CVE-2026-11157
published 2026-06-04CVE-2026-11157: Script injection in Accessibility in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to inject…
PriorityP427medium5.4CVSS 3.1
AVNACLPRNUIRSUCLILAN
EPSS
0.12%
2.3th percentile
Script injection in Accessibility in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts or HTML (UXSS) via a crafted Chrome Extension. (Chromium security severity: Medium)
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 149.0.7827.53 | 149.0.7827.53 | |
| chrome | >= 149.0.7827.53 < 149.0.7827.53 | 149.0.7827.53 | |
| chrome_desktop | — | — | |
| paloalto | prisma_browser | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026)
vendor_paloalto·2026-07-08·CVSS 9.6
CVE-2026-10881 [CRITICAL] PAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026)
PAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026)
Palo Alto Networks incorporated the following Chromium security fixes into our products: https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01245939337.html https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0482630350.html https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01750511403.html https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01962725236.html https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html CVE Summary CVE-2026-10881 Out of bounds rea
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2026-11157
vendor_chrome·2026-06-17
CVE-2026-11157 Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2026-11157
Stable Channel Update for ChromeOS / ChromeOS Flex
CVE-2026-11157
Red Hat
chromium-browser: Script injection in Accessibility
vendor_redhat·2026-06-02·CVSS 5.4
CVE-2026-11157 [MEDIUM] CWE-79 chromium-browser: Script injection in Accessibility
chromium-browser: Script injection in Accessibility
Script injection in Accessibility in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts or HTML (UXSS) via a crafted Chrome Extension. (Chromium security severity: Medium)
A script injection flaw was found in the Accessibility component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=501823385
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Chrome
Stable Channel Update for Desktop: CVE-2026-11156
vendor_chrome·2026-06-02
CVE-2026-11156 [MEDIUM] Stable Channel Update for Desktop: CVE-2026-11156
Stable Channel Update for Desktop
CVE-2026-11156: Inappropriate implementation in CSS. Reported by Google on 2026-04-12 [N/A][ 501823385 ] Medium CVE-2026-11157: Script injection in Accessibility
Reported by Google on 2026-04-12 [N/A][ 501844153 ] Medium CVE-2026-11158: Insufficient validation of untrusted input in Downloads
Severity: medium
VulDB
Google Chrome up to 148.0.7778.216 Accessibility cross site scripting (ID 501823)
vuldb·2026-06-12·CVSS 5.4
CVE-2026-11157 [MEDIUM] Google Chrome up to 148.0.7778.216 Accessibility cross site scripting (ID 501823)
A vulnerability was found in Google Chrome. It has been classified as problematic. Impacted is an unknown function of the component Accessibility. Performing a manipulation results in cross site scripting.
This vulnerability is known as CVE-2026-11157. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
GHSA
Script injection in Accessibility in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts or HTML (UXSS) via a cra
ghsa_unreviewed·2026-06-05
CVE-2026-11157 [MEDIUM] CWE-94 Script injection in Accessibility in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts or HTML (UXSS) via a cra
Script injection in Accessibility in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts or HTML (UXSS) via a crafted Chrome Extension. (Chromium security severity: Medium)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-11157 chromium-browser: Script injection in Accessibility
bugzilla·2026-06-05·CVSS 5.4
CVE-2026-11157 [MEDIUM] CVE-2026-11157 chromium-browser: Script injection in Accessibility
CVE-2026-11157 chromium-browser: Script injection in Accessibility
Script injection in Accessibility in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts or HTML (UXSS) via a crafted Chrome Extension. (Chromium security severity: Medium)
Wiz
CVE-2025-11157 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2025-11157 [HIGH] CVE-2025-11157 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-11157 :
Python vulnerability analysis and mitigation
feast/sdk/python/feast/infra/compute_engines/kubernetes/main.py
yaml.load(..., Loader=yaml.Loader)
/var/feast/feature_store.yaml
/var/feast/materialization_config.yaml
Source : NVD
## 7.8
Score
Published January 1, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Python
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 50.4
Exploitation Probability (EPSS) 0.3
Affected packages and libraries
feast
Sources
NVD
pip Severity HIGH Has Fix Added at: Jan 02, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related
2026-06-04
Published