CVE-2026-11282
published 2026-06-05CVE-2026-11282: Insufficient policy enforcement in Sandbox in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape…
PriorityP350critical9.6CVSS 3.1
AVNACLPRNUIRSCCHIHAH
EPSS
0.24%
15.6th percentile
Insufficient policy enforcement in Sandbox in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 149.0.7827.53 | 149.0.7827.53 | |
| chrome | >= 149.0.7827.53 < 149.0.7827.53 | 149.0.7827.53 | |
| chrome_desktop | — | — | |
| paloalto | prisma_browser | — | — |
CVSS provenance
nvdv3.19.6CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
vendor_redhat9.6CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome up to 148.0.7778.216 on Linux Sandbox sandbox (ID 502023 / EUVD-2026-34743)
vuldb·2026-06-05·CVSS 9.6
CVE-2026-11282 [CRITICAL] Google Chrome up to 148.0.7778.216 on Linux Sandbox sandbox (ID 502023 / EUVD-2026-34743)
A vulnerability classified as critical was found in Google Chrome on Linux. This issue affects some unknown processing of the component Sandbox. Such manipulation leads to sandbox issue.
This vulnerability is listed as CVE-2026-11282. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
GHSA
Insufficient policy enforcement in Sandbox in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
ghsa_unreviewed·2026-06-05
CVE-2026-11282 [CRITICAL] CWE-693 Insufficient policy enforcement in Sandbox in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
Insufficient policy enforcement in Sandbox in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
Palo Alto
PAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026)
vendor_paloalto·2026-07-08·CVSS 9.6
CVE-2026-10881 [CRITICAL] PAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026)
PAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026)
Palo Alto Networks incorporated the following Chromium security fixes into our products: https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01245939337.html https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0482630350.html https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01750511403.html https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01962725236.html https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html CVE Summary CVE-2026-10881 Out of bounds rea
Chrome
Stable Channel Update for Desktop: CVE-2026-11282
vendor_chrome·2026-06-02
CVE-2026-11282 [LOW] Stable Channel Update for Desktop: CVE-2026-11282
Stable Channel Update for Desktop
CVE-2026-11282: Policy bypass in Sandbox. Reported by Google on 2026-04-13 [N/A][ 502069297 ] Low CVE-2026-11283: Policy bypass in Shortcuts
Reported by Google on 2026-04-13 [N/A][ 502073069 ] Low CVE-2026-11284: Side-channel information leakage in PerformanceAPIs
Severity: low
Red Hat
chromium-browser: Policy bypass in Sandbox
vendor_redhat·2026-06-02·CVSS 9.6
CVE-2026-11282 [CRITICAL] CWE-501 chromium-browser: Policy bypass in Sandbox
chromium-browser: Policy bypass in Sandbox
Insufficient policy enforcement in Sandbox in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
A policy bypass flaw was found in the Sandbox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=502023400
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
No detection rules found.
No public exploits indexed.
2026-06-05
Published