Junglewise Threat Intelligence

CVE-2026-11255: Google Chrome improper input validation in Storage Access API

CVE-2026-11255 · Severity: info · CVSS 0 · Published 2026-06-05

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security flaw in its Storage Access API could allow a malicious website to access data from other websites that it should not be able to see. This type of data leak occurs if an attacker has already partially compromised the browser's internal processing system, potentially leading to the exposure of sensitive user information across different sites.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Storage Access API of Google Chrome prior to version 149.0.7827.53. The flaw allows a remote attacker who has already compromised the renderer process to bypass cross-origin isolation boundaries. By using a specially crafted HTML page, the attacker can leak data from different origins. This vulnerability is categorized by Chromium as Low severity and has been addressed in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Fixed in version 149.0.7827.53
  • 2026-06-05: disclosed: NVD publication date

References

Related threats