Junglewise Threat Intelligence

CVE-2026-11250: Google Chrome information disclosure in DevTools

CVE-2026-11250 · Severity: info · CVSS 3.3 · Published 2026-06-05

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's DevTools could allow a remote attacker to access sensitive information from the browser's memory. This issue requires the attacker to have already compromised a specific part of the browser (the renderer process) and then lure a user to a specially crafted webpage. While the risk is rated as low, successful exploitation could lead to the exposure of private data handled by the browser.

Technical details

This vulnerability is classified as an inappropriate implementation within the DevTools component of Google Chrome. The flaw allows an attacker who has already achieved code execution within a compromised renderer process to bypass certain memory isolation boundaries. By enticing a user to visit a malicious HTML page, the attacker can extract sensitive information from the process memory. This is a multi-stage attack requiring an initial compromise of the renderer. The issue was addressed in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-05: disclosed: CVE published.

References

Related threats