Junglewise Threat Intelligence

CVE-2026-11200: Google Chrome cross-origin data leak in WebRTC

CVE-2026-11200 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's WebRTC component could allow a malicious website to access data from other websites or browser tabs. WebRTC is the technology used for real-time communication like video calls and voice chat within the browser. An attacker could exploit this by tricking a user into visiting a specially crafted webpage, potentially leading to the unauthorized disclosure of sensitive information.

Technical details

An inappropriate implementation vulnerability exists in the WebRTC component of Google Chrome. The flaw allows for a cross-origin data leak when a user visits a malicious HTML page. By exploiting this, a remote attacker can bypass Same-Origin Policy (SOP) protections to access information from different origins. The vulnerability is triggered via a network-based attack vector requiring user interaction (visiting a site). Google has addressed this issue in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome stable channel update released.
  • 2026-06-04: disclosed: CVE published.

References

Related threats