Junglewise Threat Intelligence

CVE-2026-11683: Google Chrome use after free in WebCodecs

CVE-2026-11683 · Severity: info · CVSS 8.8 · Published 2026-06-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's WebCodecs component could allow an attacker to execute malicious code on a user's computer. This occurs when a user visits a specially crafted website designed to exploit a memory handling error. While the exploit is contained within the browser's security sandbox, it could lead to unauthorized data access or browser instability.

Technical details

A use-after-free (UAF) vulnerability exists in the WebCodecs component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory lifecycle for objects during media processing. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website containing a specially crafted HTML page. Successful exploitation allows the attacker to execute arbitrary code within the context of the browser's sandboxed process. The issue is resolved in Google Chrome version 149.0.7827.103 for Windows and Mac, and 149.0.7827.102 for Linux.

Affected products

  • Google Chrome prior to 149.0.7827.103

Timeline

  • 2026-05-27: disclosed: Reported by Google researchers
  • 2026-06-08: patched: Stable channel update released
  • 2026-06-09: advisory: NVD publication date

References

Related threats