Junglewise Threat Intelligence

CVE-2026-11093: Google Chrome cross-origin data leak in Printing

CVE-2026-11093 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's printing component could allow a malicious website to access data from other websites. This occurs if an attacker has already partially compromised the browser's rendering process, potentially leading to the exposure of sensitive user information across different web domains. Users should update to the latest version of Chrome to mitigate this risk.

Technical details

An inappropriate implementation vulnerability exists within the Printing component of Google Chrome. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass Same-Origin Policy (SOP) protections. By utilizing a specially crafted HTML page, the attacker can leak data across origins. This vulnerability is categorized under CWE-20 (Improper Input Validation). The issue is resolved in Google Chrome version 149.0.7827.53 and later.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE published.

References

Related threats