Junglewise Threat Intelligence

CVE-2026-11636: Google Chrome use after free in Autofill

CVE-2026-11636 · Severity: info · CVSS 8.8 · Published 2026-06-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical security vulnerability has been identified in the Autofill feature of Google Chrome on Windows. This flaw could allow a malicious website to corrupt the browser's memory if a user performs specific interactions, such as clicking or typing on a specially crafted page. If successfully exploited, this could allow an attacker to gain control over the browser, potentially leading to the theft of sensitive information or the installation of malicious software.

Technical details

A use-after-free (UAF) vulnerability exists in the Autofill component of Google Chrome for Windows. The flaw is triggered when a user is enticed to perform specific UI gestures on a maliciously crafted HTML page, leading to heap corruption. This memory safety issue allows a remote attacker to potentially achieve arbitrary code execution within the context of the browser process. The vulnerability was addressed in Chrome version 149.0.7827.103. While the advisory lists the severity as 'Critical' by Chromium standards, it typically requires user interaction (UI gestures) to trigger the memory corruption.

Affected products

  • Google Chrome prior to 149.0.7827.103

Timeline

  • 2026-05-27: other: Reported to Google
  • 2026-06-08: patched: Fixed in stable channel update 149.0.7827.102/.103
  • 2026-06-09: disclosed: Public advisory published

References

Related threats