Junglewise Threat Intelligence

CVE-2026-11692: Google Chrome use after free in Read Anything

CVE-2026-11692 · Severity: info · CVSS 8.8 · Published 2026-06-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a security vulnerability in its 'Read Anything' feature, which provides a simplified view of web pages. An attacker could use a specially crafted website to take control of the browser's internal processes. If successful, this could allow the attacker to bypass security protections (the sandbox) that normally keep web content isolated from the rest of your computer.

Technical details

A use-after-free (UAF) vulnerability exists in the 'Read Anything' component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of specific web content. A remote attacker who has already compromised the renderer process can exploit this memory corruption to escape the Chrome sandbox by enticing a user to visit a malicious HTML page. This could lead to arbitrary code execution on the host operating system. The issue is resolved in Google Chrome version 149.0.7827.103 and later.

Affected products

  • Google Chrome prior to 149.0.7827.103

Timeline

  • 2026-05-28: disclosed: Reported to Chrome by Google researchers.
  • 2026-06-08: patched: Fixed in Chrome Stable channel update.
  • 2026-06-09: advisory: NVD publication date.

References

Related threats