Junglewise Threat Intelligence

CVE-2026-11203: Google Chrome inappropriate implementation in GPU on Mac

CVE-2026-11203 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the Google Chrome web browser on Mac could allow a malicious website to access data from other websites. This occurs due to a flaw in how the browser's graphics processing component handles certain web content. An attacker could exploit this by tricking a user into visiting a specially crafted webpage, potentially leading to the exposure of sensitive user information across different sites.

Technical details

An inappropriate implementation vulnerability exists within the GPU component of Google Chrome for macOS. The flaw allows for a cross-origin data leak when a user visits a maliciously crafted HTML page. By exploiting this weakness, a remote attacker can bypass Same-Origin Policy (SOP) protections to read data that should be restricted to other domains. The vulnerability is triggered via the network vector and requires minimal user interaction (visiting a site). Google has addressed this issue in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released for Mac
  • 2026-06-04: disclosed: CVE published

References

Related threats