HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-11693Published Modified CNA Chrome

CVE-2026-11693: Inappropriate implementation in Plugins in Google Chrome prior to 149

Inappropriate implementation in Plugins in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

Metrics

CVSS v3.1
8.1
Severity
HIGH
Fixed in
149.0.7827.103
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

This is a security-boundary bypass in Google Chrome's plugin handling, present in all versions before 149.0.7827.103. An attacker must lure the victim to a crafted HTML page, and must have already compromised Chrome's renderer process; from there the flaw lets them break site isolation, the mechanism that keeps different websites' data separated in memory. Successful exploitation gives the attacker read access to data belonging to other origins and the ability to tamper with cross-origin content. A patched-image rebuild at 149.0.7827.103 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection for CVE-2026-11693 is available across every HarborGuard environment: the CVE is ingested from upstream advisory feeds within minutes of publication and matched against all customer images in connected registries and CI/CD pipelines, including custom-built images that bundle or depend on Chromium or Chrome packages.

Available
Triage

HarborGuard is capable of scoring this finding at CVSS 8.1 (High) and weighting it against each environment's compliance policy to determine breach-of-threshold status; from there the platform routes the finding to the appropriate team inbox configured within the customer org.

Available
Patch

A patched-image rebuild pinned to Chrome 149.0.7827.103 becomes available on HarborGuard for any image found to carry an affected version. For customers who opt into auto-remediation, HarborGuard can trigger a rebuild, run regression tests, and open a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the crafted HTML page over the network, so the victim's browser must be able to reach attacker-controlled content.

  • AuthenticationNot required

    No account or credential is needed; any unauthenticated remote attacker can serve the malicious page.

  • Victim interactionRequired

    The victim must navigate to or be redirected to the attacker's crafted HTML page, making this a social-engineering or phishing-dependent attack.

  • Attack complexityDetail

    The exploit itself is condition-free and reliable once the renderer is compromised, though obtaining that renderer compromise is a prerequisite that adds real-world difficulty.

Blast Radius

  • The attacker reads sensitive data belonging to other origins loaded in the browser, such as session tokens, form contents, and cached responses from third-party sites.
  • The attacker modifies cross-origin content rendered in the browser, enabling credential-harvesting overlays or script injection into trusted pages.
  • Site isolation is fully bypassed, so every tab or iframe sharing the same browser process becomes accessible to the attacker's renderer-level code.

How HarborGuard Handles This

Available on HarborGuard: any image in a customer registry or pipeline that packages Chrome or a Chromium-based runtime below 149.0.7827.103 is flagged against this CVE within minutes of the advisory appearing in upstream feeds. The finding is scored at CVSS 8.1 (High) and routed according to each environment's configured compliance policy. A rebuild targeting the fixed version (149.0.7827.103) is made available immediately. For customers who opt into auto-remediation, HarborGuard can rebuild the image, execute the configured regression-test suite, and open a pull request against affected workload manifests; for High-severity issues the median time from CVE publication to a merged patch PR in environments with auto-remediation enabled is around 90 minutes. Where auto-remediation is not enabled, the finding surfaces in the HarborGuard dashboard with remediation guidance pointing to the fix version.

See how HarborGuard automates this

Fix available

149.0.7827.103
Affected packages
  • Google / Chrome
    < 149.0.7827.103 (from 149.0.7827.103)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N