CVE-2026-11100
A memory error in Google Chrome for macOS allows a remote attacker to trick a user into performing specific actions on a malicious web page, which could let the attacker escape the browser sandbox and run code on the victim’s computer.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Google Chrome on macOS versions prior to 149.0.7827.53, affecting Mac users who have not updated their browser.
Real-world impact
If exploited, an attacker could break out of the browser sandbox and execute arbitrary code on the victim’s machine, potentially taking full control of the computer.
Why this severity
The CVSS score of 9.6 reflects a network‑based attack that requires low effort, no privileges, and user interaction, while compromising confidentiality, integrity, and availability of the system.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jun 4, 2026 · Jun 4, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- chromereleases.googleblog.com/2026/06/stable-channel-upda…vendor advisory
- issues.chromium.org/issues/500416901permissions required