Junglewise Threat Intelligence

CVE-2026-11153: Google Chrome side-channel information leakage in Forms

CVE-2026-11153 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's web forms component could allow a malicious website to extract information from other websites you have open. By tricking a user into visiting a specially crafted page, an attacker can use technical side-channels to leak sensitive data across different web domains. This compromises the browser's security boundaries that normally keep data from different sites isolated.

Technical details

A side-channel information leakage vulnerability exists in the Forms component of Google Chrome. The flaw (CWE-1300) allows a remote attacker to bypass Same-Origin Policy (SOP) protections by using a crafted HTML page to observe side-channel signals. This enables the extraction of cross-origin data that should otherwise be inaccessible to the attacking site. The vulnerability is triggered when a user visits a malicious webpage, requiring no special privileges from the attacker. Google has addressed this issue in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome Prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE published in NVD.

References

Related threats