Junglewise Threat Intelligence

CVE-2026-11070: Google Chrome sandbox escape in Chromoting on Windows

CVE-2026-11070 · Severity: info · CVSS 6.5 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Chromoting (Remote Desktop) feature on Windows could allow an attacker to bypass security protections. If an attacker has already compromised the browser's network process, they could use this flaw to escape the 'sandbox'—a security layer designed to keep malicious code from reaching the rest of the computer. This could lead to unauthorized access to the user's files and system operations.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Chromoting component of Google Chrome for Windows. The flaw allows a remote attacker who has already achieved code execution within the network process to bypass sandbox restrictions. By sending specially crafted network traffic that is insufficiently validated, the attacker can move from the restricted network process to the broader system. This vulnerability is mitigated by the requirement of a prior compromise of the network process. Google has addressed this issue in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE-2026-11070 published.

References

Related threats