Junglewise Threat Intelligence

CVE-2026-11020: Google Chrome cross-origin data leak in Extensions

CVE-2026-11020 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's extension system could allow a malicious website to access data from other websites that it should not be able to see. This occurs when a user interacts with a specially crafted XML file, potentially leading to the exposure of sensitive information across different web domains. Google has released an update to address this issue and protect user data.

Technical details

A cross-origin data leak vulnerability exists in Google Chrome's Extensions component due to an inappropriate implementation of security boundaries. A remote attacker can exploit this by enticing a user to process a specially crafted XML file, which bypasses Same-Origin Policy (SOP) restrictions. This allows the attacker to read data from origins other than the one serving the malicious content. The vulnerability is fixed in Google Chrome version 149.0.7827.53. Chromium developers classified this as Medium severity.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE published.

References

Related threats