Junglewise Threat Intelligence

CVE-2026-11102: Google Chrome arbitrary code execution in Isolated Web Apps

CVE-2026-11102 · Severity: info · CVSS 6.5 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome's Isolated Web Apps feature could allow a remote attacker to execute unauthorized code on a user's computer. This occurs when a user interacts with a specially crafted malicious file. While the code execution is restricted within a security sandbox, it represents a significant breakdown of the browser's intended security boundaries.

Technical details

A vulnerability classified as an 'Inappropriate Implementation' exists in the Isolated Web Apps (IWA) component of Google Chrome. The flaw allows a remote attacker to achieve arbitrary code execution (ACE) within the browser's sandbox environment. The attack is triggered when a user processes or opens a malicious file designed to exploit the implementation weakness. While the impact is mitigated by the sandbox, it allows for the execution of untrusted code within that restricted context. The issue is resolved in Chrome version 149.0.7827.53 and later.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: CVE-2026-11102 published

References

Related threats