Junglewise Threat Intelligence

CVE-2026-11163: Google Chrome for Android use after free in Messages

CVE-2026-11163 · Severity: info · CVSS 6.5 · Published 2026-06-04

Technologies: Google Chrome for Android. Vendors: Google.

Executive brief

A vulnerability in the Messages component of Google Chrome for Android could allow a remote attacker to bypass security protections. By tricking a user into visiting a specially crafted website, an attacker could potentially escape the browser's security sandbox. This could lead to unauthorized access to the underlying mobile operating system and user data.

Technical details

A use-after-free (UAF) vulnerability exists in the Messages component of Google Chrome for Android. The flaw is triggered when the browser incorrectly manages memory during the processing of specific message-related events. A remote, unauthenticated attacker can exploit this by hosting a malicious HTML page and enticing a user to visit it. Successful exploitation could allow the attacker to execute arbitrary code outside of the browser's restricted sandbox environment. The issue is addressed in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome for Android prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149 stable channel update released
  • 2026-06-04: disclosed: CVE published to NVD

References

Related threats