Junglewise Threat Intelligence

CVE-2026-11131: Google Chrome Autofill use after free in Android

CVE-2026-11131 · Severity: info · CVSS 6.5 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in the Autofill feature of Google Chrome on Android. This flaw could allow a malicious website to break out of the browser's security sandbox if the attacker has already compromised the browser's rendering process. Successfully exploiting this could lead to unauthorized access to the device's operating system or user data.

Technical details

A use-after-free (UAF) vulnerability exists in the Autofill component of Google Chrome for Android prior to version 149.0.7827.53. The flaw is triggered when the browser incorrectly manages memory during the processing of autofill data. An attacker who has already achieved code execution within the renderer process can exploit this issue via a specially crafted HTML page to perform a sandbox escape. This would allow the attacker to execute arbitrary code with the privileges of the browser application on the underlying Android operating system. The vulnerability is mitigated by the requirement of a prior renderer compromise. Google has addressed this in the stable channel update.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: CVE published by NVD

References

Related threats