PT-2026-46684 · Google · Google Chrome

Published

2026-06-04

·

Updated

2026-06-04

·

CVE-2026-11157

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Script injection in Accessibility in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts or HTML (UXSS) via a crafted Chrome Extension. (Chromium security severity: Medium)

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-11157

Affected Products

Google Chrome