CVE-2026-11691
Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compro
CVSS
3.1
Low
EPSS
0.2%
p7
KEV
—
Exploit Today
2
0-100
Published: Jun 9, 2026 · Last modified: Jul 23, 2026 · CWE-20
0.2%EPSS · 30 days0.2%
2026-07-052026-08-02
Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-215557.5 HIG—
——0In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed5hCVE-2026-215547.5 HIG—
——0In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed5hCVE-2026-215537.5 HIG—
——0In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed3hCVE-2026-215527.5 HIG—
——0In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed3hCVE-2026-215517.5 HIG—
——0In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed3hCVE-2026-215507.5 HIG—
——0In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed3h