Junglewise Threat Intelligence

CVE-2026-11104: Google Chrome uninitialized use in ANGLE

CVE-2026-11104 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's graphics translation engine (ANGLE) could allow a remote attacker to access sensitive information from the browser's memory. This issue occurs if a user visits a specially crafted website and the attacker has already partially compromised the browser's rendering process. Such an exploit could lead to the exposure of private data or internal process details, though it does not directly allow for full system control.

Technical details

An uninitialized use vulnerability (CWE-457) exists in ANGLE, the graphics abstraction layer used by Google Chrome. The flaw is reachable via a crafted HTML page and requires the attacker to have already compromised the renderer process (a 'sandbox escape' or similar initial foothold is typically required for full impact, though the advisory notes this as a precondition for the memory leak). By exploiting this uninitialized variable, an attacker can read potentially sensitive data from the process memory. The issue was addressed in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE published in NVD.

References

Related threats