Junglewise Threat Intelligence

CVE-2026-11120: Google Chrome sandbox escape in Enterprise Reporting

CVE-2026-11120 · Severity: info · CVSS 6.5 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Enterprise Reporting component could allow a malicious website to bypass the browser's security sandbox. This component is used by organizations to monitor and manage browser security policies. If exploited, an attacker who has already gained a foothold in the browser could potentially gain full access to the underlying operating system and user data.

Technical details

This vulnerability is classified as improper input validation (CWE-20) within the Enterprise Reporting component of Google Chrome. The flaw exists because the browser does not sufficiently validate untrusted input, which can be leveraged by an attacker who has already achieved code execution within a compromised renderer process. By enticing a user to visit a specially crafted HTML page, the attacker can trigger this validation failure to escape the Chromium sandbox. A successful sandbox escape allows the attacker to execute arbitrary code with the privileges of the browser process on the host operating system. This issue is resolved in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: CVE-2026-11120 published

References

Related threats