Junglewise Threat Intelligence

CVE-2026-11141: Google Chrome uninitialized use in Audio

CVE-2026-11141 · Severity: info · CVSS 0 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's audio component could allow an attacker to access sensitive information from the browser's memory. To exploit this, an attacker would first need to compromise the browser's rendering process and then trick a user into visiting a specially crafted website. This could lead to the exposure of private data handled by the browser.

Technical details

This vulnerability (CWE-457) exists in the Audio component of Google Chrome due to the use of uninitialized variables. An attacker who has already achieved code execution within the sandboxed renderer process can leverage this flaw to read sensitive data from the process memory. The attack is delivered via a malicious HTML page. Google has addressed this issue in Chrome version 149.0.7827.53 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome version 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE published.

References

Related threats