Junglewise Threat Intelligence

CVE-2026-11100: Google Chrome use after free in File Input on macOS

CVE-2026-11100 · Severity: info · CVSS 0 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome for macOS could allow a malicious website to escape the browser's security sandbox. To exploit this, an attacker must trick a user into performing specific mouse or keyboard actions on a specially crafted webpage. If successful, this could allow the attacker to gain unauthorized access to the underlying operating system, potentially compromising user data or system integrity.

Technical details

A use-after-free (UAF) vulnerability exists in the File Input component of Google Chrome for macOS. The flaw is triggered when a user is convinced to engage in specific UI gestures on a malicious HTML page, leading to memory corruption. A remote attacker can leverage this condition to achieve a sandbox escape, potentially executing code outside the restricted browser environment. This issue is tracked as CWE-416 and was resolved in version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53/54 released for Windows and Mac.
  • 2026-06-04: disclosed: CVE-2026-11100 published.

References

Related threats