Junglewise Threat Intelligence

CVE-2026-11165: Google Chrome for iOS use after free in WebMIDI

CVE-2026-11165 · Severity: info · CVSS 6.5 · Published 2026-06-04

Technologies: Google Chrome, Google Chrome for iOS. Vendors: Google.

Executive brief

A security vulnerability exists in the Google Chrome browser for iOS devices. By tricking a user into visiting a specially crafted website, an attacker could potentially bypass security protections (the 'sandbox') that normally keep web content isolated from the rest of the device. This could lead to unauthorized access to sensitive data or broader control over the application.

Technical details

A use-after-free (UAF) vulnerability exists in the WebMIDI implementation of Google Chrome for iOS. The flaw is triggered when the browser incorrectly manages memory for MIDI device interfaces, allowing an attacker to reference memory after it has been freed. By enticing a user to visit a malicious website, a remote attacker can exploit this condition to execute arbitrary code or achieve a sandbox escape. The vulnerability was addressed in version 149.0.7827.53.

Affected products

  • Google Chrome for iOS prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149 stable channel update released
  • 2026-06-04: disclosed: NVD publication date

References

Related threats