Junglewise Threat Intelligence

CVE-2026-11263: Google Chrome for Android cross-origin data leak in WebAuthentication

CVE-2026-11263 · Severity: info · CVSS 3.3 · Published 2026-06-05

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security issue in Google Chrome for Android could allow a malicious website to access data from other websites. This occurs when an attacker has already partially compromised the browser's internal processing system and uses a specially crafted webpage to bypass security boundaries. While the risk is considered low, it could lead to the unauthorized disclosure of sensitive information across different web origins.

Technical details

A vulnerability exists in the WebAuthentication component of Google Chrome for Android due to insufficient policy enforcement. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass Same-Origin Policy (SOP) protections. By enticing a user to visit a malicious HTML page, the attacker can leak sensitive data across different origins. This issue is addressed in version 149.0.7827.53 and later. Google classifies this as a Low severity security issue.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149 promoted to stable channel
  • 2026-06-05: disclosed: CVE published

References

Related threats