
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-11005 is an out-of-bounds read vulnerability in ANGLE (Almost Native Graphics Layer Engine) affecting Google Chrome on Windows. It allows a remote attacker who has already compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. The vulnerability affects Google Chrome versions prior to 149.0.7827.53 and was reported by researcher 86ac1f1587b71893ed2ad792cd7dde32 on March 22, 2026. It was publicly disclosed on June 4, 2026, with a patch released on June 2, 2026. It carries a CVSS v3.1 base score of 5.3 (Medium) (Chrome Advisory).
The vulnerability is classified as CWE-125 (Out-of-bounds Read) and resides in Chrome's ANGLE component, which is the graphics abstraction layer used on Windows to translate OpenGL ES calls to DirectX. The flaw can be triggered by a crafted HTML page that causes ANGLE to read memory beyond the bounds of an allocated buffer, potentially exposing adjacent process memory contents. Exploitation requires a pre-existing renderer process compromise — meaning this vulnerability is typically chained with another exploit that first breaks out of the renderer sandbox or is used as a second stage within an already-compromised renderer context. The Chromium issue tracker reference for this bug is issue #495052581 (Chrome Advisory).
Successful exploitation results in an information disclosure impact, specifically the leakage of potentially sensitive data from Chrome's process memory. Confidentiality is the primary concern (rated High in the CVSS vector), while integrity and availability are unaffected. Because exploitation requires a pre-compromised renderer, this vulnerability is most dangerous as part of a multi-stage attack chain — for example, leaking memory addresses or secrets to facilitate sandbox escape or further exploitation of the browser process (Chrome Advisory).
Google has released a fix in Chrome 149.0.7827.53 (Linux) and 149.0.7827.53/54 (Windows/Mac). Users and administrators should update Google Chrome to version 149.0.7827.53 or later immediately. No configuration-based workaround is available; upgrading is the only remediation. Organizations should also ensure broader browser security controls are in place (e.g., site isolation, sandboxing) to reduce the risk of renderer process compromise that is a prerequisite for this vulnerability (Chrome Advisory).
The vulnerability was part of a large Chrome 149 security release that addressed 429 security fixes, drawing general attention from the security community. Coverage appeared on security news aggregators including security-next.com and VulDB, as well as Linux distribution security mailing lists (openSUSE, Fedora) due to the Chromium dependency. No notable individual researcher commentary or significant social media discussion specific to CVE-2026-11005 has been identified beyond routine patch tracking (Chrome Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."