Executive brief
A security vulnerability in Google Chrome's rendering component could allow a malicious website to bypass the browser's Same Origin Policy. This policy is a fundamental security boundary that prevents one website from reading data from or interacting with another website. If exploited, an attacker could potentially access sensitive information from other sites you have open in your browser.
Technical details
This vulnerability exists due to insufficient policy enforcement within the 'Paint' component of the Chromium rendering engine. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass the Same Origin Policy (SOP), which could lead to the unauthorized access of data across different domains. The issue is fixed in Google Chrome version 149.0.7827.53 for Linux and 149.0.7827.53/.54 for Windows and Mac.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE-2026-11142 published.