Junglewise Threat Intelligence

CVE-2026-11027: Google Chrome improper input validation in Glic

CVE-2026-11027 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's Glic component that could allow a malicious website to access data from other websites. This occurs if an attacker has already partially compromised the browser's rendering process, potentially leading to the exposure of sensitive user information across different web domains. Users should update to the latest version of Chrome to mitigate this risk.

Technical details

This vulnerability is classified as improper input validation (CWE-20) within the Glic component of Google Chrome. The flaw allows a remote attacker to bypass cross-origin restrictions and leak data from different origins. To exploit this, an attacker must first achieve a compromise of the renderer process and then entice a user to visit a specially crafted HTML page. The vulnerability was addressed in Chrome version 149.0.7827.53. While the reported severity in some feeds is 'info', Chromium's internal security assessment classifies this as 'Medium' severity.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE published.

References

Related threats