Junglewise Threat Intelligence

CVE-2026-11637: Google Chrome use after free in Views on macOS

CVE-2026-11637 · Severity: info · CVSS 9.8 · Published 2026-06-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical security vulnerability has been identified in Google Chrome for macOS. This flaw exists in the 'Views' component, which handles the browser's user interface elements. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to take control of the computer or execute unauthorized commands. Users should update to version 149.0.7827.103 or later to protect their systems.

Technical details

A use-after-free (UAF) vulnerability exists in the Views component of Google Chrome for macOS. The flaw is triggered when the browser incorrectly manages memory for UI elements, allowing an attacker to reference memory after it has been freed. By enticing a user to visit a malicious HTML page, a remote attacker can exploit this memory corruption to execute arbitrary code within the context of the browser process. This vulnerability is tracked as CVE-2026-11637 and was addressed in the Stable channel update to version 149.0.7827.103.

Affected products

  • Google Chrome prior to 149.0.7827.103

Timeline

  • 2026-05-27: disclosed: Reported by Google researchers
  • 2026-06-08: patched: Fixed in version 149.0.7827.103 for Mac and Windows
  • 2026-06-09: advisory: NVD publication date

References

Related threats