CVE-2026-11029
A flaw in Chrome on Android lets a malicious web page escape the browser sandbox if the renderer process is compromised. The bug is triggered by Drag and Drop handling of untrusted input.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Google Chrome for Android, versions before 149.0.7827.53. Typical users are Android device owners who browse the web with Chrome.
Real-world impact
An attacker could run code outside the browser sandbox, potentially taking control of the device or accessing sensitive data.
Why this severity
The CVSS score of 9.6 reflects that the vulnerability is exploitable over the network, requires no user interaction beyond a drag‑and‑drop action, and gives an attacker full control of the system if successful.
What to do about it
- 01Upgrade Google Chrome to version 149.0.7827.53 or later.
NVD description indicates fix in version 149.0.7827.53
Timeline
- Jun 4, 2026 · Jun 4, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
- Jul 24, 2026 · 11d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- chromereleases.googleblog.com/2026/06/stable-channel-upda…vendor advisory
- issues.chromium.org/issues/497651688permissions required