Junglewise Threat Intelligence

CVE-2026-11126: Google Chrome data leak in DevTools via malicious extension

CVE-2026-11126 · Severity: info · CVSS 0 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's developer tools (DevTools) could allow a malicious browser extension to access data from other websites. To exploit this, an attacker must first trick a user into installing a specifically crafted malicious extension. This could lead to the unauthorized exposure of sensitive information from different web services the user is logged into.

Technical details

A vulnerability classified as 'Inappropriate Implementation' exists in the DevTools component of Google Chrome. The flaw stems from improper input validation (CWE-20) within the developer tools interface. An attacker can exploit this by distributing a malicious Chrome Extension; if a user installs the extension, it can leverage DevTools to bypass cross-origin isolation and leak data from other origins. This issue was addressed in Chrome version 149.0.7827.53. The vulnerability requires user interaction (installing an extension) and is rated as Medium severity by Chromium.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE published to NVD.

References

Related threats