Junglewise Threat Intelligence

CVE-2026-11069: Google Chrome SOP bypass in Cast

CVE-2026-11069 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome's Cast feature could allow a malicious website to bypass standard security boundaries. By tricking a user into visiting a specially crafted webpage, an attacker could potentially access data from other websites that the user has open. This undermines the "Same Origin Policy," which is a fundamental security mechanism designed to keep data from different websites isolated from one another.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Cast component of Google Chrome. The flaw allows a remote attacker to bypass the Same Origin Policy (SOP) by inducing a user to visit a malicious HTML page. By exploiting this lack of validation, the attacker can potentially perform cross-origin data access or actions that should be restricted by the browser's security model. The vulnerability is addressed in Google Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 promoted to stable channel.
  • 2026-06-04: disclosed: CVE published to NVD.

References

Related threats