Junglewise Threat Intelligence

CVE-2026-11048: Google Chrome Same Origin Policy bypass in Extensions

CVE-2026-11048 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's extension system could allow a malicious browser extension to bypass security boundaries. If a user is convinced to install a specially crafted extension, the attacker could access data from other websites that the user is visiting. This could lead to the unauthorized disclosure of sensitive information or the manipulation of web sessions.

Technical details

An inappropriate implementation vulnerability exists in the Extensions component of Google Chrome prior to version 149.0.7827.53. The flaw allows a crafted Chrome Extension to bypass the Same Origin Policy (SOP), which is a fundamental security mechanism that restricts how a document or script loaded from one origin can interact with a resource from another origin. To exploit this, an attacker must convince a user to install a malicious extension. Once installed, the extension can perform unauthorized cross-origin requests, potentially leading to data exfiltration from other sites the user is authenticated to. The issue is resolved in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: CVE-2026-11048 published

References

Related threats