Junglewise Threat Intelligence

CVE-2026-11266: Google Chrome Safe Browsing bypass via malicious file

CVE-2026-11266 · Severity: info · CVSS 0 · Published 2026-06-05

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Safe Browsing feature could allow a malicious file to bypass security checks. Safe Browsing is a service that identifies unsafe websites and files to protect users from malware and phishing. If exploited, an attacker could potentially deliver harmful files to a user's system without the browser providing the standard security warnings.

Technical details

An inappropriate implementation vulnerability exists in the Safe Browsing component of Google Chrome. The flaw allows a remote attacker to bypass the Safe Browsing security mechanism by utilizing a specifically crafted malicious file. This bypass occurs because the implementation fails to correctly process or categorize certain file types or delivery methods, preventing the browser from triggering security warnings. The vulnerability is reachable via the network and requires a user to interact with or download a malicious file. Google has addressed this issue in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-05: disclosed: CVE published.

References

Related threats