Junglewise Threat Intelligence

CVE-2026-11256: Google Chrome integer overflow in GPU

CVE-2026-11256 · Severity: info · CVSS 0 · Published 2026-06-05

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the Google Chrome web browser could allow a malicious website to escape the browser's security sandbox. This occurs if an attacker has already compromised the browser's rendering process, potentially allowing them to gain broader access to the underlying operating system. Users are protected by updating to the latest version of the browser.

Technical details

An integer overflow vulnerability exists in the GPU component of Google Chrome prior to version 149.0.7827.53. The flaw is categorized as an out-of-bounds read (CWE-125) resulting from the overflow. An attacker who has already compromised the renderer process can exploit this vulnerability via a specially crafted HTML page to achieve a sandbox escape. This would allow the attacker to execute code outside of the restricted browser environment. Google has addressed this issue in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome Prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-05: disclosed: CVE published.

References

Related threats