Junglewise Threat Intelligence

CVE-2026-11115: Google Chrome use after free in Updater

CVE-2026-11115 · Severity: info · CVSS 0 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the Google Chrome updater on Windows could allow a local user to gain higher-level system permissions. By using a specially crafted malicious file, an attacker who already has basic access to a computer could take full control of the operating system. This could lead to unauthorized access to sensitive data or the ability to disable security software.

Technical details

A use-after-free (UAF) vulnerability exists in the Updater component of Google Chrome on Windows (versions prior to 149.0.7827.53). The flaw is triggered when the updater improperly handles memory after it has been freed, which can be exploited by a local attacker providing a malicious file. Successful exploitation allows the attacker to bypass security boundaries and achieve local privilege escalation (LPE) to system-level authority. Users are advised to update to version 149.0.7827.53 or later to mitigate this risk.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE-2026-11115 published.

References

Related threats