
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-11139 is a policy bypass vulnerability in the Paint feature of Google Chrome that allows a remote attacker to leak cross-origin data via a crafted HTML page. It affects all versions of Google Chrome prior to 149.0.7827.53 on Windows, macOS, and Linux. The vulnerability was reported internally by Google on April 11, 2026, and publicly disclosed on June 4, 2026, as part of the Chrome 149 stable channel release. It carries a CVSS v3.1 base score of 6.5 (Medium) (Chrome Advisory, Feedly).
The vulnerability stems from an inappropriate implementation (policy bypass) in Chrome's Paint subsystem, classified under CWE-352 (Cross-Site Request Forgery) by CISA-ADP, though the practical mechanism involves bypassing same-origin policy controls within the rendering pipeline to expose cross-origin data. The Chromium issue tracker references bug ID 501650594, which remains access-restricted. An attacker can exploit this by serving a specially crafted HTML page that, when rendered by a vulnerable Chrome instance, causes the Paint component to improperly handle cross-origin content boundaries, resulting in data leakage. No public technical write-up or proof-of-concept code has been identified (Chrome Advisory, Feedly).
Successful exploitation results in a confidentiality breach, allowing an unauthenticated remote attacker to read sensitive data from other web origins that the victim user is authenticated to. The attack requires user interaction — specifically, the victim must visit a malicious HTML page — and does not affect integrity or availability. The scope is limited to the browser context, but leaked cross-origin data could include session tokens, personal information, or other sensitive content rendered by third-party sites (Feedly, Chrome Advisory).
Google has addressed this vulnerability in Chrome 149.0.7827.53 (Linux) and 149.0.7827.53/54 (Windows/Mac). Users and administrators should update Google Chrome to version 149.0.7827.53 or later immediately. No configuration-based workaround is available; upgrading is the only effective remediation. Enterprise administrators should use Google Update, Microsoft Intune, or other endpoint management tools to enforce the update across managed devices (Chrome Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."