Junglewise Threat Intelligence

CVE-2026-10992: Google Chrome insufficient data validation in Animation

CVE-2026-10992 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's animation component could allow a malicious website to access sensitive information from the browser's memory. This occurs when a user visits a specially crafted webpage, potentially leading to the exposure of private data from other open tabs or browser processes. Google has released an update to address this issue and protect user data.

Technical details

An information disclosure vulnerability exists in Google Chrome's Animation component due to insufficient data validation. A remote, unauthenticated attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to perform an out-of-bounds read or similar memory access to leak sensitive information from the browser's process memory. This issue is fixed in Chrome version 149.0.7827.53 and later.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome Stable Channel Update released
  • 2026-06-04: disclosed: CVE published to NVD

References

Related threats