Critical· 9.6official fix available
CVE-2026-11213
A flaw in Google Chrome’s Reading Mode lets a remote attacker escape the browser sandbox by loading a specially crafted HTML page. The bug is only present in versions older than 149.0.7827.53.
publishedJun 4, 2026
last modifiedJul 23, 2026
sourcesNVD
severity · cvss
9.6
critical · how bad it is
exploitation · epss
<1%
9th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 23, 2026
An official fix is available, so this entry is kept for 30 days and then removed automatically.
01
Who is affected
Google Chrome browsers older than version 149.0.7827.53 on Windows, macOS, and Linux.
02
Real-world impact
An attacker could run code outside the browser sandbox, potentially taking control of the victim’s computer or accessing sensitive data.
03
Why this severity
The CVSS score of 9.6 reflects that the vulnerability can be exploited remotely with no user interaction, gives an attacker full control over the system, and is highly likely to be used in the wild.
04
What to do about it
official fix available
recommended steps
- 011. Update Google Chrome to version 149.0.7827.53 or later.
- 022. Restart the browser.
NVD description
05
Timeline
- Jun 4, 2026 · Jun 4, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
- Jul 24, 2026 · 11d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
06
How it’s attacked
Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionRequired
ScopeChanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07
References & advisories
- chromereleases.googleblog.com/2026/06/stable-channel-upda…vendor advisory
- issues.chromium.org/issues/507382702permissions required
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →