Junglewise Threat Intelligence

CVE-2026-11117: Google Chrome use after free in Views

CVE-2026-11117 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for Windows could allow a malicious website to execute unauthorized code on a user's computer. This occurs when the browser improperly handles memory while displaying certain visual elements. An attacker could exploit this by tricking a user into visiting a specially crafted webpage, potentially leading to the theft of sensitive data or full system compromise.

Technical details

A use-after-free (UAF) vulnerability exists in the 'Views' component of Google Chrome for Windows. The flaw is triggered when the browser attempts to access memory that has already been deallocated during the rendering of UI elements. A remote attacker can exploit this by hosting a malicious HTML page; when a victim visits the page, the attacker can achieve arbitrary code execution (ACE) within the context of the browser process. This vulnerability was addressed in version 149.0.7827.53.

Affected products

  • Google Chrome Prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE-2026-11117 published.

References

Related threats