Junglewise Threat Intelligence

CVE-2026-11145: Google Chrome for Android race condition in Geolocation

CVE-2026-11145 · Severity: info · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A race condition vulnerability exists in the Geolocation component of Google Chrome for Android. A remote attacker could use a specially crafted website to bypass security boundaries and access data from other websites or the user's location information. This could lead to the unauthorized disclosure of sensitive user data or browsing information.

Technical details

A race condition (CWE-362) exists in the Geolocation implementation of Google Chrome for Android prior to version 149.0.7827.53. The vulnerability is triggered when a remote attacker entices a user to visit a specially crafted HTML page. Due to improper synchronization during concurrent execution, an attacker can achieve a cross-origin data leak, potentially accessing information that should be restricted by the Same-Origin Policy. The issue was addressed in the stable channel update to version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Fix released in Chrome 149.0.7827.53
  • 2026-06-04: disclosed: CVE published

References

Related threats