You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve 2026-11034
About this tag
CVE-2026-11034 is a medium-severity vulnerability in Google Chrome on Android, fixed before version 149.0.7827.53. The flaw involves insufficient validation in the Tab Group Sync feature, which could allow a remote attacker to inject script or HTML via malicious network traffic, leading to universal cross-site scripting (UXSS). A notable aspect of this CVE is a metadata mismatch: the NVD configuration ties the vulnerability to Android, while the public vendor reference points to a desktop stable-channel post, creating confusion for CPE-based asset management. Discussions on WindowsForum highlight this discrepancy and its implications for security teams tracking affected systems.
Google’s CVE-2026-11034 entry describes a medium-severity Chrome-on-Android flaw fixed before version 149.0.7827.53, where insufficient validation in Tab Group Sync could let a remote attacker inject script or HTML through malicious network traffic. The oddity is not the bug class; universal...