Junglewise Threat Intelligence

CVE-2026-11024: Google Chrome stack buffer overflow in Skia

CVE-2026-11024 · Severity: info · CVSS 6.5 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the Skia graphics engine used by Google Chrome could allow a remote attacker to compromise a user's system. By tricking a user into visiting a specially crafted website, an attacker could cause the browser to crash or potentially execute unauthorized code. This could lead to the theft of sensitive information or the installation of malicious software on the user's computer.

Technical details

A stack-based buffer overflow (CWE-121) exists in the Skia graphics component of Google Chrome. The vulnerability is triggered when the browser processes a specially crafted HTML page, leading to stack corruption. A remote, unauthenticated attacker can exploit this flaw by inducing a user to visit a malicious website. Successful exploitation could result in arbitrary code execution within the context of the browser's renderer process or a denial-of-service condition. The issue is resolved in Google Chrome version 149.0.7827.53 and later.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: CVE published to NVD

References

Related threats