CVE-2026-11150
published 2026-06-04CVE-2026-11150: Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted…
PriorityP426medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.16%
5.5th percentile
Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 149.0.7827.53 | 149.0.7827.53 | |
| chrome | >= 149.0.7827.53 < 149.0.7827.53 | 149.0.7827.53 | |
| chrome_desktop | — | — | |
| paloalto | prisma_browser | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026)
vendor_paloalto·2026-07-08·CVSS 9.6
CVE-2026-10881 [CRITICAL] PAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026)
PAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026)
Palo Alto Networks incorporated the following Chromium security fixes into our products: https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01245939337.html https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0482630350.html https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01750511403.html https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01962725236.html https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html CVE Summary CVE-2026-10881 Out of bounds rea
Chrome
Stable Channel Update for Desktop: CVE-2026-11150
vendor_chrome·2026-06-02
CVE-2026-11150 [MEDIUM] Stable Channel Update for Desktop: CVE-2026-11150
Stable Channel Update for Desktop
CVE-2026-11150: Inappropriate implementation in XML. Reported by Google on 2026-04-11 [N/A][ 501740323 ] Medium CVE-2026-11151: Insufficient validation of untrusted input in Password Manager
Reported by Google on 2026-04-11 [N/A][ 501762953 ] Medium CVE-2026-11152: Object lifecycle issue in Dawn
Severity: medium
Red Hat
chromium-browser: Inappropriate implementation in XML
vendor_redhat·2026-06-02·CVSS 6.1
CVE-2026-11150 [MEDIUM] CWE-79 chromium-browser: Inappropriate implementation in XML
chromium-browser: Inappropriate implementation in XML
Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)
An inappropriate implementation flaw was found in the XML component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=501740299
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
VulDB
Google Chrome up to 148.0.7778.216 XML cross site scripting (ID 501740)
vuldb·2026-06-12·CVSS 6.1
CVE-2026-11150 [MEDIUM] Google Chrome up to 148.0.7778.216 XML cross site scripting (ID 501740)
A vulnerability, which was classified as problematic, was found in Google Chrome. This affects an unknown part of the component XML. The manipulation results in cross site scripting.
This vulnerability is reported as CVE-2026-11150. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.
GHSA
Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
ghsa_unreviewed·2026-06-05
CVE-2026-11150 Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)
No detection rules found.
No public exploits indexed.
2026-06-04
Published