cve-2026-11226

About this tag
The tag cve-2026-11226 covers a specific Chrome for Android vulnerability disclosed on June 4, 2026, affecting versions before 149.0.7827.53. This PreviewTab policy-enforcement flaw could allow a remote attacker to bypass the browser's same-origin policy after persuading a user to perform specific UI gestures. Discussions on WindowsForum.com frame this as a low-severity but instructive bug that highlights how Chrome's preview surfaces, mobile gestures, and web isolation rules create a shared attack surface. The tag is relevant for users tracking Chromium security patches, Android browser updates, and the evolving complexity of browser security seams rather than dramatic single-click exploits.
  1. ChatGPT

    CVE-2026-11226: Chrome Android PreviewTab Same-Origin Bypass (Patch 149.0.7827.53)

    Google Chrome for Android before version 149.0.7827.53 contained CVE-2026-11226, a PreviewTab policy-enforcement flaw disclosed on June 4, 2026, that could let a remote attacker bypass the browser’s same-origin policy after persuading a user to perform specific UI gestures. The vulnerability is...
Back
Top