Junglewise Threat Intelligence

CVE-2026-11149: Google Chrome privilege escalation in Extensions

CVE-2026-11149 · Severity: info · CVSS 6.5 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's extension system could allow a remote attacker to gain elevated privileges on a user's computer. This issue occurs if an attacker has already partially compromised the browser's rendering process and then lures a user to a specially crafted webpage. Successful exploitation could lead to unauthorized access to sensitive data or the ability to perform actions with higher-level system permissions.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Extensions component of Google Chrome. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to escalate their privileges. This is achieved by enticing a user to visit a maliciously crafted HTML page. By exploiting insufficient validation of untrusted input, the attacker can bypass security boundaries intended to isolate browser extensions. The vulnerability is addressed in Google Chrome version 149.0.7827.53 and later.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE-2026-11149 published.

References

Related threats