Junglewise Threat Intelligence

CVE-2026-11009: Google Chrome use after free in USB component

CVE-2026-11009 · Severity: info · CVSS 6.5 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's USB component could allow a malicious website to break out of the browser's security sandbox. If an attacker convinces a user to visit a specially crafted webpage, they could potentially execute unauthorized commands on the underlying Windows operating system. This poses a significant risk to the confidentiality and integrity of data on the affected machine.

Technical details

A use-after-free (UAF) vulnerability exists in the USB implementation of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory pointers during USB device interactions, which can be exploited by a remote attacker using a specially crafted HTML page. Successful exploitation could allow the attacker to bypass the Chromium sandbox and execute arbitrary code in the context of the operating system. The vulnerability is addressed in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE-2026-11009 published.

References

Related threats