Junglewise Threat Intelligence

CVE-2026-11179: Google Chrome site isolation bypass in ORB

CVE-2026-11179 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's Opaque Response Blocking (ORB) mechanism, which is designed to prevent websites from reading sensitive data from other sites. By tricking a user into visiting a specially crafted webpage, a remote attacker could bypass these protections to access information that should be isolated. This could lead to the unauthorized exposure of user data across different websites.

Technical details

A vulnerability classified as an 'Inappropriate Implementation' exists in the Opaque Response Blocking (ORB) mechanism of Google Chrome prior to version 149.0.7827.53. ORB is a security feature intended to prevent cross-site data leakage by filtering sensitive resource responses. A remote attacker can exploit this flaw by hosting a malicious HTML page; if a user visits this page, the attacker can bypass site isolation boundaries. This bypass could allow the attacker to read cross-origin data that should have been blocked by the browser's security policies. The issue is resolved in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE published.

References

Related threats