Executive brief
A vulnerability in Google Chrome's tab management component could allow a malicious website to execute unauthorized code on a user's computer. This occurs when a user visits a specially crafted webpage, potentially leading to the theft of sensitive data or a full system compromise. Users should update their browser to the latest version to mitigate this risk.
Technical details
A use-after-free (UAF) vulnerability exists in the TabStrip component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the handling of tab elements, allowing a remote attacker to exploit the memory corruption via a specially crafted HTML page. If successful, an attacker could achieve arbitrary code execution (ACE) within the context of the browser process. The vulnerability is assigned a 'Low' severity by Chromium and is addressed in version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-05: disclosed: CVE-2026-11262 published.