CVE-2026-11254
published 2026-06-05CVE-2026-11254: Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page…
PriorityP419medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
EPSS
0.18%
7.3th percentile
Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bytecodealliance | wasmtime | >= 25.0.0 < 36.0.7 | 36.0.7 |
| bytecodealliance | wasmtime | >= 37.0.0 < 42.0.2 | 42.0.2 |
| bytecodealliance | wasmtime | >= 43.0.0 < 43.0.1 | 43.0.1 |
| chrome | < 149.0.7827.53 | 149.0.7827.53 | |
| chrome | >= 149.0.7827.53 < 149.0.7827.53 | 149.0.7827.53 | |
| chrome_desktop | — | — | |
| paloalto | prisma_browser | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026)
vendor_paloalto·2026-07-08·CVSS 9.6
CVE-2026-10881 [CRITICAL] PAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026)
PAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026)
Palo Alto Networks incorporated the following Chromium security fixes into our products: https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01245939337.html https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0482630350.html https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01750511403.html https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01962725236.html https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html CVE Summary CVE-2026-10881 Out of bounds rea
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2026-11254
vendor_chrome·2026-06-17
CVE-2026-11254 Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2026-11254
Stable Channel Update for ChromeOS / ChromeOS Flex
CVE-2026-11254
Red Hat
chromium-browser: Inappropriate implementation in Permissions
vendor_redhat·2026-06-02·CVSS 4.3
CVE-2026-11254 [MEDIUM] CWE-1021 chromium-browser: Inappropriate implementation in Permissions
chromium-browser: Inappropriate implementation in Permissions
Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
An inappropriate implementation flaw was found in the Permissions component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=498405554
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Chrome
Stable Channel Update for Desktop: CVE-2026-11252
vendor_chrome·2026-06-02
CVE-2026-11252 [LOW] Stable Channel Update for Desktop: CVE-2026-11252
Stable Channel Update for Desktop
CVE-2026-11252: Policy bypass in Content Settings. Reported by Google on 2026-04-01 [N/A][ 498397912 ] Low CVE-2026-11253: Race in Permissions
Reported by Google on 2026-04-01 [N/A][ 498405554 ] Low CVE-2026-11254: Inappropriate implementation in Permissions
Severity: low
GHSA
Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page.
ghsa_unreviewed·2026-06-05
CVE-2026-11254 [MEDIUM] CWE-451 Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page.
Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
GHSA
Wasmtime has host panic when Winch compiler executes `table.fill`
ghsa·2026-04-09
CVE-2026-34946 [MEDIUM] CWE-248 Wasmtime has host panic when Winch compiler executes `table.fill`
Wasmtime has host panic when Winch compiler executes `table.fill`
### Impact
Wasmtime's Winch compiler contains a vulnerability where the compilation of the `table.fill` instruction can result in a host panic. This means that a valid guest can be compiled with Winch, on any architecture, and cause the host to panic. This represents a denial-of-service vulnerability in Wasmtime due to guests being able to trigger a panic.
The specific issue is that a historical refactoring, #11254, changed how compiled code referenced tables within the `table.*` instructions. This refactoring forgot to update the Winch code paths associated as well, meaning that Winch was using the wrong indexing scheme. Due to the feature support of Winch the only problem that can result is tables being mixed up or none
No detection rules found.
No public exploits indexed.
2026-06-05
Published