Junglewise Threat Intelligence

CVE-2026-11689: Google Chrome insufficient policy enforcement in Passwords

CVE-2026-11689 · Severity: info · CVSS 0 · Published 2026-06-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability in the browser's password management component could allow a remote attacker to bypass 'site isolation,' a critical security feature that keeps data from different websites separate. If exploited, an attacker who has already partially compromised the browser could potentially access sensitive information from other websites, such as login credentials or private data.

Technical details

A vulnerability exists in Google Chrome's Passwords component due to insufficient policy enforcement and improper input validation (CWE-20). The flaw allows a remote attacker who has already compromised the renderer process to bypass site isolation protections by using a specially crafted HTML page. Site isolation is a security boundary intended to ensure that pages from different websites run in separate processes to prevent data leakage. This vulnerability was addressed in Chrome version 149.0.7827.103 for Windows and Mac, and 149.0.7827.102 for Linux.

Affected products

  • Google Chrome prior to 149.0.7827.103

Timeline

  • 2026-05-28: other: Reported to Google by internal researchers
  • 2026-06-08: patched: Stable channel update released
  • 2026-06-09: disclosed: NVD publication date

References

Related threats