
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-11260 is a Content Security Policy (CSP) bypass vulnerability caused by an inappropriate implementation in the Permissions component of Google Chrome. It affects all versions of Google Chrome prior to 149.0.7827.53 on Windows, Mac, and Linux. The vulnerability was disclosed on June 4–5, 2026, and patched in the Chrome 149 stable channel release announced June 2, 2026. It carries a CVSS v3.1 base score of 4.3 (Medium) and is rated Low severity by the Chromium security team (GitHub Advisory, Chrome Release).
The root cause is classified as CWE-693 (Protection Mechanism Failure), specifically an inappropriate implementation in Chrome's Permissions subsystem that fails to correctly enforce Content Security Policy restrictions. An unauthenticated remote attacker can exploit this by serving a specially crafted HTML page to a victim user; when the user visits the page, Chrome's permission handling logic incorrectly processes certain constructs, allowing CSP directives to be bypassed. Exploitation requires user interaction (the victim must visit the attacker-controlled page) but no special privileges on the attacker's part. The Chromium issue tracker entry (issue 499257860) is currently access-restricted (GitHub Advisory, Chrome Release).
Successful exploitation allows an attacker to bypass Content Security Policy protections on affected Chrome instances, resulting in a low-integrity impact with no direct confidentiality or availability consequences. In practice, a CSP bypass can enable injection of unauthorized scripts or resources into a web page that would otherwise be blocked, potentially facilitating cross-site scripting (XSS) attacks or loading of malicious content within the browser context. The scope is limited to the affected browser session and does not directly enable lateral movement or system-level compromise (GitHub Advisory, Feedly).
Google has addressed this vulnerability in Chrome 149.0.7827.53 (Linux) and 149.0.7827.53/54 (Windows/Mac), released June 2, 2026. Users and administrators should update Google Chrome to version 149.0.7827.53 or later immediately. Enabling automatic updates in Chrome ensures timely receipt of security patches. No configuration-based workaround is available; updating to the patched version is the only recommended remediation (Chrome Release, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."