
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-11255 is an improper input validation vulnerability in the Storage Access API of Google Chrome that allows a remote attacker who has already compromised the renderer process to leak cross-origin data via a crafted HTML page. It affects all versions of Google Chrome prior to 149.0.7827.53 on Windows, macOS, and Linux. The vulnerability was published on June 5, 2026, and patched in Chrome 149.0.7827.53, released June 2, 2026. It carries a CVSS v3.1 base score of 7.5 (High), assessed by CISA-ADP, though Google internally rates it as Low severity (Github Advisory, Chrome Releases).
The vulnerability is classified as CWE-20 (Improper Input Validation) and resides in Chrome's Storage Access API implementation. The Storage Access API governs how embedded cross-origin content can request access to first-party storage; insufficient validation of untrusted input in this component allows a compromised renderer process to improperly access or infer cross-origin data. Exploitation requires a precondition: the attacker must have already achieved renderer process compromise (e.g., via a separate browser vulnerability), making this a post-exploitation information disclosure rather than a standalone remote code execution flaw. The Chromium issue tracker entry (ID 498417152) is currently access-restricted (Chrome Releases, Github Advisory).
Successful exploitation results in a confidentiality breach — specifically, the leakage of cross-origin data to an attacker-controlled renderer process. There is no integrity or availability impact. In practice, this could expose sensitive information from other origins (e.g., cookies, storage data, or page content) that the same-origin policy is designed to protect, potentially enabling session hijacking or credential theft when chained with a renderer compromise exploit (Github Advisory, Chrome Releases).
Update Google Chrome to version 149.0.7827.53 or later on all platforms (Windows, macOS, Linux), which was released on June 2, 2026 and contains the fix for this vulnerability along with 428 other security fixes (Chrome Releases). As a defense-in-depth measure, organizations should enforce Chrome's Site Isolation feature and ensure renderer sandboxing is enabled to limit the impact of any renderer compromise. Deploying Content Security Policy (CSP) headers on web properties can also reduce the risk of renderer exploitation that would be a prerequisite for this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."