Junglewise Threat Intelligence

CVE-2026-11006: Google Chrome out of bounds read in Dawn

CVE-2026-11006 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's Dawn component, which is responsible for handling modern web graphics. By tricking a user into visiting a specially crafted website, a remote attacker could read sensitive information from the browser's memory. This could potentially lead to the exposure of data that should remain private within the browser session.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the Dawn component of Google Chrome prior to version 149.0.7827.53. Dawn is the open-source implementation of the WebGPU standard. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to perform an unauthorized memory read. This can lead to information disclosure by accessing data outside the intended buffer. The vulnerability is exploited via the network vector and requires user interaction (visiting a malicious site). Google has addressed this issue in the stable channel update for desktop.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Fixed in Chrome version 149.0.7827.53
  • 2026-06-04: disclosed: NVD publication date

References

Related threats