Junglewise Threat Intelligence

CVE-2026-11042: Google Chrome use after free in Views

CVE-2026-11042 · Severity: info · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in the browser's user interface component could allow a remote attacker to cause memory corruption if they can trick a user into performing specific mouse or keyboard actions on a malicious webpage. This could potentially lead to the browser crashing or allow the attacker to execute unauthorized code on the user's system.

Technical details

A use-after-free (UAF) vulnerability exists in the 'Views' component of Google Chrome. The flaw is triggered when a remote attacker provides a specially crafted HTML page and successfully convinces a user to perform specific UI gestures. This sequence leads to the reuse of memory after it has been freed, resulting in heap corruption. An attacker could leverage this to achieve arbitrary code execution within the context of the browser process, though it is mitigated by the requirement for specific user interaction. The issue is addressed in version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: CVE published

References

Related threats