CVE-2026-11066
A critical flaw in Google Chrome’s ANGLE component lets attackers escape the browser sandbox by loading a specially crafted HTML page. The issue stems from insufficient input validation, enabling remote code execution. Updating Chrome to the latest version removes the vulnerability.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Google Chrome browsers older than version 149.0.7827.53, affecting users on any platform who run the Chrome web browser.
Real-world impact
An attacker could run arbitrary code outside the browser sandbox, potentially taking full control of the victim’s computer, stealing data, or installing malware.
Why this severity
The CVSS score of 9.6 reflects the vulnerability’s high exploitability (network attack, low complexity, no privileges required) and its severe impact (complete compromise of confidentiality, integrity, and availability).
What to do about it
- 01Upgrade Google Chrome to version 149.0.7827.53 or later.
- 02Restart the browser to apply the update.
NVD-referenced vendor advisory
Timeline
- Jun 4, 2026 · Jun 4, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
- Jul 23, 2026 · 12d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- chromereleases.googleblog.com/2026/06/stable-channel-upda…release notes
- issues.chromium.org/issues/499124128permissions required