Junglewise Threat Intelligence

CVE-2026-11184: Google Chrome insufficient policy enforcement in Actor

CVE-2026-11184 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Actor component could allow a malicious website to bypass security restrictions that normally control how the browser navigates between pages. By tricking a user into visiting a specially crafted HTML page, an attacker could force the browser to navigate to restricted or unintended locations. This could be used to circumvent security policies designed to protect users while they browse the web.

Technical details

A policy enforcement vulnerability exists in the Actor component of Google Chrome. The flaw stems from insufficient validation of navigation requests, which allows a remote attacker to bypass established navigation restrictions. To exploit this, an attacker must entice a user to visit a maliciously crafted HTML page. Successful exploitation enables the attacker to trigger navigations that should otherwise be blocked by browser security policies. The issue is resolved in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome Stable Channel Update released version 149.0.7827.53
  • 2026-06-04: disclosed: CVE published to NVD

References

Related threats