Junglewise Threat Intelligence

CVE-2026-11690: Google Chrome OOB read and write in Media

CVE-2026-11690 · Severity: info · CVSS 8.8 · Published 2026-06-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in the media processing component of Google Chrome for macOS. This flaw could allow a malicious website to execute unauthorized code on a user's computer if they visit a specially crafted page. While the attack requires the browser's initial security layer to be bypassed first, a successful exploit could lead to full system compromise or unauthorized access to sensitive user data.

Technical details

This vulnerability is classified as an out-of-bounds (OOB) read and write within the Media component of Google Chrome for macOS. The flaw is triggered when the browser processes specially crafted HTML content. An attacker who has already compromised the renderer process (a 'sandbox escape' prerequisite or chained exploit) can leverage this OOB access to execute arbitrary code within the context of the browser's sandbox or potentially escalate privileges. The issue was addressed in Chrome version 149.0.7827.103. Google characterizes the severity as High.

Affected products

  • Google Chrome prior to 149.0.7827.103

Timeline

  • 2026-05-28: other: Reported to Google by internal researchers
  • 2026-06-08: patched: Fixed in Stable Channel Update 149.0.7827.102/.103
  • 2026-06-09: disclosed: NVD publication date

References

Related threats