Junglewise Threat Intelligence

CVE-2026-11129: Google Chrome cross-origin data leak in Extensions

CVE-2026-11129 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's extension system could allow a malicious website to access data from other websites. This occurs when a user visits a specially crafted webpage, potentially leading to the unauthorized disclosure of sensitive information across different web domains. Users should update to the latest version of Chrome to mitigate this risk.

Technical details

An inappropriate implementation vulnerability exists in the Extensions component of Google Chrome prior to version 149.0.7827.53. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass cross-origin resource sharing (CORS) or similar isolation boundaries to leak data from other origins. This is classified by Chromium as Medium severity and has been addressed in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: CVE published

References

Related threats