Junglewise Threat Intelligence

CVE-2026-11089: Google Chrome uninitialized use in Media

CVE-2026-11089 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's media component could allow an attacker to access sensitive information from the browser's memory. This issue occurs if a user visits a specially crafted website and the attacker has already partially compromised the browser's rendering process. Such an exploit could lead to the exposure of private data or browsing information.

Technical details

This vulnerability is classified as a 'Use of Uninitialized Variable' (CWE-457) within the Media component of Google Chrome. The flaw is reachable by a remote attacker via a crafted HTML page, provided the attacker has already achieved code execution within the sandboxed renderer process (a 'renderer compromise'). By exploiting this uninitialized state, the attacker can read sensitive data from the process memory that should otherwise be inaccessible. Google addressed this issue in version 149.0.7827.53 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE-2026-11089 published.

References

Related threats