Junglewise Threat Intelligence

CVE-2026-11028: Google Chrome use after free in Media component

CVE-2026-11028 · Severity: info · Published 2026-06-04

Technologies: Google ChromeOS, Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in the media processing component of Google Chrome for Linux and ChromeOS. This flaw could allow a remote attacker who has already partially compromised the browser's rendering process to execute malicious code. While the attack is limited by the browser's security sandbox, it represents a significant step in a multi-stage attack that could lead to unauthorized access to user data or system resources.

Technical details

A use-after-free (UAF) vulnerability exists in the Media component of Google Chrome for Linux and ChromeOS. The flaw is triggered when the browser incorrectly manages memory during the processing of media content. An attacker can exploit this by enticing a user to visit a specially crafted HTML page. A successful exploit requires the attacker to have already compromised the renderer process; from there, they can leverage this UAF to execute arbitrary code within the confines of the browser's sandbox. The issue is addressed in version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53
  • Google ChromeOS prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: CVE published to NVD

References

Related threats