Junglewise Threat Intelligence

CVE-2026-11133: Google Chrome Same Origin Policy bypass in Paint

CVE-2026-11133 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security flaw in the browser's 'Paint' component allowed a malicious website to bypass the Same Origin Policy, which is a fundamental security rule that prevents websites from interacting with data from other sites. If exploited, an attacker could potentially access sensitive information from other websites you have open in your browser.

Technical details

An insufficient policy enforcement vulnerability exists in the Paint component of Google Chrome. The flaw allows a remote attacker to bypass the Same Origin Policy (SOP) by enticing a user to visit a specially crafted HTML page. By bypassing SOP, the attacker could potentially read data from or interact with web content from different origins that the user is currently authenticated to. This issue was addressed in Chrome version 149.0.7827.53. The vulnerability is categorized by Chromium as Medium severity.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: CVE published to NVD

References

Related threats