Junglewise Threat Intelligence

CVE-2026-11085: Google Chrome integer overflow in GPU on Android

CVE-2026-11085 · Severity: info · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome for Android is a mobile web browser used to access the internet. A vulnerability in its graphics processing component could allow a malicious website to access restricted memory. This could potentially lead to the exposure of sensitive information or cause the browser to crash when a user visits a specially crafted web page.

Technical details

An integer overflow vulnerability exists in the GPU component of Google Chrome for Android prior to version 149.0.7827.53. The flaw is triggered when the browser processes a specially crafted HTML page, leading to an out-of-bounds memory access. This is classified under CWE-472 (External Control of Assumed-Immutable Web Parameter). A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website, potentially leading to information disclosure or a renderer process crash. Google has addressed this in the stable channel update for version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Stable channel update released for version 149.0.7827.53
  • 2026-06-04: disclosed: CVE published to NVD

References

Related threats