Junglewise Threat Intelligence

CVE-2026-11675: Google Chrome out of bounds read in Skia

CVE-2026-11675 · Severity: info · CVSS 0 · Published 2026-06-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability in its graphics engine, Skia, could allow a malicious website to access sensitive information from other websites you have open. This could lead to the theft of personal data or login sessions if a user visits a specially crafted webpage.

Technical details

An out-of-bounds read vulnerability exists in the Skia graphics component of Google Chrome. The flaw is rooted in insufficient validation of untrusted input. A remote attacker who has already compromised the renderer process can exploit this vulnerability by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass cross-origin restrictions and leak sensitive data from other origins. The issue is addressed in Chrome version 149.0.7827.103.

Affected products

  • Google Chrome prior to 149.0.7827.103

Timeline

  • 2026-05-27: disclosed: Reported to Chrome by Google researchers
  • 2026-06-08: patched: Stable channel update released for Windows, Mac, and Linux
  • 2026-06-09: advisory: NVD publication date

References

Related threats