Severity: High (CVSS 8.3)
Affected Systems: Affected products listed in the NVD and vendor advisory
Overview
A high vulnerability identified as CVE-2026-11640 has been disclosed.
Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Risk
CVSS and CISA data indicate the following:
- Review the NVD and vendor advisory for exploit conditions and impact
OpenCVE Analysis
CVSS v4.0 N/ACVSS v3.1 8.3 HighCVSS v3.0 N/ACVSS v2 N/AKEV noEPSS yesSSVC yes
- OpenCVE title: CVE-2026-11640
- Severity score: High (CVSS 8.3)
- SSVC Automatable: no
- SSVC Exploitation: none
- SSVC Technical Impact: total
- EPSS score: 0.00035
- Weaknesses: CWE-472
| Attack Vector | Network |
| Attack Complexity | High |
| Privileges Required | None |
| User Interaction | Required |
| Scope | Changed |
| Confidentiality Impact | High |
| Integrity Impact | High |
| Availability Impact | High |
Required Action
Review the linked vendor and NVD advisory, then apply the vendor-provided update or mitigation for the affected product.
Prioritize systems where the affected product is internet-facing, handles authentication, or runs with elevated privileges.
Verify Updates
Confirm whether your environment uses the affected product(s): Affected products listed in the NVD and vendor advisory.
After remediation, verify the installed version against the fixed or unaffected versions listed by the vendor.
Temporary Mitigation (if patch is not available)
Use the mitigation published by the vendor. If no vendor mitigation is available, reduce exposure to the affected product, restrict access to trusted users or networks, and increase monitoring until an update can be applied.
Recommendation
- Use OpenCVE, vendor, and source references as the source of truth for affected versions and remediation
- Patch or mitigate affected products after confirming exposure in your environment
- Monitor affected systems for unusual activity until remediation is complete
Support
If you require assistance, please contact our support team.
Immediate action is strongly recommended to protect your infrastructure.
Source Details
Tuesday, June 9, 2026
