CVE-2026-11281
published 2026-06-05CVE-2026-11281: Integer overflow in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to obtain potentially sensitive information from…
PriorityP421medium5CVSS 3.1
AVLACLPRLUIRSUCHINAN
EPSS
0.08%
0.4th percentile
Integer overflow in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted ETW event. (Chromium security severity: Low)
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 149.0.7827.53 | 149.0.7827.53 | |
| chrome | >= 149.0.7827.53 < 149.0.7827.53 | 149.0.7827.53 | |
| chrome_desktop | — | — | |
| paloalto | prisma_browser | — | — |
CVSS provenance
nvdv3.15.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome up to 148.0.7778.216 on Windows Chromoting integer overflow (ID 501900 / EUVD-2026-34742)
vuldb·2026-06-05·CVSS 5.0
CVE-2026-11281 [MEDIUM] Google Chrome up to 148.0.7778.216 on Windows Chromoting integer overflow (ID 501900 / EUVD-2026-34742)
A vulnerability was found in Google Chrome on Windows. It has been declared as critical. The affected element is an unknown function of the component Chromoting. Such manipulation leads to integer overflow.
This vulnerability is listed as CVE-2026-11281. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
GHSA
Integer overflow in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted ETW event.
ghsa_unreviewed·2026-06-05
CVE-2026-11281 [MEDIUM] CWE-190 Integer overflow in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted ETW event.
Integer overflow in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted ETW event. (Chromium security severity: Low)
Palo Alto
PAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026)
vendor_paloalto·2026-07-08·CVSS 9.6
CVE-2026-10881 [CRITICAL] PAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026)
PAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026)
Palo Alto Networks incorporated the following Chromium security fixes into our products: https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01245939337.html https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0482630350.html https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01750511403.html https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01962725236.html https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html CVE Summary CVE-2026-10881 Out of bounds rea
Red Hat
chromium-browser: Integer overflow in Chromoting
vendor_redhat·2026-06-02·CVSS 5.0
CVE-2026-11281 [MEDIUM] CWE-190 chromium-browser: Integer overflow in Chromoting
chromium-browser: Integer overflow in Chromoting
Integer overflow in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted ETW event. (Chromium security severity: Low)
An integer overflow flaw was found in the Chromoting component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=501900366
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Chrome
Stable Channel Update for Desktop: CVE-2026-11279
vendor_chrome·2026-06-02
CVE-2026-11279 [LOW] Stable Channel Update for Desktop: CVE-2026-11279
Stable Channel Update for Desktop
CVE-2026-11279: Out of bounds read in DevTools. Reported by Google on 2026-04-12 [N/A][ 501892820 ] Low CVE-2026-11280: Insufficient validation of untrusted input in Signin
Reported by Google on 2026-04-12 [N/A][ 501900366 ] Low CVE-2026-11281: Integer overflow in Chromoting
Severity: low
No detection rules found.
No public exploits indexed.
2026-06-05
Published