Junglewise Threat Intelligence

CVE-2026-11106: Google Chrome inappropriate implementation in Media

CVE-2026-11106 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's media component could allow a malicious website to access data from other websites you have open. This type of 'cross-origin' leak can compromise user privacy by exposing information that should be restricted to a specific site. Users are protected by updating to the latest version of the Chrome browser.

Technical details

A vulnerability classified as an 'Inappropriate Implementation' exists within the Media component of Google Chrome. The flaw allows a remote attacker to bypass Same-Origin Policy (SOP) protections and leak data across origins. To exploit this, an attacker must entice a user to visit a specially crafted HTML page. Successful exploitation results in the unauthorized disclosure of information from different origins. The issue is addressed in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: CVE published to NVD

References

Related threats