Junglewise Threat Intelligence

CVE-2026-11181: Google Chrome same origin policy bypass in Media Session

CVE-2026-11181 · Severity: info · CVSS 0 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Media Session component could allow a malicious website to bypass security boundaries. Specifically, an attacker could use a specially crafted webpage to circumvent the Same Origin Policy, which is a fundamental security mechanism that prevents websites from interacting with data from other sites. This could potentially lead to unauthorized access to sensitive information or actions on behalf of the user across different web domains.

Technical details

An inappropriate implementation in the Media Session component of Google Chrome prior to version 149.0.7827.53 allowed a remote attacker to bypass the Same Origin Policy (SOP). The vulnerability is triggered when a user visits a maliciously crafted HTML page. By exploiting this flaw, an attacker can potentially access data or perform actions across origin boundaries that should be restricted by the browser's security model. The issue is addressed in Chrome version 149.0.7827.53 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE record published.

References

Related threats