Junglewise Threat Intelligence

CVE-2026-11064: Google Chrome for Android race condition in GPU

CVE-2026-11064 · Severity: info · CVSS 6.5 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome for Android could allow a malicious website to access sensitive data from other websites you have open. This occurs due to a timing issue in the browser's graphics processing component. For an attack to be successful, the attacker must first compromise the browser's page-rendering process, typically by tricking a user into visiting a specially crafted web page.

Technical details

A race condition exists in the GPU component of Google Chrome for Android prior to version 149.0.7827.53. The vulnerability is classified as a 'Use of Uninitialized Variable' (CWE-457) resulting from a race condition. An attacker who has already achieved code execution within a compromised renderer process can exploit this flaw to bypass Same-Origin Policy (SOP) protections. By enticing a user to visit a malicious HTML page, the attacker can leak sensitive cross-origin data. Google has addressed this issue in the stable channel update for version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: CVE-2026-11064 published

References

Related threats