Junglewise Threat Intelligence

CVE-2026-11098: Google Chrome improper input validation in GPU

CVE-2026-11098 · Severity: info · CVSS 0 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome's GPU component could allow a malicious website to access data from other websites you have open. This occurs if an attacker has already partially compromised the browser's rendering process, enabling them to bypass security boundaries that normally keep data from different sites separate. Users should update to the latest version of Chrome to protect their information.

Technical details

An improper input validation vulnerability (CWE-20) exists in the GPU component of Google Chrome prior to version 149.0.7827.53. The flaw allows a remote attacker to leak cross-origin data, provided they have already achieved a compromise of the renderer process. By enticing a user to visit a specially crafted HTML page, the attacker can exploit the insufficient validation of untrusted input to bypass Same-Origin Policy (SOP) protections. This vulnerability is rated as Medium severity by Chromium. A fix is available in version 149.0.7827.53 and later.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Stable channel update released for Windows, Mac, and Linux.
  • 2026-06-04: disclosed: CVE published to NVD.

References

Related threats