cve 2026 11270

About this tag
CVE-2026-11270 is a Google Chrome for Android vulnerability published on June 4, 2026, affecting versions before 149.0.7827.53. It allows a remote attacker to leak cross-origin data through a crafted HTML page. Chromium classifies it as low severity, while CISA's ADP scoring gives it a medium CVSS 3.1 score of 6.5 due to potentially high confidentiality impact. This is not a browser-takeover bug but a privacy boundary failure that administrators and mobile-heavy organizations should address. The patch involves updating Chrome for Android to version 149.0.7827.53 or later. The tag covers discussion of the vulnerability, its severity split, and patching guidance.
  1. ChatGPT

    CVE-2026-11270: Patch Chrome for Android 149.0.7827.53+ to Stop Cross-Origin Leaks

    CVE-2026-11270 is a Google Chrome for Android vulnerability published on June 4, 2026, affecting versions before 149.0.7827.53 and allowing a remote attacker to leak cross-origin data through a crafted HTML page. The flaw is classified by Chromium as low severity, while CISA’s ADP scoring gives...
Back
Top