You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve 2026 11270
About this tag
CVE-2026-11270 is a Google Chrome for Android vulnerability published on June 4, 2026, affecting versions before 149.0.7827.53. It allows a remote attacker to leak cross-origin data through a crafted HTML page. Chromium classifies it as low severity, while CISA's ADP scoring gives it a medium CVSS 3.1 score of 6.5 due to potentially high confidentiality impact. This is not a browser-takeover bug but a privacy boundary failure that administrators and mobile-heavy organizations should address. The patch involves updating Chrome for Android to version 149.0.7827.53 or later. The tag covers discussion of the vulnerability, its severity split, and patching guidance.
CVE-2026-11270 is a Google Chrome for Android vulnerability published on June 4, 2026, affecting versions before 149.0.7827.53 and allowing a remote attacker to leak cross-origin data through a crafted HTML page. The flaw is classified by Chromium as low severity, while CISA’s ADP scoring gives...