Junglewise Threat Intelligence

CVE-2026-11195: Google Chrome cross-origin data leak in MHTML

CVE-2026-11195 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's MHTML handling could allow a malicious website to access data from other websites. To exploit this, an attacker must trick a user into performing specific interactions or gestures on a specially crafted web page. This could lead to the unauthorized exposure of sensitive information across different web domains.

Technical details

A cross-origin data leak vulnerability exists in the MHTML implementation of Google Chrome. The flaw is categorized as an 'inappropriate implementation' that fails to properly enforce origin boundaries when processing MHTML content. A remote attacker can exploit this by hosting a malicious HTML page and inducing a user to perform specific UI gestures. Successful exploitation allows the attacker to bypass Same-Origin Policy (SOP) protections and access data from other origins. The issue is resolved in Google Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE-2026-11195 published.

References

Related threats