Junglewise Threat Intelligence

CVE-2026-11671: Google Chrome use after free in Navigation

CVE-2026-11671 · Severity: info · Published 2026-06-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its navigation component could allow a malicious website to bypass security boundaries (the 'sandbox') that normally keep web content isolated from the rest of the computer. If exploited, this could allow an attacker to gain unauthorized access to the underlying operating system or user data.

Technical details

A use-after-free (UAF) vulnerability exists in the Navigation component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during page navigation processes. A remote attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation could allow the attacker to escape the Chrome sandbox and execute arbitrary code in the context of the operating system. This issue was resolved in Google Chrome version 149.0.7827.103.

Affected products

  • Google Chrome prior to 149.0.7827.103

Timeline

  • 2026-05-26: disclosed: Reported to Chrome by Google researchers
  • 2026-06-08: patched: Stable channel update released
  • 2026-06-09: advisory: NVD publication date

References

Related threats