Junglewise Threat Intelligence

CVE-2026-11191: Google Chrome out of bounds memory access in ANGLE

CVE-2026-11191 · Severity: info · CVSS 6.5 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's graphics layer could allow a malicious website to access memory locations it should not be able to reach. This occurs when the browser processes a specially crafted webpage, potentially allowing an attacker to read sensitive information from the browser's memory. Users are protected by updating to the latest version of Chrome.

Technical details

An out-of-bounds memory access vulnerability exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to bypass memory safety boundaries. This can lead to the disclosure of sensitive information from the process memory or potentially cause a crash. The vulnerability is addressed in Chrome version 149.0.7827.53 and later. Exploitation requires the victim to visit a malicious website (User Interaction).

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: CVE-2026-11191 published

References

Related threats