Executive brief
A vulnerability in Google Chrome's XML processing could allow a remote attacker to access sensitive information from the browser's memory. This occurs when a user visits a malicious website or opens a specially crafted XML file. An exploit could lead to the exposure of private data, such as login tokens or other information currently being processed by the browser.
Technical details
A type confusion vulnerability (CWE-843) exists in the XML component of Google Chrome prior to version 149.0.7827.53. The flaw is triggered when the browser processes a specially crafted XML file, leading to an incompatible type access. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious webpage, potentially allowing the attacker to read sensitive information from the browser's process memory. Google has addressed this issue in the stable channel update for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE-2026-11196 published.