
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-11075 is an out-of-bounds read vulnerability in the V8 JavaScript engine within Google Chrome that allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. It affects all versions of Google Chrome prior to 149.0.7827.53 on Windows, Mac, and Linux. The vulnerability was reported by JunYoung Park (@candymate) of KAIST Hacking Lab on April 6, 2026, and patched with the Chrome 149 stable channel release on June 2, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium) (Chrome Releases).
The vulnerability is classified as CWE-125 (Out-of-bounds Read) and resides in Chrome's V8 JavaScript engine. When processing a specially crafted HTML page, V8 performs a memory read operation beyond the bounds of an allocated buffer, potentially exposing adjacent process memory contents to the attacker. Exploitation requires user interaction — specifically, a victim must visit a malicious or attacker-controlled web page — but no authentication or special privileges are required on the attacker's side. The Chromium issue tracker reference for this bug is issue #499659070 (Chrome Releases).
Successful exploitation of CVE-2026-11075 results in a confidentiality impact only — an attacker can read potentially sensitive data from Chrome's process memory, which may include cached credentials, session tokens, or other in-memory data. Integrity and availability are not directly affected by this vulnerability. The scope is limited to the Chrome renderer process, and there is no evidence that this vulnerability alone enables code execution or lateral movement (Chrome Releases).
Google has released a patch in Chrome 149.0.7827.53 (Linux) and 149.0.7827.53/54 (Windows/Mac). Users should update Chrome to version 149.0.7827.53 or later immediately by navigating to chrome://settings/help or enabling automatic updates. As an interim measure, users should avoid visiting untrusted or unfamiliar websites and consider enabling Chrome's Enhanced Safe Browsing mode. Enterprise administrators should push the update via policy management tools and verify deployment across all managed endpoints (Chrome Releases).
The vulnerability was part of a large Chrome 149 security release that addressed 429 security fixes, drawing general attention from the security community. Security tracking platforms including Tenable (Nessus plugins 319634 and 320419), VulDB, and openSUSE security announcements referenced the issue shortly after disclosure. No notable individual researcher commentary or significant media coverage specific to CVE-2026-11075 beyond routine patch reporting has been identified (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."