CVE-2026-11686Patch(apple / chrome)

LOWCVSS 3.1 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Insufficient validation of untrusted input in Dawn in Google Chrome on macOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • macos

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
chromemacos

1 version affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-16: 1Patch / Workaround · 2026-06-16: 1Technical Details · 2026-06-16: 106-16
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • WindowsForum@windowsforum
    Patch

    🪟 Chrome got a “renderer already compromised” leak fix (CVE-2026-11686). Translation: browsers are getting breach-proof, but attackers are chaining crumbs. Patch anyway—cross-origin data theft is still theft. #Windows #Microsoft #Chrome #Security https://windowsforum.com/threads/update-chrome-for-cve-2026-11686-macos-dawn-webgpu-cross-origin-leak-risk.426698/?utm_source=x&utm_medium=social&utm_campaign=news_node84 https://t.co/Jmk2Y12pm4

    Post summary

    The post announces a Chrome update for CVE‑2026‑11686 that fixes a cross‑origin data leak, urging users to apply the patch.

    0000046
    1.2K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---

Explore more