Junglewise Threat Intelligence

CVE-2026-11012: Google Chrome for Android use after free in Serial

CVE-2026-11012 · Severity: info · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for Android could allow a remote attacker to bypass security protections. By convincing a user to visit a specially crafted website, an attacker who has already compromised part of the browser's internal processes could escape the 'sandbox'—a security layer designed to keep malicious code from accessing the rest of the device. This could lead to unauthorized access to user data or further control over the mobile device.

Technical details

A use-after-free (UAF) vulnerability exists in the Serial component of Google Chrome for Android. The flaw is triggered when the browser incorrectly manages memory during the lifecycle of serial port objects. An attacker who has already achieved code execution within the renderer process can exploit this memory corruption to escape the Chrome sandbox via a crafted HTML page. This vulnerability was addressed in version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149 promoted to stable channel
  • 2026-06-04: disclosed: NVD publication date

References

Related threats