CVE-2026-11274
Google Chrome vulnerability analysis and mitigation

Overview

CVE-2026-11274 is a security feature bypass vulnerability caused by an inappropriate implementation in the DOM Distiller component of Google Chrome on iOS. It allows a remote attacker to bypass navigation restrictions by luring a user to visit a crafted HTML page. The vulnerability affects all versions of Google Chrome on iOS prior to 149.0.7827.53, disclosed on June 4–5, 2026, as part of the Chrome 149 stable channel release. It carries a CVSS v3.1 base score of 4.3 (Medium) and is rated Low severity by the Chromium security team (Chrome Releases, Github Advisory).

Technical details

The root cause is classified as CWE-284 (Improper Access Control), stemming from an inappropriate implementation in Chrome's DOM Distiller feature on iOS — a component that simplifies web pages for reader mode. The flaw allows a remote attacker to craft a malicious HTML page that, when visited by a victim, causes the browser to improperly handle navigation restrictions, potentially allowing unauthorized navigation to restricted resources or origins. Exploitation requires user interaction (visiting the attacker-controlled page) and no special privileges. The Chromium issue tracker entry (ID 501760514) is currently access-restricted (Chrome Releases, Github Advisory).

Impact

Successful exploitation results in a limited integrity impact — specifically, an attacker can bypass navigation restrictions within Chrome on iOS, potentially redirecting users to unintended or restricted pages without their knowledge. There is no confidentiality or availability impact associated with this vulnerability. The scope is limited to the affected browser instance on iOS devices, and there is no evidence of lateral movement potential or significant data exposure risk (Github Advisory, Chrome Releases).

Mitigation and workarounds

Google has addressed this vulnerability in Chrome version 149.0.7827.53 for iOS, released as part of the Chrome 149 stable channel update on June 2, 2026. Users should update Google Chrome on iOS to version 149.0.7827.53 or later immediately. Enabling automatic updates in the App Store is the recommended approach to ensure timely patching. No configuration-based workarounds have been published (Chrome Releases, Github Advisory).

Additional resources


SourceThis report was generated using AI

Related Google Chrome vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-16424CRITICAL9.6
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesJul 21, 2026
CVE-2026-16423HIGH8.8
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesJul 21, 2026
CVE-2026-16422HIGH7.5
  • Google Chrome logoGoogle Chrome
  • chromium
NoYesJul 21, 2026
CVE-2026-16421NONEN/A
  • Google Chrome logoGoogle Chrome
  • chromium
NoYesJul 21, 2026
CVE-2026-16420NONEN/A
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management