Junglewise Threat Intelligence

CVE-2026-11288: Google Chrome cross-origin data leak in CSS

CVE-2026-11288 · Severity: info · CVSS 0 · Published 2026-06-05

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's handling of web page styling (CSS) could allow a malicious website to access information from other websites you have open. This type of flaw breaks the security boundaries that normally prevent one site from reading data belonging to another. While rated as low severity, it could lead to the unauthorized disclosure of sensitive user information if a victim visits a specially crafted webpage.

Technical details

A policy enforcement vulnerability exists in the CSS component of Google Chrome. The flaw allows a remote attacker to bypass cross-origin restrictions by enticing a user to visit a maliciously crafted HTML page. By exploiting insufficient enforcement of security policies during CSS processing, the attacker can leak data from a different origin than the one hosting the malicious content. This is a cross-origin information leak that impacts confidentiality. The issue is resolved in Google Chrome version 149.0.7827.53 and later.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-05: disclosed: CVE published in NVD.

References

Related threats