Junglewise Threat Intelligence

CVE-2026-11648: Google Chrome use after free in FullScreen

CVE-2026-11648 · Severity: info · CVSS 8.8 · Published 2026-06-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in the FullScreen component of Google Chrome for Windows. By tricking a user into visiting a specially crafted website, an attacker could cause the browser to crash or potentially execute unauthorized code on the user's computer. This could lead to the theft of sensitive information or a complete compromise of the user's browsing session.

Technical details

A use-after-free (UAF) vulnerability exists in the FullScreen implementation of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory pointers after an object has been deleted, specifically during full-screen transitions or operations. A remote attacker can exploit this by enticing a user to visit a malicious HTML page, leading to heap corruption. Successful exploitation could allow for arbitrary code execution within the context of the browser's renderer process. The issue is addressed in Chrome version 149.0.7827.103 for Windows.

Affected products

  • Google Chrome prior to 149.0.7827.103

Timeline

  • 2026-04-27: disclosed: Reported by Mihnea Nicolau
  • 2026-06-08: patched: Fixed in Stable Channel Update 149.0.7827.102/.103
  • 2026-06-09: advisory: NVD publication date

References

Related threats