Junglewise Threat Intelligence

CVE-2026-11677: Google Chrome race condition sandbox escape in Network component

CVE-2026-11677 · Severity: info · CVSS 8.8 · Published 2026-06-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for macOS could allow a remote attacker to escape the browser's security sandbox. This occurs if an attacker first compromises the browser's network process and then lures a user to a specially crafted website. Successfully exploiting this flaw could allow an attacker to gain unauthorized access to the underlying operating system, potentially compromising user data or system integrity.

Technical details

A race condition (CWE-362) exists in the Network component of Google Chrome for macOS. The vulnerability allows a remote attacker who has already achieved code execution within the compromised network process to escalate privileges and perform a sandbox escape. The attack is triggered when a user visits a maliciously crafted HTML page. This flaw is rated as High severity by Chromium. Users are advised to update to version 149.0.7827.103 or later to mitigate this risk.

Affected products

  • Google Chrome prior to 149.0.7827.103

Timeline

  • 2026-05-27: other: Reported to Google
  • 2026-06-08: patched: Fixed in Stable Channel Update 149.0.7827.102/.103
  • 2026-06-09: disclosed: CVE published

References

Related threats