Junglewise Threat Intelligence

CVE-2026-11051: Google Chrome out of bounds read in ANGLE

CVE-2026-11051 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its graphics engine (ANGLE) could allow a malicious website to read sensitive information from the browser's memory. This could potentially expose private data such as login tokens or other session information to an attacker if a user visits a specially crafted webpage.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the ANGLE component of Google Chrome for Linux. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to read data beyond the intended buffer in the process memory. This can lead to the disclosure of sensitive information from the browser's memory space. The vulnerability is addressed in version 149.0.7827.53. Exploitation requires user interaction (visiting a malicious site) but no prior authentication.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE-2026-11051 published.

References

Related threats