
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-11120 is an improper input validation vulnerability in the Enterprise Reporting component of Google Chrome that allows a remote attacker who has already compromised the renderer process to potentially escape the browser sandbox via a crafted HTML page. It affects all versions of Google Chrome prior to 149.0.7827.53 on Windows, Mac, and Linux. The vulnerability was reported internally by Google on April 10, 2026, and patched with the Chrome 149 stable channel release on June 2, 2026. It carries a CVSS v3.1 base score of 9.6 (Critical), though Google's internal Chromium severity rating is Medium (Chrome Release Notes, Feedly).
The root cause is classified as CWE-20 (Improper Input Validation) in Chrome's Enterprise Reporting subsystem, which fails to adequately validate untrusted input received from a compromised renderer process. An attacker who has already achieved renderer process compromise — for example, through a separate renderer exploit — can supply a specially crafted HTML page that passes malformed or unexpected data to the Enterprise Reporting component, triggering a sandbox escape. The changed scope (S:C) in the CVSS vector reflects that successful exploitation crosses the sandbox boundary, allowing code execution outside the renderer's restricted environment. The Chromium issue tracker entry (ID 501467566) is currently access-restricted pending broad user update (Chrome Release Notes, Feedly).
Successful exploitation enables an attacker with a pre-compromised renderer process to escape Chrome's sandbox and execute arbitrary code with browser-level privileges on the underlying host system. This results in high confidentiality, integrity, and availability impact — an attacker could access sensitive data stored on the system, install malware, modify files, or pivot to other systems on the network. Because exploitation requires user interaction (visiting a crafted HTML page) and a prior renderer compromise, it is typically chained with a separate renderer vulnerability in a two-stage attack (Feedly).
Google has addressed CVE-2026-11120 in Chrome 149.0.7827.53 (Linux) and 149.0.7827.53/54 (Windows/Mac), released to the stable channel on June 2, 2026. Users and administrators should update Google Chrome to version 149.0.7827.53 or later immediately. As an interim measure, organizations should enforce policies preventing users from visiting untrusted or unknown websites, since user interaction is required to trigger the vulnerability. Enterprise administrators using Chrome's managed deployment should prioritize pushing the update via their software management infrastructure (Chrome Release Notes).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."