Junglewise Threat Intelligence

CVE-2026-11139: Google Chrome cross-origin data leak in Paint

CVE-2026-11139 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's rendering component could allow a malicious website to access data from other websites you have open. This bypasses standard browser security boundaries that normally keep data from different sites isolated. An attacker would need to trick a user into visiting a specially crafted webpage to exploit this flaw.

Technical details

An inappropriate implementation vulnerability exists in the Paint component of Google Chrome. By leveraging a specially crafted HTML page, a remote attacker can bypass cross-origin isolation policies to leak sensitive data from different origins. The attack requires user interaction, specifically enticing a victim to visit a malicious website. This issue is addressed in Google Chrome version 149.0.7827.53 and later. The vulnerability is categorized by Chromium as Medium severity.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE published.

References

Related threats