree counts from encoded BHV_IPF payloads are used as allocation sizes and loop bounds without validation. Attackers can supply crafted payloads with mismatched dimension values to write attacker-controlled doubles past the end of the IvPBox weight array, causing memory corruption and potential code execution.3dCVE-2026-847625.3 MED10.9%
——3Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions.3d