Junglewise Threat Intelligence

CVE-2026-11176: Google Chrome cross-origin data leak in Media

CVE-2026-11176 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's media handling component could allow a malicious website to access data from other websites. This type of flaw breaks the security boundaries between different web pages, potentially leading to the exposure of sensitive user information. Users are advised to update to the latest version of Chrome to mitigate this risk.

Technical details

A vulnerability classified as an inappropriate implementation exists in the Media component of Google Chrome prior to version 149.0.7827.53. The flaw allows a remote attacker to bypass Same-Origin Policy (SOP) restrictions and leak cross-origin data. To exploit this, an attacker would need to entice a user to visit a specially crafted HTML page. Successful exploitation results in the unauthorized disclosure of information from other origins. The issue has been addressed in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome version 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE published.

References

Related threats