Junglewise Threat Intelligence

CVE-2026-11218: Google Chrome inappropriate implementation in PlatformIntegration

CVE-2026-11218 · Severity: info · CVSS 4.6 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome on Windows could allow a remote attacker to execute unauthorized code on a user's computer. To exploit this, an attacker must trick a user into performing specific interactions with the browser's interface and opening a malicious file. This could lead to a compromise of the user's local system and data.

Technical details

A vulnerability classified as an 'Inappropriate Implementation' exists within the PlatformIntegration component of Google Chrome for Windows. The flaw is triggered when a remote attacker successfully induces a user to perform specific, non-standard UI gestures while interacting with a malicious file. This sequence of actions can bypass intended security boundaries to achieve arbitrary code execution in the context of the browser process. The vulnerability is specific to the Windows platform and was addressed in Chrome version 149.0.7827.53. While the impact is code execution, the requirement for specific user interaction (UI gestures) resulted in a 'Low' severity rating from Chromium.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE-2026-11218 published.

References

Related threats