CVE-2026-11282
A flaw in Google Chrome’s Linux sandbox lets a remote attacker escape the browser’s security boundaries by loading a specially crafted HTML page. The vulnerability can give the attacker full control over the host system. It affects Chrome versions before 149.0.7827.53 on Linux.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Google Chrome on Linux, any version earlier than 149.0.7827.53. Typical users are Linux desktop users who browse the web with Chrome.
Real-world impact
An attacker could run arbitrary code on the victim’s machine, steal data, install malware, or take over the system after tricking the user into opening a malicious web page.
Why this severity
The CVSS score is 9.6 because the flaw allows remote exploitation with no authentication, gives complete compromise of confidentiality, integrity, and availability, and requires only a user interaction with a crafted page.
What to do about it
- 01Upgrade Google Chrome to version 149.0.7827.53 or later.
- 02Restart the browser to apply the update.
NVD description indicates fix version
Timeline
- Jun 5, 2026 · Jun 5, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
- Jul 24, 2026 · 11d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- chromereleases.googleblog.com/2026/06/stable-channel-upda…release notes
- issues.chromium.org/issues/502023400permissions required