Junglewise Threat Intelligence

CVE-2026-11159: Google Chrome uninitialized use in Skia

CVE-2026-11159 · Severity: info · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its graphics engine, Skia, could allow a malicious website to access sensitive information from other websites you have open. This could lead to the exposure of private user data or login sessions if a user visits a specially crafted web page.

Technical details

A vulnerability classified as CWE-457 (Use of Uninitialized Variable) exists in the Skia graphics library component of Google Chrome. By enticing a user to visit a specially crafted HTML page, a remote attacker can trigger the use of uninitialized memory during rendering operations. This flaw can be leveraged to bypass cross-origin isolation and leak sensitive data from different origins. The issue is resolved in Chrome version 149.0.7827.53 and later.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: NVD publication date

References

Related threats