Junglewise Threat Intelligence

CVE-2026-11136: Google Chrome use after free in Canvas

CVE-2026-11136 · Severity: info · CVSS 6.5 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the Google Chrome web browser could allow a remote attacker to execute malicious code on a user's computer. This occurs when the browser processes a specially crafted web page using the Canvas component, which is responsible for rendering 2D and 3D graphics. While the exploit is limited by the browser's security sandbox, it could still lead to unauthorized data access or serve as a stepping stone for further system compromise.

Technical details

A use-after-free (UAF) vulnerability exists in the Canvas rendering component of Google Chrome. The flaw is triggered when the browser attempts to access memory that has already been deallocated during the processing of graphics instructions. A remote, unauthenticated attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation allows for arbitrary code execution (ACE) within the context of the Chromium sandbox. The issue is resolved in Google Chrome version 149.0.7827.53 and later.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE-2026-11136 published.

References

Related threats