Junglewise Threat Intelligence

CVE-2026-11687: Google Chrome use after free in Dawn

CVE-2026-11687 · Severity: info · CVSS 8.8 · Published 2026-06-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability in its graphics component, Dawn, could allow a malicious website to corrupt the browser's memory. If exploited, this could lead to the browser crashing or potentially allow an attacker to gain unauthorized control over the user's system.

Technical details

A use-after-free (UAF) vulnerability exists in Dawn, the WebGPU implementation in Google Chrome for macOS. The flaw is triggered when the browser improperly manages memory lifecycles during the processing of graphics commands. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, leading to heap corruption. This can result in a stable browser crash (denial of service) or arbitrary code execution within the context of the browser process. The issue is resolved in Chrome version 149.0.7827.103 for Mac.

Affected products

  • Google Chrome prior to 149.0.7827.103

Timeline

  • 2026-05-28: disclosed: Reported by Google researchers
  • 2026-06-08: patched: Fixed in stable channel update 149.0.7827.102/.103
  • 2026-06-09: advisory: NVD publication date

References

Related threats