Junglewise Threat Intelligence

CVE-2026-11672: Google Chrome heap buffer overflow in GPU component

CVE-2026-11672 · Severity: info · CVSS 8.8 · Published 2026-06-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome on Android is a mobile web browser used for accessing the internet. A security vulnerability in the browser's graphics processing component could allow a malicious website to break out of the browser's security sandbox. This could lead to unauthorized access to the device's data or the ability to run malicious code outside of the browser's restricted environment.

Technical details

A heap buffer overflow (CWE-787) exists in the GPU component of Google Chrome for Android. The vulnerability is reachable by a remote attacker who has already compromised the renderer process, typically through a separate exploit. By enticing a user to visit a specially crafted HTML page, the attacker can leverage this out-of-bounds write to achieve a sandbox escape, gaining elevated privileges on the underlying operating system. The issue was addressed in version 149.0.7827.103.

Affected products

  • Google Chrome prior to 149.0.7827.103

Timeline

  • 2026-05-26: disclosed: Reported to Chromium by Google researchers
  • 2026-06-08: patched: Fixed in Stable Channel Update 149.0.7827.102/.103
  • 2026-06-09: advisory: NVD publication date

References

Related threats