Junglewise Threat Intelligence

CVE-2026-11249: Google Chrome use after free in Network component

CVE-2026-11249 · Severity: info · CVSS 0 · Published 2026-06-05

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the Google Chrome web browser could allow a remote attacker to access sensitive information from the computer's memory. This occurs when a user visits a specially crafted website using an older version of the browser. While the risk is classified as low, it could be used by attackers who have already partially compromised the browser to gain further access to private data.

Technical details

This vulnerability is a use-after-free (UAF) flaw within the Network stack of the Chromium engine. The issue is triggered when the browser incorrectly manages memory lifecycle for network-related objects, allowing a remote attacker to exploit the memory corruption. A precondition for this attack is that the renderer process must already be compromised. By enticing a user to visit a malicious HTML page, the attacker can leverage this UAF condition to read sensitive information from the process memory. Google has addressed this in version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-05: disclosed: CVE published.

References

Related threats