Executive brief
A vulnerability in Google Chrome's Autofill feature could allow a remote attacker to bypass security protections. By using malicious network traffic, an attacker could potentially escape the browser's 'sandbox,' which is the security layer designed to prevent web content from interacting with the rest of the computer. This could lead to unauthorized access to the user's system or data.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Autofill component of Google Chrome. The flaw stems from insufficient validation of untrusted input received via network traffic. A remote attacker can exploit this by delivering specially crafted malicious network traffic to a victim's browser. If successful, this could allow the attacker to perform a sandbox escape, potentially gaining higher privileges on the host system. The issue is resolved in Google Chrome version 149.0.7827.53 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE-2026-11207 published.