Junglewise Threat Intelligence

CVE-2026-11052: Google Chrome type confusion in GPU

CVE-2026-11052 · Severity: info · CVSS 6.5 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a web browser used to access the internet. A vulnerability in the browser's graphics processing component could allow a malicious website to bypass security protections (the sandbox) that normally keep web content isolated from the rest of the computer. If exploited, an attacker who has already gained partial control of the browser could potentially gain broader access to the underlying Windows operating system.

Technical details

A type confusion vulnerability (CWE-843) exists in the GPU component of Google Chrome for Windows. The flaw is reachable by a remote attacker who has already compromised the renderer process, typically through a separate vulnerability. By enticing a user to visit a specially crafted HTML page, the attacker can exploit this type confusion to achieve a sandbox escape, potentially leading to arbitrary code execution outside of the browser's restricted environment. This issue was addressed in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE-2026-11052 published.

References

Related threats