Vulnary
← back to the feed
Critical· 9.6official fix available

CVE-2026-11697

Google Chrome versions before 149.0.7827.103 contain a flaw in the UI where untrusted input is not properly validated. A remote attacker could trick a user into opening a crafted HTML page, potentially allowing a sandbox escape. The issue affects Chrome on Windows, macOS, and Linux, but there is no known active exploitation according to CISA KEV.

publishedJun 9, 2026
last modifiedJul 23, 2026
sourcesNVD
severity · cvss
9.6
critical · how bad it is
exploitation · epss
<1%
10th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 23, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

Google Chrome on Windows, macOS, and Linux.

02

Real-world impact

An attacker who successfully exploits this vulnerability could escape the Chrome sandbox, gaining higher privileges on the victim's system.

03

Why this severity

The CVSS base score is 9.6 (Critical) due to the network‑attack vector, low attack complexity, no privileges required, user interaction needed, and high impacts to confidentiality, integrity, and availability.

04

What to do about it

official fix available
recommended steps
  1. 011. Update Google Chrome to version 149.0.7827.103 or later.

NVD description

05

Timeline

  1. Jun 9, 2026 · Jun 9, 2026
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 23, 2026 · 12d ago
    Advisory updated
    The NVD record was last revised.
  3. Jul 24, 2026 · 11d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionRequired
ScopeChanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →