Junglewise Threat Intelligence

CVE-2026-11661: Google Chrome use after free in Views

CVE-2026-11661 · Severity: info · Published 2026-06-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in the 'Views' component on Windows could allow an attacker who has already gained limited control over the browser's rendering process to escape the security sandbox. This could lead to unauthorized access to the underlying operating system and user data.

Technical details

A use-after-free (UAF) vulnerability exists in the Views component of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory for UI elements, allowing an attacker who has already compromised the renderer process to execute code outside of the browser's sandbox. Exploitation typically involves a crafted HTML page. This vulnerability was addressed in version 149.0.7827.103.

Affected products

  • Google Chrome prior to 149.0.7827.103

Timeline

  • 2026-05-16: disclosed: Reported to Chromium project
  • 2026-06-08: patched: Fixed in Stable Channel Update 149.0.7827.103
  • 2026-06-09: advisory: NVD publication date

References

Related threats