Junglewise Threat Intelligence

CVE-2026-11185: Google Chrome V8 use after free via malicious extension

CVE-2026-11185 · Severity: info · CVSS 6.5 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's V8 engine could allow a malicious browser extension to execute unauthorized code. If a user is tricked into installing a specifically crafted extension, an attacker could gain control within the browser's security sandbox. This could lead to the compromise of browser data or serve as a stepping stone for further attacks on the user's system.

Technical details

A use-after-free (UAF) vulnerability exists in the V8 JavaScript engine within Google Chrome prior to version 149.0.7827.53. The flaw is triggered when a user installs and runs a specially crafted Chrome Extension designed to exploit memory management errors in the engine. Successful exploitation allows an attacker to achieve arbitrary code execution (ACE) within the confines of the browser's sandbox. This requires user interaction in the form of installing a malicious extension. Google has addressed this issue in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE-2026-11185 published.

References

Related threats