Junglewise Threat Intelligence

CVE-2026-11090: Google Chrome uninitialized use in ANGLE

CVE-2026-11090 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's ANGLE component, which is responsible for processing graphics. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to access sensitive information from other websites the user has open. This could lead to the exposure of private data across different web domains.

Technical details

A vulnerability classified as 'Use of Uninitialized Variable' (CWE-457) exists within the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw occurs when the engine attempts to use a variable that has not been properly initialized, which can be triggered by a remote attacker through a specially crafted HTML page. Successful exploitation allows for a side-channel or direct leak of cross-origin data, bypassing the Same-Origin Policy (SOP). This issue was addressed in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome stable channel update released.
  • 2026-06-04: disclosed: CVE published to NVD.

References

Related threats