Junglewise Threat Intelligence

CVE-2026-11050: Google Chrome use after free in V8

CVE-2026-11050 · Severity: info · CVSS 6.5 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's V8 engine could allow a remote attacker to execute unauthorized code on a user's computer. This occurs when a user visits a specially crafted, malicious website. While the attack is limited by the browser's security sandbox, it could still lead to data exposure or further system compromise if combined with other flaws.

Technical details

A use-after-free (UAF) vulnerability exists in the V8 JavaScript engine component of Google Chrome. The flaw is triggered when the engine attempts to access memory that has already been freed, which can be induced by a remote attacker through a specially crafted HTML page. Successful exploitation allows for arbitrary code execution within the context of the browser's renderer process (the sandbox). While the sandbox provides a layer of defense, this vulnerability represents a significant step in an exploit chain. The issue is resolved in Chrome version 149.0.7827.53 and later.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE-2026-11050 published.

References

Related threats