Junglewise Threat Intelligence

CVE-2026-11071: Google Chrome use after free in Base

CVE-2026-11071 · Severity: info · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A memory management vulnerability exists in Google Chrome for Linux. This flaw allows a remote attacker who has already partially compromised the browser's rendering process to access sensitive information from the computer's memory. This could lead to the exposure of private data or help an attacker bypass further security protections.

Technical details

A use-after-free (UAF) vulnerability exists in the 'Base' component of Google Chrome for Linux. The flaw is triggered when the browser incorrectly manages memory pointers, allowing a remote attacker who has already compromised the renderer process to read sensitive information from process memory via a specially crafted HTML page. This vulnerability is tracked as CWE-416. It requires the attacker to have a foothold in the renderer process as a precondition. The issue is resolved in Google Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Stable channel update released for Linux
  • 2026-06-04: disclosed: CVE published to NVD

References

Related threats