Junglewise Threat Intelligence

CVE-2026-11156: Google Chrome cross-origin data leak in CSS

CVE-2026-11156 · Severity: info · CVSS 0 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its CSS implementation allowed malicious websites to potentially access data from other websites you have open. This could lead to the unauthorized disclosure of sensitive information if a user visits a specially crafted webpage.

Technical details

A cross-origin data leak vulnerability exists in the CSS implementation of Google Chrome. The flaw is categorized as an 'inappropriate implementation' that allows a remote attacker to bypass same-origin policy boundaries. By enticing a user to visit a specially crafted HTML page, an attacker can exploit this weakness to extract information from different origins (cross-origin data). The vulnerability was addressed in Chrome version 149.0.7827.53. Chromium developers assigned this a 'Medium' severity rating.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: NVD publication date

References

Related threats