Junglewise Threat Intelligence

CVE-2026-11253: Google Chrome cross-origin data leak in Permissions

CVE-2026-11253 · Severity: info · CVSS 0 · Published 2026-06-05

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in the browser's permissions component could allow a malicious website to access data from other websites that the user has open. This could lead to the unauthorized disclosure of sensitive information across different web origins.

Technical details

A vulnerability classified as an 'Inappropriate Implementation' exists in the Permissions component of Google Chrome prior to version 149.0.7827.53. The flaw is associated with a race condition (CWE-362) involving concurrent execution using shared resources with improper synchronization. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, potentially allowing the attacker to bypass cross-origin isolation and leak sensitive data from other origins. The issue is resolved in version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-05: disclosed: CVE published in NVD.

References

Related threats