CVE-2026-11157
EUVD-2026-3461804.06.2026, 23:17
Script injection in Accessibility in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts or HTML (UXSS) via a crafted Chrome Extension. (Chromium security severity: Medium)
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| chrome | 𝑥 ≤ 149.0.7827.53 | CNA |
Debian Releases
Vulnerability Media Exposure