Junglewise Threat Intelligence

CVE-2026-11655: Google Chrome integer overflow in Media on macOS

CVE-2026-11655 · Severity: info · CVSS 8.8 · Published 2026-06-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability has been identified in Google Chrome for macOS that could allow an attacker to bypass the browser's security sandbox. Chrome uses a sandbox to isolate web pages from the rest of the computer, preventing malicious sites from accessing personal files or system settings. If exploited, this flaw could allow an attacker who has already gained control of a browser tab to escape that isolation and execute unauthorized commands on the user's Mac.

Technical details

An integer overflow vulnerability exists in the Media component of Google Chrome for macOS. The flaw can be triggered by a crafted HTML page. An attacker who has already compromised the renderer process (for example, through a separate memory corruption bug) can exploit this overflow to achieve a sandbox escape. This would allow the attacker to execute arbitrary code outside of the restricted browser environment on the host operating system. The issue is addressed in Chrome version 149.0.7827.103 for Mac.

Affected products

  • Google Chrome prior to 149.0.7827.103

Timeline

  • 2026-05-15: disclosed: Reported to Chrome by Google researchers
  • 2026-06-08: patched: Fixed in Stable Channel Update 149.0.7827.102/.103
  • 2026-06-09: advisory: NVD publication date

References

Related threats