Junglewise Threat Intelligence

CVE-2026-11632: Google Chrome use after free in TabStrip

CVE-2026-11632 · Severity: info · CVSS 9.8 · Published 2026-06-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical vulnerability exists in Google Chrome's tab management system. By tricking a user into visiting a malicious website and performing specific mouse or keyboard actions, an attacker could take control of the user's computer. This could lead to the theft of sensitive data, installation of malware, or complete system compromise.

Technical details

A use-after-free (UAF) vulnerability exists in the TabStrip component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory for tab UI elements, specifically when a user is coerced into performing specific UI gestures while viewing a malicious HTML page. An attacker can exploit this memory corruption to achieve remote code execution (RCE) within the context of the browser process. The vulnerability was patched in version 149.0.7827.103 for Windows and Mac, and 149.0.7827.102 for Linux.

Affected products

  • Google Chrome prior to 149.0.7827.103

Timeline

  • 2026-05-26: disclosed: Reported by Google internal researchers
  • 2026-06-08: patched: Fixed in Stable Channel Update 149.0.7827.103
  • 2026-06-09: advisory

References

Related threats