Junglewise Threat Intelligence

CVE-2026-11676: Google Chrome improper input validation in Dawn

CVE-2026-11676 · Severity: info · Published 2026-06-09

Technologies: Google Chrome, Google ChromeOS. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability in its Dawn component (the engine responsible for WebGPU graphics) could allow a malicious website to break out of the browser's security sandbox. If successful, an attacker who has already compromised the browser's rendering process could gain broader access to the underlying Linux or ChromeOS system, potentially leading to unauthorized data access or full system compromise.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Dawn component of Google Chrome for Linux and ChromeOS. Dawn is the implementation of the WebGPU standard in Chromium. The vulnerability is reachable by a remote attacker who can entice a user to visit a specially crafted HTML page. A successful exploit requires the attacker to have already achieved code execution within the sandboxed renderer process; from there, the insufficient validation in Dawn allows for a sandbox escape to the browser process or host operating system. Google has addressed this in version 149.0.7827.103.

Affected products

  • Google Chrome prior to 149.0.7827.103
  • Google ChromeOS prior to 149.0.7827.103

Timeline

  • 2026-05-27: disclosed: Reported to Chrome by Google researchers
  • 2026-06-08: patched: Fixed in Stable Channel Update 149.0.7827.102/.103
  • 2026-06-09: advisory: NVD publication date

References

Related threats