Executive brief
A vulnerability in Google Chrome's memory safety component (GWP-ASan) could allow a local attacker to access sensitive information from the browser's memory. This occurs when a user is tricked into opening a malicious file, potentially leading to the exposure of private data. Users should update to Chrome version 149.0.7827.53 or later to mitigate this risk.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the GWP-ASan component of Google Chrome. The flaw is triggered when the browser processes a specially crafted malicious file provided by a local attacker. Successful exploitation allows the attacker to read sensitive data from the process memory that should otherwise be inaccessible. The vulnerability was addressed in Chrome version 149.0.7827.53. While the NVD report lists the severity as 'info', Chromium's internal assessment classifies it as 'Medium'.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE-2026-11183 published.