CVE-2026-11057 is an uninitialized-use vulnerability in the Skia graphics component of Google Chrome before version 149.0.7827.53. A remote attacker who has already compromised the renderer process can trigger the flaw through a crafted HTML page to obtain potentially sensitive information from process memory. The specific vulnerable function is not identified.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a browser-based Android Chromium full-chain proof-of-concept that combines CVE-2026-11057 (Skia uninitialized glyph image memory leak) with CVE-2026-5281 (Dawn wire server DeviceInfo use-after-free). The repo is not a framework module; it is a standalone exploit research repository with 10 files: three primary C++ patch files, one main HTML/JavaScript exploit page, and several development artifacts under other/. Core structure and purpose: - SkStrike.cpp.patch modifies Skia's SkStrike::FlattenGlyphsByType to serialize glyph data in a way that causes the GPU process to create glyphs with valid metrics but null image pointers, enabling disclosure of uninitialized image buffer contents. - Device.cpp.patch adds SprayChunkedCommandsFromLabel(), invoked from Device::APICreateBuffer, which parses a specially formatted WebGPU buffer label ("CCM:<m_hex>:<n>") and injects many incomplete ChunkedCommands. These commands remain resident in the Dawn wire server and act as a heap spray containing fake Server / serializer / vtable structures tailored for Android ARM64. - ApiProcs.cpp.patch alters the QueueWriteBuffer path so that when bufferOffset equals 0x414141, it unregisters the Device object to free DeviceInfo, immediately serializes a small occupy ChunkedCommand to reclaim that freed slot, copies an attacker-controlled fake server pointer from the writeBuffer data, and then continues with an invalid offset to provoke the dangling callback path. - exploit.html is the main orchestrator. It uses canvas text rendering and pixel readback to recover leaked heap pointers, validates candidate pointers by looking for arithmetic runs at expected object strides, derives the PartitionAlloc pool base, computes the fake server target address M, creates a hidden iframe child that initializes WebGPU, triggers the CCM label-based spray, and then launches the 5281 trigger stage. Exploit capabilities: 1. Browser-accessible info leak from GPU-process memory via canvas glyph rendering. 2. Heap layout inference by deriving PartitionAlloc pool base from leaked pointers. 3. WebGPU-assisted heap spray into the GPU process using persistent incomplete ChunkedCommands. 4. Triggering a Dawn wire DeviceInfo use-after-free and reclaiming the freed slot with attacker-controlled data. 5. Redirecting a dangling callback to attacker-controlled fake server/vtable structures, reaching a controlled indirect call / vtable hijack crash. The repository explicitly states that disclosure stops at the vtable-hijack stage and does not include a post-control-flow RCE payload. Development files in other/ are auxiliary experiments: Android and Windows leak-only pages, a leak+spray page, and a debug logging patch. Overall, this is a real exploit PoC chain rather than a detector, with operational exploit logic but without a final weaponized payload.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An uninitialized-use vulnerability in Chrome's Skia component can disclose potentially sensitive process memory through a crafted HTML page. Exploitation requires an already-compromised renderer process. The advisory rates Chromium security severity as Medium and lists a CVSS v3 base score of 6.5. Updating Chromium and related packages to version 149.0.7827.53 or later addresses the vulnerability.
A vulnerability addressed by the Miracle Linux 9 WebKitGTK3 package update.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.