Junglewise Threat Intelligence

CVE-2026-11150: Google Chrome UXSS in XML implementation

CVE-2026-11150 · Severity: info · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in how the browser handles XML data could allow a malicious website to execute unauthorized scripts or display fake content on other websites you have open. This type of attack, known as Universal Cross-Site Scripting (UXSS), can lead to the theft of sensitive information like login session cookies or personal data from other active web accounts.

Technical details

A Universal Cross-Site Scripting (UXSS) vulnerability exists in Google Chrome's XML implementation prior to version 149.0.7827.53. The flaw stems from an inappropriate implementation that fails to properly isolate execution contexts when processing XML data. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass Same-Origin Policy (SOP) protections and execute arbitrary JavaScript or inject HTML into the context of any website currently open in the browser. This issue is addressed in Chrome version 149.0.7827.53 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: CVE published to NVD

References

Related threats