Junglewise Threat Intelligence

CVE-2026-11140: Google Chrome out of bounds read in Chromecast

CVE-2026-11140 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Chromecast component could allow an attacker to access sensitive information from the browser's memory. This occurs when a user visits a specially crafted website, provided the attacker has already gained a foothold in the browser's rendering process. This could lead to the exposure of private data or internal browser information.

Technical details

An out-of-bounds read vulnerability exists in the Chromecast component of Google Chrome prior to version 149.0.7827.53. The flaw is triggered when a remote attacker, who has already compromised the renderer process, lures a user to a crafted HTML page. This allows the attacker to bypass memory safety boundaries and read potentially sensitive information from the process memory. The vulnerability is categorized by Chromium as Medium severity and is addressed in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome version 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE published to NVD.

References

Related threats