Junglewise Threat Intelligence

CVE-2026-11634: Google Chrome use after free in Gamepad component

CVE-2026-11634 · Severity: info · Published 2026-06-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A critical security vulnerability was found in its Gamepad component on Windows, which handles input from gaming controllers. An attacker could use a specially designed website to break out of the browser's security protections (the sandbox), potentially allowing them to gain unauthorized access to the underlying operating system and user data.

Technical details

A use-after-free (UAF) vulnerability exists in the Gamepad component of Google Chrome on Windows. The flaw is triggered when the browser incorrectly manages memory for gamepad devices, allowing a remote attacker to exploit the memory corruption via a malicious HTML page. This vulnerability is classified as Critical by Chromium because it can lead to a sandbox escape, allowing code execution outside of the restricted browser environment. The issue was addressed in version 149.0.7827.103.

Affected products

  • Google Chrome prior to 149.0.7827.103

Timeline

  • 2026-05-27: disclosed: Reported to the Chromium project
  • 2026-06-08: patched: Fixed in Stable Channel Update 149.0.7827.102/.103
  • 2026-06-09: advisory: NVD publication date

References

Related threats