You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2026-11175
About this tag
CVE-2026-11175 is a security vulnerability affecting Google Chrome on Android versions prior to 149.0.7827.53. Disclosed on June 4, 2026, this flaw allows a crafted HTML page to spoof security-related UI in the browser's Messages surface, enabling UI spoofing attacks. Unlike typical memory corruption issues, this bug misleads users about the security state of the browser. The National Vulnerability Database initially recorded it as a compound Chrome-and-Android configuration problem, but it is specifically a Chrome-for-Android vulnerability. This distinction is important for vulnerability management systems. Discussions on WindowsForum cover the fix, risk management, and implications for enterprise security teams.
Google Chrome on Android versions before 149.0.7827.53 were assigned CVE-2026-11175 on June 4, 2026, after Google disclosed that a crafted HTML page could spoof security-related UI in the browser’s Messages surface. The flaw is not a classic memory-corruption emergency, but it lands in a class...