Junglewise Threat Intelligence

CVE-2026-11074: Google Chrome use after free in WebRTC

CVE-2026-11074 · Severity: info · CVSS 6.5 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's WebRTC component, used for real-time communication like video calls, could allow a remote attacker to execute malicious code on a user's Linux system. This occurs when a user visits a specially crafted website, potentially leading to unauthorized access to personal data or full system compromise. Users should update to the latest version of Chrome to mitigate this risk.

Technical details

A use-after-free (UAF) vulnerability exists in the WebRTC component of Google Chrome for Linux. The flaw is triggered when the browser incorrectly manages memory during the processing of WebRTC sessions, allowing an attacker to reference memory after it has been freed. By enticing a user to visit a malicious HTML page, a remote attacker can exploit this condition to achieve arbitrary code execution within the context of the browser process. This issue was addressed in version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Fixed in Chrome version 149.0.7827.53 for Linux.
  • 2026-06-04: disclosed: CVE-2026-11074 published.

References

Related threats