Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-11244

CVE-2026-11244: Google Chrome Auth Bypass Vulnerability

CVE-2026-11244 is an authentication bypass flaw in Google Chrome WebAuthentication that enables same origin policy bypass through a compromised renderer. This article covers technical details, affected versions, and fixes.

Published:

CVE-2026-11244 Overview

CVE-2026-11244 is an input validation flaw [CWE-20] in the WebAuthentication component of Google Chrome prior to version 149.0.7827.53. The vulnerability allows a remote attacker who has already compromised the renderer process to bypass the same-origin policy through a crafted HTML page. Google rated the Chromium security severity as Low. The flaw affects Chrome on Windows, macOS, and Linux desktop platforms. Exploitation requires user interaction and a pre-existing renderer compromise, which reduces practical risk but extends the impact of any chained renderer exploit.

Critical Impact

An attacker controlling a compromised renderer can bypass the same-origin policy via WebAuthentication, enabling cross-origin data access beyond the renderer's intended sandbox boundary.

Affected Products

  • Google Chrome prior to 149.0.7827.53
  • Chrome desktop on Microsoft Windows, Apple macOS, and Linux
  • Chromium-based browsers sharing the affected WebAuthentication implementation

Discovery Timeline

  • 2026-06-05 - CVE-2026-11244 published to NVD
  • 2026-06-05 - Last updated in NVD database

Technical Details for CVE-2026-11244

Vulnerability Analysis

The vulnerability resides in Chrome's WebAuthentication (WebAuthn) implementation, which handles credential creation and assertion requests originating from web pages. The component fails to sufficiently validate untrusted input received from the renderer process. An attacker who has already gained code execution inside a renderer can craft messages that the WebAuthentication layer accepts without enforcing origin checks correctly.

The practical consequence is a same-origin policy (SOP) bypass. The same-origin policy is the foundational browser security boundary that isolates content loaded from different origins. Bypassing it allows the attacker to read or interact with data from origins the renderer should not be able to reach. The flaw is classified under [CWE-20] Improper Input Validation and carries a Low severity rating from Chromium because it is post-exploitation in nature.

Root Cause

The root cause is insufficient validation of input crossing the renderer-to-browser process boundary in the WebAuthentication code path. Chrome's multi-process architecture relies on the browser process treating renderer input as untrusted, then validating origin and parameter constraints before acting. The WebAuthentication handler did not enforce these constraints completely, allowing a compromised renderer to assert origins it should not control.

Attack Vector

Exploitation requires two preconditions. First, the attacker must have already compromised the renderer process, typically through a separate memory corruption or logic bug. Second, the victim must interact with a crafted HTML page that drives WebAuthentication calls from the compromised renderer. Once both conditions are met, the attacker chains the SOP bypass to access cross-origin resources that the renderer sandbox normally blocks. The EPSS score is 0.032%, reflecting low expected exploitation activity in the wild.

No public exploit code or proof-of-concept is available for this issue. Technical details are tracked in the Chromium Issue Tracker Entry.

Detection Methods for CVE-2026-11244

Indicators of Compromise

  • Chrome browser processes running versions earlier than 149.0.7827.53 after the patch release window
  • Renderer process crashes or anomalous child process behavior preceding cross-origin data access patterns
  • Outbound requests from browser sessions to attacker-controlled domains following visits to untrusted pages

Detection Strategies

  • Inventory installed Chrome versions across managed endpoints and flag any build below 149.0.7827.53
  • Monitor for renderer exploit precursors such as unexpected chrome.exe child processes, sandbox escape patterns, or unsigned module loads
  • Correlate browser telemetry with network egress events to detect cross-origin data exfiltration following WebAuthn API invocations

Monitoring Recommendations

  • Enable enterprise browser reporting through Chrome Browser Cloud Management to surface version drift and extension installs
  • Capture process and network telemetry from endpoints to support retrospective hunting if a renderer exploit is later disclosed
  • Track Chromium issue 497609145 and the Chrome stable channel release notes for related advisories

How to Mitigate CVE-2026-11244

Immediate Actions Required

  • Update Google Chrome to version 149.0.7827.53 or later on all Windows, macOS, and Linux endpoints
  • Restart Chrome after the update so the patched binaries are loaded by all browser and renderer processes
  • Validate update deployment through fleet management tooling and remediate clients that fail to pull the new build

Patch Information

Google released the fix in the stable channel update documented in the Google Chrome Desktop Update. The patched version is 149.0.7827.53 for desktop platforms. Chromium-based browser vendors typically incorporate the same fix into their downstream releases; administrators should confirm the corresponding patched build for Edge, Brave, Opera, and similar browsers.

Workarounds

  • No vendor-supplied workaround exists; apply the official patch as the primary remediation
  • Restrict browsing to trusted sites and enforce policies that block untrusted extensions to reduce renderer compromise opportunities
  • Enable Chrome Site Isolation and Enhanced Safe Browsing where not already active to raise the bar for chained exploitation
bash
# Verify Chrome version on Linux/macOS endpoints
google-chrome --version

# Windows: query installed Chrome version via registry
reg query "HKLM\SOFTWARE\Google\Update\Clients\{8A69D345-D564-463C-AFF1-A69D9E530F96}" /v pv

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.