CVE-2026-11169
Analyzed Analyzed - Analysis Complete
Inappropriate XML Implementation in Google Chrome Leads to UXSS

Publication date: 2026-06-04

Last updated on: 2026-06-08

Assigner: Chrome

Description
Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted XML file. (Chromium security severity: Medium)
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-04
Last Modified
2026-06-08
Generated
2026-06-25
AI Q&A
2026-06-05
EPSS Evaluated
2026-06-24
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
google chrome to 149.0.7827.53 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-91 The product does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is an inappropriate implementation in the XML handling of Google Chrome versions prior to 149.0.7827.53. It allows a remote attacker to inject arbitrary scripts or HTML content through a specially crafted XML file, leading to a type of attack known as UXSS (Universal Cross-Site Scripting).

Impact Analysis

The vulnerability can allow a remote attacker to execute arbitrary scripts or inject HTML into your browser context via a crafted XML file. This can lead to unauthorized actions such as stealing sensitive information, session hijacking, or performing actions on behalf of the user without their consent.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-11169. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart