Junglewise Threat Intelligence

CVE-2026-11284: Google Chrome side-channel information leakage in PerformanceAPIs

CVE-2026-11284 · Severity: info · CVSS 3.3 · Published 2026-06-05

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Performance APIs could allow a malicious website to capture data from other open websites or services. This is a side-channel attack where a specially crafted webpage can observe timing or performance data to infer sensitive information from different origins. While the risk is considered low, it could lead to the unauthorized disclosure of private user data.

Technical details

A side-channel information leakage vulnerability (CWE-1300) exists in the PerformanceAPIs component of Google Chrome. The flaw allows a remote attacker to bypass cross-origin isolation boundaries by using a crafted HTML page to observe performance metrics. By analyzing these metrics, an attacker can infer data from different origins (cross-origin data leakage). The attack requires a user to visit a malicious website but does not require special privileges. Google has addressed this issue in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-05: disclosed: CVE published.

References

Related threats