← Browse

CVE-2026-11676

Medium

Elevated severity or exploit probability.

CVSS base
8.3 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
0.2%
14.1th percentile
CISA KEV
Not listed
Weakness / dates
CWE-20
Published 2026-06-09 · modified 2026-07-23

CVSS breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Attack VectorNNetwork
Attack ComplexityHHigh
Privileges RequiredNNone
User InteractionRRequired
ScopeCChanged
ConfidentialityHHigh
IntegrityHHigh
AvailabilityHHigh

Timeline

Description

Insufficient validation of untrusted input in Dawn in Google Chrome on Linux and ChromeOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Affected

google linux

References

Official: NVD · CVE.org