Junglewise Threat Intelligence

CVE-2026-11679: Google Chrome use after free in Codecs

CVE-2026-11679 · Severity: info · CVSS 8.8 · Published 2026-06-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its media processing component could allow a malicious website to bypass the browser's security sandbox. If exploited, an attacker who has already gained limited control over the browser's rendering process could potentially execute commands on the underlying Windows operating system, leading to full system compromise or data theft.

Technical details

A use-after-free (UAF) vulnerability exists in the Codecs component of Google Chrome for Windows. The flaw is triggered when the browser improperly manages memory during the processing of media content. An attacker who has already compromised the renderer process (for example, through a separate memory corruption bug) can leverage this UAF to escape the Chromium sandbox. This is achieved by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to execute arbitrary code with the privileges of the user running the browser. The issue is resolved in Google Chrome version 149.0.7827.103.

Affected products

  • Google Chrome prior to 149.0.7827.103

Timeline

  • 2026-05-27: disclosed: Reported to the Chromium project
  • 2026-06-08: patched: Fixed in Stable Channel Update 149.0.7827.102/.103
  • 2026-06-09: advisory: NVD publication date

References

Related threats