Junglewise Threat Intelligence

CVE-2026-11015: Google Chrome out of bounds read in WebGPU

CVE-2026-11015 · Severity: info · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's WebGPU component could allow a malicious website to read sensitive information from the browser's memory. WebGPU is a technology used to provide high-performance graphics and computation within the browser. If a user visits a specially crafted webpage, an attacker could potentially access data they are not authorized to see, which may lead to further exploitation or information disclosure.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the WebGPU implementation of Google Chrome prior to version 149.0.7827.53. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to perform an unauthorized memory read. This could lead to the disclosure of sensitive information from the browser process. The vulnerability is rated as Medium severity by Chromium and has been addressed in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: CVE published in NVD

References

Related threats