CVE-2026-11284
Google Chrome ≤ 149.0.7827.53
Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NSummary
CVE-2026-11284 is a medium-severity Improper Protection of Physical Side Channels (CWE-1300) vulnerability in Google Chrome. Its CVSS base score is 6.5 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Account Discovery (T1087); ranked at the 15th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to IA-6 (Authentication Feedback) and SI-11 (Error Handling) — see the control section below for these in your framework.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-34745
Vulnerability Data
Side-channel information leakage in PerformanceAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
—
—
- 3 hardening rules · 2 OS baselines
—
Mitigating Controls (NIST 800-53 r5) AI
Obscures authentication feedback so that success/failure differences are not observable to attackers.
Requires error messages to avoid revealing exploitable details, directly stopping observable response discrepancies.
Directly requires protection against electromagnetic emanation leakage, which stops one class of the physical side-channel exposures described in CWE-1300.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly prevent observable response discrepancies via consistent error handling and timing.
Limiting physical access reduces opportunity for side-channel observation but does not address emission-protection mechanisms inside the device.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Physical perimeters can limit attacker proximity needed for side-channel capture.
Entry controls reduce opportunities for physical observation of emissions.
Securing rooms and facilities can shield equipment from side-channel probing.
Monitoring deters or detects attempts to exploit physical side channels.
Protecting against physical threats can include shielding against emanation attacks.
Proper siting and protection of equipment can reduce observable emissions.