FeedVulnerabilityMultiple Vulnerabilities in Google Chrome Could Allow for Ar...
VulnerabilityCIS Advisories
8.8CRITICAL

Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution

📅 9 June 2026 at 13:45 UTC📰 CIS AdvisoriesView original source ↗

Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

Multiple vulnerabilities have been discovered in Google Chrome, allowing for arbitrary code execution with potentially severe consequences. The most severe vulnerability could allow an attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

⚙️Technical Details
CVEs
CVE-2026-11645CVE-2026-11628CVE-2026-11629CVE-2026-11630CVE-2026-11631
Affected Systems
Apple MacosGoogle ChromeLinux Linux KernelMicrosoft Windows
Attack Vectors
NETWORKPHYSICAL
💥Impact Assessment
Severity: Unknown
🛡️Recommended Actions
1Apply appropriate updates provided by Google to vulnerable systems immediately after testing.
2Establish and maintain a documented vulnerability management process for enterprise assets.
3Safeguard 7.1: Implement robust input validation and sanitization measures in web applications.
📦Affected Products
Apple MacosGoogle ChromeLinux Linux KernelMicrosoft Windows
🔐NVD Verified DataVERIFIED
CVE-2026-11645CVSS 8.8HIGH
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-125CWE-787
Affected Products (CPE)
Apple MacosGoogle ChromeLinux Linux KernelMicrosoft Windows
CVE-2026-11628CVSS 6.8MEDIUM
Attack Vector
PHYSICAL
Complexity
LOW
Vector String
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-416
Affected Products (CPE)
Apple MacosGoogle ChromeLinux Linux KernelMicrosoft Windows
CVE-2026-11629CVSS 8.8HIGH
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-416
Affected Products (CPE)
Apple MacosGoogle ChromeLinux Linux KernelMicrosoft Windows
CVE-2026-11630CVSS 8.8HIGH
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-416
Affected Products (CPE)
Apple MacosGoogle ChromeLinux Linux KernelMicrosoft Windows
CVE-2026-11631CVSS 8.3HIGH
Attack Vector
NETWORK
Complexity
HIGH
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Weaknesses
CWE-416
Affected Products (CPE)
Google ChromeMicrosoft Windows

Read the full article

This is a curated summary. The complete article is available at CIS Advisories.

Read on CIS Advisories
← Back to feed