Google · Google Chrome · CVE-2026-11169
**Name of the Vulnerable Software and Affected Versions**
Google Chrome versions prior to 149.0.7827.53
**Description**
An inappropriate implementation in XML allows a remote attacker to perform Universal Cross-Site Scripting (UXSS), which is a vulnerability that enables the execution of arbitrary scripts or HTML across different origins, by using a crafted XML file.
**Recommendations**
Update to version 149.0.7827.53 or later.