CVE-2026-11006
published 2026-06-04CVE-2026-11006: Out of bounds read in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page…
PriorityP434medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.31%
22.9th percentile
Out of bounds read in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 149.0.7827.53 | 149.0.7827.53 | |
| chrome | >= 149.0.7827.53 < 149.0.7827.53 | 149.0.7827.53 | |
| chrome_desktop | — | — | |
| paloalto | prisma_browser | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026)
vendor_paloalto·2026-07-08·CVSS 9.6
CVE-2026-10881 [CRITICAL] PAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026)
PAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026)
Palo Alto Networks incorporated the following Chromium security fixes into our products: https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01245939337.html https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0482630350.html https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01750511403.html https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01962725236.html https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html CVE Summary CVE-2026-10881 Out of bounds rea
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2026-11006
vendor_chrome·2026-06-17
CVE-2026-11006 Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2026-11006
Stable Channel Update for ChromeOS / ChromeOS Flex
CVE-2026-11006
Red Hat
chromium-browser: Out of bounds read in Dawn
vendor_redhat·2026-06-02·CVSS 6.5
CVE-2026-11006 [MEDIUM] CWE-125 chromium-browser: Out of bounds read in Dawn
chromium-browser: Out of bounds read in Dawn
Out of bounds read in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
An out of bounds read flaw was found in the Dawn component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=495489174
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Chrome
Stable Channel Update for Desktop: CVE-2026-11004
vendor_chrome·2026-06-02
CVE-2026-11004 [MEDIUM] Stable Channel Update for Desktop: CVE-2026-11004
Stable Channel Update for Desktop
CVE-2026-11004: Out of bounds read in ANGLE. Reported by 86ac1f1587b71893ed2ad792cd7dde32 on 2026-03-22 [TBD][ 495052581 ] Medium CVE-2026-11005: Out of bounds read in ANGLE
Reported by 86ac1f1587b71893ed2ad792cd7dde32 on 2026-03-22 [N/A][ 495489174 ] Medium CVE-2026-11006: Out of bounds read in Dawn
Severity: medium
VulDB
Google Chrome up to 148.0.7778.216 Dawn out-of-bounds (ID 495489 / EUVD-2026-34455)
vuldb·2026-06-07·CVSS 6.5
CVE-2026-11006 [MEDIUM] Google Chrome up to 148.0.7778.216 Dawn out-of-bounds (ID 495489 / EUVD-2026-34455)
A vulnerability categorized as problematic has been discovered in Google Chrome. This issue affects some unknown processing of the component Dawn. Executing a manipulation can lead to out-of-bounds read.
The identification of this vulnerability is CVE-2026-11006. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.
GHSA
Out of bounds read in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
ghsa_unreviewed·2026-06-05
CVE-2026-11006 CWE-125 Out of bounds read in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Out of bounds read in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
No detection rules found.
No public exploits indexed.
2026-06-04
Published