Junglewise Threat Intelligence

CVE-2026-11062: Google Chrome script injection in Extensions

CVE-2026-11062 · Severity: info · CVSS 6.1 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's extension system could allow a malicious browser extension to interfere with privileged internal browser pages. If a user is tricked into installing a specially crafted extension, the attacker could inject scripts or HTML into sensitive areas of the browser. This could potentially lead to unauthorized access to browser settings or other internal data.

Technical details

A vulnerability classified as insufficient policy enforcement exists in the Extensions component of Google Chrome. The flaw allows a crafted Chrome Extension to bypass security boundaries and inject arbitrary scripts or HTML into privileged pages (such as internal chrome:// pages). Exploitation requires an attacker to convince a user to install a malicious extension. Once installed, the extension can leverage this lack of enforcement to execute code in a higher-privilege context than typically permitted for web extensions. This issue is resolved in Google Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Fixed in Chrome 149.0.7827.53 stable channel update.
  • 2026-06-04: disclosed: CVE published to NVD.

References

Related threats