Junglewise Threat Intelligence

CVE-2026-11262: Google Chrome use after free in TabStrip

CVE-2026-11262 · Severity: info · CVSS 0 · Published 2026-06-05

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's tab management component could allow a malicious website to execute unauthorized code on a user's computer. This occurs when a user visits a specially crafted webpage, potentially leading to the theft of sensitive data or a full system compromise. Users should update their browser to the latest version to mitigate this risk.

Technical details

A use-after-free (UAF) vulnerability exists in the TabStrip component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the handling of tab elements, allowing a remote attacker to exploit the memory corruption via a specially crafted HTML page. If successful, an attacker could achieve arbitrary code execution (ACE) within the context of the browser process. The vulnerability is assigned a 'Low' severity by Chromium and is addressed in version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-05: disclosed: CVE-2026-11262 published.

References

Related threats