Junglewise Threat Intelligence

CVE-2026-11157: Google Chrome script injection in Accessibility

CVE-2026-11157 · Severity: info · CVSS 6.1 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's accessibility features could allow a malicious browser extension to inject unauthorized scripts or HTML into web pages. To exploit this, an attacker must first trick a user into installing a specifically crafted malicious extension. If successful, the attacker could potentially bypass security boundaries to interact with or steal data from other websites the user visits.

Technical details

A script injection vulnerability exists in the Accessibility component of Google Chrome. The flaw allows a crafted Chrome Extension to bypass security boundaries and inject arbitrary scripts or HTML into other origins, a condition known as Universal Cross-Site Scripting (UXSS). Exploitation requires a user to install a malicious extension, which then leverages improper control of code generation (CWE-94) within the accessibility framework. This could lead to the execution of unauthorized code in the context of any website the user visits. The issue is resolved in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE-2026-11157 published.

References

Related threats