CVE-2026-11112
A flaw in Google Chrome on Linux lets a remote attacker who has already compromised the renderer process escape the sandbox by using a specially crafted Chrome Extension. The vulnerability is caused by insufficient validation of untrusted input in the Chromoting component. It can lead to full system compromise if exploited.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Google Chrome on Linux, versions earlier than 149.0.7827.53. Typical users are Linux desktop users running Chrome.
Real-world impact
An attacker could gain full control of the victim’s operating system, read or modify files, install malware, and bypass security controls.
Why this severity
The CVSS score of 9.6 reflects that the vulnerability can be exploited remotely with no authentication, requires user interaction (installing a malicious extension), and gives the attacker complete compromise of confidentiality, integrity, and availability.
What to do about it
- 01Update Google Chrome to version 149.0.7827.53 or later.
- 02Restart Chrome.
NVD description indicates fix in version 149.0.7827.53
Timeline
- Jun 4, 2026 · Jun 4, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
- Jul 24, 2026 · 11d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- chromereleases.googleblog.com/2026/06/stable-channel-upda…vendor advisory
- issues.chromium.org/issues/500541413permissions required