CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-11153

CVSS 9.1pub. 2026-06-04upd. 2026-06-08

Side-channel information leakage in Forms in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

🤖 AI Analysis
How it works

The vulnerability consists of an information leakage side-channel vulnerability in the component responsible for handling forms (Forms) in Google Chrome. An attacker can prepare a malicious HTML page, which when visited by the victim causes unauthorized reading of data from other sources (cross-origin). The side-channel mechanism means that the leak occurs not through direct violation of access control mechanisms, but through observation of side effects of browser operation.

Impact

An attacker can gain access to sensitive cross-origin data, violating the confidentiality of information processed in other browser contexts. Data integrity is not directly threatened, however data disclosure may lead to further attacks.

Mitigation & patch

Google Chrome should be updated to version 149.0.7827.53 or newer. The update is available through the browser's built-in update mechanism or on the manufacturer's website according to the reference chromereleases.googleblog.com.

Who is affected

Google Chrome in versions earlier than 149.0.7827.53 on Google Chrome operating systems, Apple macOS, Linux and Microsoft Windows.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Apple macOS

    OS
    Apple
    all versions
  • Google Chrome

    APP
    Google
    < 149.0.7827.53
  • Linux Kernel

    OS
    Linux
    all versions
  • Microsoft Windows

    OS
    Microsoft
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-65400CRITICAL9.8⚠ KEVPL ✓same product

Pominięcie uwierzytelniania w Screen Sharing na macOS

CVE-2026-8398CRITICAL9.3⚠ KEVPL ✓same product

Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2025-43300CRITICAL10.0⚠ KEVPL ✓same product

Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu

CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product

Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP