Executive brief
A security vulnerability in Google Chrome for Android could allow a malicious website to access sensitive data from other websites you have open. This occurs due to a timing issue in the browser's graphics processing component. For an attack to be successful, the attacker must first compromise the browser's page-rendering process, typically by tricking a user into visiting a specially crafted web page.
Technical details
A race condition exists in the GPU component of Google Chrome for Android prior to version 149.0.7827.53. The vulnerability is classified as a 'Use of Uninitialized Variable' (CWE-457) resulting from a race condition. An attacker who has already achieved code execution within a compromised renderer process can exploit this flaw to bypass Same-Origin Policy (SOP) protections. By enticing a user to visit a malicious HTML page, the attacker can leak sensitive cross-origin data. Google has addressed this issue in the stable channel update for version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
- 2026-06-04: disclosed: CVE-2026-11064 published