What is CVE-2026-11247?
Insufficient policy enforcement in CustomTabs in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Timeline
- 2026-06-05Published to the U.S. National Vulnerability Database (NVD)
- 2026-07-23NVD record last updated
Affected product
Google Chrome
NVD also lists CPE entries for: Google Chrome, Google Android
Remediation Steps
- Apply PAN-OS hotfix or upgrade to the fixed version per Palo Alto security advisory.
- Restrict management interface access to trusted IP ranges only.
- Enable Threat Prevention signatures for this vulnerability.
- Review firewall admin activity logs for unauthorized access.
References
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 3 of March 2026 (March 14–20)
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.