CVE-2026-11697
Google Chrome versions before 149.0.7827.103 contain a flaw in the UI where untrusted input is not properly validated. A remote attacker could trick a user into opening a crafted HTML page, potentially allowing a sandbox escape. The issue affects Chrome on Windows, macOS, and Linux, but there is no known active exploitation according to CISA KEV.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Google Chrome on Windows, macOS, and Linux.
Real-world impact
An attacker who successfully exploits this vulnerability could escape the Chrome sandbox, gaining higher privileges on the victim's system.
Why this severity
The CVSS base score is 9.6 (Critical) due to the network‑attack vector, low attack complexity, no privileges required, user interaction needed, and high impacts to confidentiality, integrity, and availability.
What to do about it
- 011. Update Google Chrome to version 149.0.7827.103 or later.
NVD description
Timeline
- Jun 9, 2026 · Jun 9, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
- Jul 24, 2026 · 11d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- chromereleases.googleblog.com/2026/06/stable-channel-upda…vendor advisory
- issues.chromium.org/issues/518105731permissions required