Junglewise Threat Intelligence

CVE-2026-11213: Google Chrome sandbox escape in Reading Mode

CVE-2026-11213 · Severity: info · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Reading Mode, a feature that simplifies web pages for easier reading, contained a security flaw that could allow a malicious website to bypass the browser's security boundaries. If an attacker first compromises the browser's rendering process, they could use this vulnerability to escape the 'sandbox'—a restricted environment designed to prevent malicious code from accessing the rest of the computer. This could lead to unauthorized access to the user's local files or system operations.

Technical details

A vulnerability exists in Google Chrome's Reading Mode due to improper input validation (CWE-20). The flaw allows a remote attacker who has already achieved code execution within the sandboxed renderer process to escalate privileges and perform a sandbox escape. By enticing a user to visit a specially crafted HTML page, the attacker can exploit the insufficient validation to interact with higher-privilege browser processes. This vulnerability is mitigated by the requirement of a prior renderer compromise. The issue is addressed in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome version 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE published in NVD.

References

Related threats