Executive brief
Google Chrome is a widely used web browser. A vulnerability in its graphics engine (ANGLE) could allow a malicious website to read sensitive information from the browser's memory. This could potentially lead to the exposure of private data if a user visits a specially crafted web page.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the ANGLE component of Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to perform an unauthorized memory read. This could lead to information disclosure from the renderer process. The vulnerability was addressed in Chrome version 149.0.7827.53. Attackers require no special privileges, but the exploit does require user interaction (visiting a malicious site).
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome version 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE-2026-11111 published.