CVE-2026-11200Active Exploitation(apple / chrome)

MEDIUMCVSS 6.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for apple chrome systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Inappropriate implementation in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-346CWE-352

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-05: 1Active Exploitation · 2026-02-05: 102-05
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Valentin Scerbacov@notVallium
    Active Exploitation

    Your WordPress backup plugin just leaked your entire database. 💀 CVE-2026-11200 is live. If you're using UpdraftPlus or similar, check your versions NOW. This is why we moved everything to infrastructure-level JetBackup. Full technical breakdown on why your "safety net" is actually a trap: https://t.me/webhostmost Are you still trusting PHP to handle your data security? #WebHostMost

    Post summary

    The post alerts that CVE‑2026‑11200 is live and poses a database leak risk for UpdraftPlus users, urging a move to JetBackup but offering no patch or exploit details.

    0000058
    29 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more