Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2329 articles · 160680 vulns · 36/41 feeds (7d)
← Back to list
9.6
CVE-2026-11070EXPLOITEDPATCHED
google · chrome

CVE-2026-11070: Insufficient validation of untrusted input in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a re

Description

Insufficient validation of untrusted input in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the network process to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: Medium)

Affected Products

VendorProductVersions
googlechrome149.0.7827.53

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
googlechromecert_advisory90%
microsoftedgecert_advisory90%

References

  • https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop.html
  • https://issues.chromium.org/issues/499225384

Related News (3 articles)

Tier B
BSI Advisories2d ago
[NEU] [hoch] Google Chrome und Microsoft Edge: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB2d ago
CVE-2026-11070 | Google Chrome up to 148.0.7778.216 on Windows Chromoting sandbox (ID 499225)
→ No new info (linked only)
Tier B
CERT-FR2d ago
Multiples vulnérabilités dans Google Chrome (05 juin 2026)
→ No new info (linked only)
CVSS 3.19.6 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
149.0.7827.53
CWECWE-20
PublishedJun 4, 2026
Last enriched2d agov2
Trending Score49
Source articles3
Independent3
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2025-48595EXP
CVE-2025-48595: In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to
Trending: 98
CRITICALCVE-2026-10881EXP
CVE-2026-10881: Out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially p
Trending: 52
HIGHCVE-2026-11255EXP
CVE-2026-11255: Insufficient validation of untrusted input in Storage Access API in Google Chrome prior to 149.0.7827.53 allowed a remot
Trending: 51
CRITICALCVE-2026-11082EXP
CVE-2026-11082: Race in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the rendere
Trending: 49
CRITICALCVE-2026-11088EXP
CVE-2026-11088: Integer overflow in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the rend
Trending: 49

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 4, 2026
Discovered by ZDM
Jun 4, 2026
Updated: description, affectedVersions, severity, activelyExploited
Jun 5, 2026
Actively Exploited
Jun 5, 2026
Patch Available
Jun 5, 2026

Version History

v2
Last enriched 2d ago
v2Tier C2d ago

Updated severity to CRITICAL, added affected version 148.0.7778.216, and corrected exploit availability to false.

descriptionaffectedVersionsseverityactivelyExploited
via VulDB
v12d ago

Initial creation