Junglewise Threat Intelligence

CVE-2026-11030: Google Chrome use after free in Network component

CVE-2026-11030 · Severity: info · CVSS 6.5 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in the networking component of Google Chrome. A remote attacker could exploit this flaw by tricking a user into interacting with malicious network traffic, potentially leading to a browser crash or unauthorized code execution. This could compromise the confidentiality and integrity of the user's data or the stability of the application.

Technical details

A use-after-free (UAF) vulnerability exists in the Network component of Google Chrome prior to version 149.0.7827.53. The flaw is triggered when the browser incorrectly manages memory during the processing of network traffic, allowing an attacker to reference memory after it has been freed. A remote attacker can exploit this by delivering specially crafted network traffic to a victim's browser, potentially leading to heap corruption. Successful exploitation could allow for arbitrary code execution within the context of the browser process. Google has addressed this issue in the stable channel update 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Fixed in Chrome 149.0.7827.53 for Desktop
  • 2026-06-04: disclosed: NVD publication date

References

Related threats