
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-11274 is a security feature bypass vulnerability caused by an inappropriate implementation in the DOM Distiller component of Google Chrome on iOS. It allows a remote attacker to bypass navigation restrictions by luring a user to visit a crafted HTML page. The vulnerability affects all versions of Google Chrome on iOS prior to 149.0.7827.53, disclosed on June 4–5, 2026, as part of the Chrome 149 stable channel release. It carries a CVSS v3.1 base score of 4.3 (Medium) and is rated Low severity by the Chromium security team (Chrome Releases, Github Advisory).
The root cause is classified as CWE-284 (Improper Access Control), stemming from an inappropriate implementation in Chrome's DOM Distiller feature on iOS — a component that simplifies web pages for reader mode. The flaw allows a remote attacker to craft a malicious HTML page that, when visited by a victim, causes the browser to improperly handle navigation restrictions, potentially allowing unauthorized navigation to restricted resources or origins. Exploitation requires user interaction (visiting the attacker-controlled page) and no special privileges. The Chromium issue tracker entry (ID 501760514) is currently access-restricted (Chrome Releases, Github Advisory).
Successful exploitation results in a limited integrity impact — specifically, an attacker can bypass navigation restrictions within Chrome on iOS, potentially redirecting users to unintended or restricted pages without their knowledge. There is no confidentiality or availability impact associated with this vulnerability. The scope is limited to the affected browser instance on iOS devices, and there is no evidence of lateral movement potential or significant data exposure risk (Github Advisory, Chrome Releases).
Google has addressed this vulnerability in Chrome version 149.0.7827.53 for iOS, released as part of the Chrome 149 stable channel update on June 2, 2026. Users should update Google Chrome on iOS to version 149.0.7827.53 or later immediately. Enabling automatic updates in the App Store is the recommended approach to ensure timely patching. No configuration-based workarounds have been published (Chrome Releases, Github Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."