Junglewise Threat Intelligence

CVE-2026-11161: Google Chrome cross-origin data leak in DataTransfer

CVE-2026-11161 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's data transfer handling could allow a malicious website to access information from other websites you have open. This bypasses standard security boundaries designed to keep data from different sites separate, potentially leading to the exposure of sensitive user information. Users should update to the latest version of Chrome to mitigate this risk.

Technical details

An inappropriate implementation in the DataTransfer component of Google Chrome prior to version 149.0.7827.53 allowed a remote attacker to perform cross-origin data leakage. By enticing a user to visit a specially crafted HTML page, an attacker could exploit this flaw to bypass Same-Origin Policy (SOP) protections. This could result in the unauthorized disclosure of sensitive information from other origins. The vulnerability is addressed in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: NVD publication date

References

Related threats