CVE-2026-11166
BaseFortify
Publication date: 2026-06-04
Last updated on: 2026-06-04
Assigner: Chrome
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| chrome | to 149.0.7827.53 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an inappropriate implementation in the SVG component of Google Chrome versions prior to 149.0.7827.53. It allows a remote attacker to inject arbitrary scripts or HTML content through a crafted HTML page, resulting in a UXSS (Universal Cross-Site Scripting) attack.
How can this vulnerability impact me? :
The vulnerability can allow a remote attacker to execute arbitrary scripts or inject HTML in the context of the victim's browser. This can lead to unauthorized actions such as stealing sensitive information, session hijacking, or performing actions on behalf of the user without their consent.