CVE-2026-11108

Google · Chrome on Android

An inappropriate implementation of NFC in Google Chrome on Android allows a remote attacker to perform privilege escalation via a crafted HTML page.

Executive summary

A high-severity privilege escalation vulnerability in Google Chrome on Android poses a significant risk to user device integrity and data security.

Vulnerability

This vulnerability involves an inappropriate implementation of NFC functionality. A remote, unauthenticated attacker can exploit this flaw by enticing a user to navigate to a specially crafted HTML page, which subsequently triggers unauthorized privilege escalation.

Business impact

The CVSS score of 8.8 indicates a high-severity risk that could lead to full system compromise of the affected mobile device. Successful exploitation allows an attacker to bypass security boundaries, potentially resulting in unauthorized access to sensitive user data, application credentials, or further device manipulation.

Remediation

Immediate Action: Update Google Chrome on Android to version 149.0.7827.53 or later immediately.

Proactive Monitoring: Monitor device application logs for unusual NFC-related service calls or unexpected browser-initiated system activity.

Compensating Controls: Ensure Google Play Protect is enabled on all Android devices to assist in detecting and blocking malicious web content.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Given the potential for privilege escalation, administrators and individual users should prioritize the update to version 149.0.7827.53. Applying this patch is the only effective way to neutralize the risk of remote exploitation via malicious web content.