Junglewise Threat Intelligence

CVE-2026-11091: Google Chrome out of bounds memory access in Dawn

CVE-2026-11091 · Severity: info · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability was identified in its Dawn component, which handles graphics processing. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially leading to unauthorized memory access that could crash the browser or allow for further exploitation.

Technical details

An inappropriate implementation vulnerability exists in the Dawn component of Google Chrome. Dawn is the underlying implementation of the WebGPU standard. The flaw allows a remote attacker to trigger out-of-bounds memory access by convincing a user to load a maliciously crafted HTML page. This is a client-side vulnerability reachable over the network without prior authentication. The issue is addressed in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: NVD publication date

References

Related threats