CVE-2026-11685: Insufficient data validation in MediaCapture
Chromium: CVE-2026-11684 Insufficient policy enforcement in Network
Other sources
Inappropriate implementation in MediaCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
— NVD
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 149.0.7827.102 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 149.0.4022.62 - Upgrade
Upgrade
Google Chrome (Chromium) on Macto a version that resolves this vulnerability.Fixed in 149.0.7827.103 - Compensating control
Until the affected Chrome version is updated, reduce exposure by limiting the ability for remote attackers to get users to open crafted HTML pages (e.g., restrict access to untrusted web content).
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-11628
- CVE-2026-11629
- CVE-2026-11630
- CVE-2026-11631
- CVE-2026-11632
- CVE-2026-11633
- CVE-2026-11634
- CVE-2026-11635
- CVE-2026-11636
- CVE-2026-11637
- CVE-2026-11638
- CVE-2026-11639
- CVE-2026-11640
- CVE-2026-11641
- CVE-2026-11642
- CVE-2026-11643
- CVE-2026-11644
- CVE-2026-11645
- CVE-2026-11646
- CVE-2026-11647
- CVE-2026-11648
- CVE-2026-11649
- CVE-2026-11650
- CVE-2026-11651
- CVE-2026-11652
- CVE-2026-11653
- CVE-2026-11654
- CVE-2026-11655
- CVE-2026-11656
- CVE-2026-11657
- CVE-2026-11658
- CVE-2026-11659
- CVE-2026-11660
- CVE-2026-11661
- CVE-2026-11662
- CVE-2026-11663
- CVE-2026-11664
- CVE-2026-11665
- CVE-2026-11666
- CVE-2026-11667
- CVE-2026-11668
- CVE-2026-11669
- CVE-2026-11670
- CVE-2026-11671
- CVE-2026-11672
- CVE-2026-11673
- CVE-2026-11674
- CVE-2026-11675
- CVE-2026-11676
- CVE-2026-11677
- CVE-2026-11678
- CVE-2026-11679
- CVE-2026-11680
- CVE-2026-11681
- CVE-2026-11682
- CVE-2026-11683
- CVE-2026-11684
- CVE-2026-11686
- CVE-2026-11687
- CVE-2026-11688
- CVE-2026-11689
- CVE-2026-11690
- CVE-2026-11691
- CVE-2026-11692
- CVE-2026-11693
- CVE-2026-11694
- CVE-2026-11695
- CVE-2026-11696
- CVE-2026-11697
- CVE-2026-11698
- CVE-2026-11699
- CVE-2026-11700
- CVE-2026-11701
Frequently Asked Questions
What is the severity of CVE-2026-11685?
The severity of CVE-2026-11685 is rated as medium with a CVSS score of 4.3.
How do I fix CVE-2026-11685?
To fix CVE-2026-11685, update Google Chrome to version 149.0.7827.103 or later on macOS.
What does CVE-2026-11685 affect?
CVE-2026-11685 affects Google Chrome on macOS prior to version 149.0.7827.103.
What type of vulnerability is CVE-2026-11685?
CVE-2026-11685 is classified as an Insufficient data validation vulnerability.
Can CVE-2026-11685 lead to data leakage?
Yes, CVE-2026-11685 can allow a remote attacker to leak cross-origin data through a crafted HTML page.