Junglewise Threat Intelligence

CVE-2026-10934: Google Chrome Autofill use after free sandbox escape

CVE-2026-10934 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability has been identified in the Autofill feature of Google Chrome on Android. This flaw could allow a malicious website to break out of the browser's security sandbox if the attacker has already compromised the browser's rendering process. Successfully exploiting this could lead to unauthorized access to the underlying mobile operating system and user data.

Technical details

A use-after-free (UAF) vulnerability exists in the Autofill component of Google Chrome for Android prior to version 149.0.7827.53. The flaw is triggered when the browser incorrectly manages memory during the processing of web forms. An attacker who has already achieved code execution within a compromised renderer process can leverage this vulnerability to perform a sandbox escape. This is typically achieved by enticing a user to visit a specially crafted HTML page. Google has addressed this issue in the stable channel update for version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-04-11: other: Reported by Google internal researchers
  • 2026-06-02: patched: Fixed in Chrome 149.0.7827.53 stable release
  • 2026-06-04: disclosed: Public advisory published

References

Related threats