Junglewise Threat Intelligence

CVE-2026-11308: Google Chrome privilege escalation in Extensions

CVE-2026-11308 · Severity: info · CVSS 3.3 · Published 2026-06-05

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's extension system could allow a malicious extension to gain higher-than-intended permissions. To exploit this, an attacker must first trick a user into installing a specifically crafted malicious extension. Once installed, the extension could perform actions or access data beyond its normal restrictions, potentially compromising the user's privacy or browser security.

Technical details

An inappropriate implementation in the Extensions framework of Google Chrome prior to version 149.0.7827.53 allowed for privilege escalation. The vulnerability is triggered when a user installs a crafted malicious extension designed to exploit flaws in how Chrome manages extension permissions or execution contexts. An attacker can leverage this to perform actions with elevated privileges within the browser environment. The issue is mitigated by the requirement for user interaction (installing the extension) and has been addressed in the stable channel update to version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-05: disclosed: CVE published

References

Related threats