Executive brief
A security vulnerability exists in the USB component of Google Chrome for Android. By tricking a user into visiting a specially crafted website, an attacker could potentially bypass the browser's security sandbox. This could allow the attacker to gain unauthorized access to the underlying mobile operating system or sensitive user data.
Technical details
A use-after-free (UAF) vulnerability exists in the USB implementation within Google Chrome for Android. The flaw is triggered when the browser incorrectly manages memory during interactions with USB devices via the WebUSB API. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious HTML page. Successful exploitation could lead to a sandbox escape, allowing for arbitrary code execution outside of the browser's restricted environment. The issue is addressed in Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149 promoted to stable channel containing the fix.
- 2026-06-04: disclosed: CVE-2026-11188 published.