Junglewise Threat Intelligence

CVE-2026-11236: Google Chrome insufficient policy enforcement in Web Bluetooth

CVE-2026-11236 · Severity: info · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its Web Bluetooth component could allow a remote attacker who has already partially compromised the browser to bypass security restrictions (sandbox escape). This could lead to unauthorized access to the underlying operating system or user data beyond the browser's normal security boundaries.

Technical details

An insufficient policy enforcement vulnerability exists in the Web Bluetooth component of Google Chrome. The flaw allows a remote attacker to perform a sandbox escape if they have already achieved code execution within the renderer process (e.g., via a separate exploit). By leveraging a specially crafted HTML page, the attacker can bypass the security boundaries intended to isolate the browser's rendering engine from the rest of the system. This issue is addressed in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: CVE published

References

Related threats