Junglewise Threat Intelligence

CVE-2026-11697: Google Chrome sandbox escape in UI

CVE-2026-11697 · Severity: info · CVSS 8.8 · Published 2026-06-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in the browser's user interface component could allow a malicious website to bypass security restrictions known as the 'sandbox.' If successful, an attacker could potentially gain unauthorized access to the underlying operating system or user data, moving beyond the isolated environment where websites normally run.

Technical details

A vulnerability exists in Google Chrome's UI component due to insufficient validation of untrusted input. By enticing a user to visit a specially crafted HTML page, a remote attacker can exploit this flaw to perform a sandbox escape. This bypasses the security boundaries designed to isolate the browser process from the host operating system. The issue is categorized as High severity by Chromium and is addressed in version 149.0.7827.103. The vulnerability is tracked as CWE-20 (Improper Input Validation).

Affected products

  • Google Chrome prior to 149.0.7827.103

Timeline

  • 2026-06-08: disclosed
  • 2026-06-08: patched: Fixed in version 149.0.7827.103
  • 2026-06-09: advisory

References

Related threats