Executive brief
A vulnerability in Google Chrome's graphics engine could allow a malicious website to access sensitive information from the browser's memory. This occurs if an attacker has already partially compromised the browser's rendering process, potentially leading to the exposure of private user data. Users should update to the latest version of Chrome to mitigate this risk.
Technical details
An out-of-bounds read vulnerability exists in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome prior to version 149.0.7827.53. The flaw is triggered when a remote attacker, who has already achieved code execution within a compromised renderer process, lures a user to a specially crafted HTML page. This allows the attacker to read data outside of intended memory buffers, potentially leaking sensitive information from the process memory. Google has addressed this issue in the stable channel update for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE-2026-11004 published.