PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-11241 Google CVE debrief

CVE-2026-11241 is a vulnerability in Google Chrome's Cast feature, which allowed an attacker on the local network segment to perform privilege escalation via a crafted HTML page. The vulnerability was reported with a CVSS score of 8 and a severity of HIGH.

Vendor
Google
Product
Chrome
CVSS
HIGH 8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-05
Original CVE updated
2026-06-05
Advisory published
2026-06-05
Advisory updated
2026-06-05

Who should care

Users of Google Chrome prior to version 149.0.7827.53

Technical summary

The vulnerability was caused by insufficient validation of untrusted input in the Cast feature of Google Chrome. This allowed an attacker on the local network segment to perform privilege escalation via a crafted HTML page.

Defensive priority

HIGH

Recommended defensive actions

  • Update Google Chrome to version 149.0.7827.53 or later

Evidence notes

The CVE was published on 2026-06-05T00:17:00.340Z and modified on 2026-06-05T15:29:16.977Z. The vulnerability was reported by [email protected] with a CVSS vector of CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.

Official resources

CVE-2026-11241 was published on 2026-06-05T00:17:00.340Z and modified on 2026-06-05T15:29:16.977Z.