You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2026-11029
About this tag
CVE-2026-11029 is a security vulnerability in Google Chrome's Drag and Drop handling on Android, classified as an insufficient-input-validation flaw. It was fixed before Chrome version 149.0.7827.53 and published by NVD on June 4, 2026, though a final NIST CVSS score is pending. The vulnerability is notable not as a direct sandbox escape from a simple page visit, but as a potential second-stage escape after an attacker has already compromised the renderer process. This distinction highlights the importance of browser sandboxing, where the renderer is treated as hostile and the containment boundary is critical. Discussions around CVE-2026-11029 emphasize that modern browser security relies on maintaining that containment line, making such flaws significant for understanding Chrome's defense-in-depth approach.
Google assigned CVE-2026-11029 to an insufficient-input-validation flaw in Chrome’s Drag and Drop handling on Android, fixed before version 149.0.7827.53 and published by NVD on June 4, 2026, where it remains without a final NIST CVSS score. The dry wording understates the interesting part: this...