Junglewise Threat Intelligence

CVE-2026-11112: Google Chrome improper input validation in Chromoting

CVE-2026-11112 · Severity: info · CVSS 0 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in the Chromoting (Remote Desktop) feature of Google Chrome for Linux. An attacker who has already partially compromised the browser could use a specially crafted extension to break out of the browser's security sandbox. This could allow the attacker to gain broader access to the underlying operating system and the user's private data.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Chromoting component of Google Chrome for Linux. The flaw allows a remote attacker who has already compromised the renderer process to escalate their privileges. By utilizing a maliciously crafted Chrome Extension, the attacker can bypass sandbox restrictions to execute code outside of the restricted browser environment. This issue was addressed in Chrome version 149.0.7827.53 for Linux.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released for Linux
  • 2026-06-04: disclosed: CVE-2026-11112 published

References

Related threats