Junglewise Threat Intelligence

CVE-2026-11691: Google Chrome improper input validation in New Tab Page

CVE-2026-11691 · Severity: info · CVSS 8.8 · Published 2026-06-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's New Tab Page could allow a remote attacker to access sensitive data from other websites. This occurs if an attacker has already partially compromised the browser's internal processing, allowing them to bypass security boundaries that normally keep data from different sites separate. This could lead to the exposure of private user information or login sessions from across the web.

Technical details

An improper input validation vulnerability (CWE-20) exists in the New Tab Page component of Google Chrome. The flaw allows a remote attacker who has already achieved renderer process compromise to bypass Same-Origin Policy (SOP) restrictions. By utilizing a specially crafted HTML page, the attacker can trigger the vulnerability to leak sensitive cross-origin data. This issue was addressed in Chrome version 149.0.7827.103 for Windows and Mac, and 149.0.7827.102 for Linux.

Affected products

  • Google Chrome prior to 149.0.7827.103

Timeline

  • 2026-05-28: other: Reported to Google
  • 2026-06-08: patched: Fixed in stable channel update 149.0.7827.103
  • 2026-06-09: disclosed: CVE published

References

Related threats