Junglewise Threat Intelligence

CVE-2026-11657: Google Chrome use after free in Payments on macOS

CVE-2026-11657 · Severity: info · CVSS 8.8 · Published 2026-06-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in the Payments component of Google Chrome for macOS. This flaw could allow a malicious website to execute unauthorized code on a user's computer if they visit a specially crafted webpage. This could lead to the theft of sensitive information or full control over the affected browser session.

Technical details

A use-after-free (UAF) vulnerability exists in the Payments component of Google Chrome for macOS. The flaw is triggered when the browser incorrectly manages memory during payment processing operations. A remote, unauthenticated attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation allows for arbitrary code execution within the context of the browser process. This issue was addressed in Chrome version 149.0.7827.103 for Mac.

Affected products

  • Google Chrome prior to 149.0.7827.103

Timeline

  • 2026-05-15: disclosed: Reported to Chromium by Google researchers
  • 2026-06-08: patched: Fixed in Stable Channel Update 149.0.7827.102/.103
  • 2026-06-09: advisory: NVD publication date

References

Related threats