Junglewise Threat Intelligence

CVE-2026-11694: Google Chrome use after free in ServiceWorker

CVE-2026-11694 · Severity: info · CVSS 8.8 · Published 2026-06-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its ServiceWorker component—which handles background tasks for websites—could allow a remote attacker to execute malicious code on a user's computer. To exploit this, an attacker would first need to compromise the browser's rendering process and then trick a user into visiting a specially crafted website. This could lead to unauthorized access to data or full system compromise within the browser's security sandbox.

Technical details

A use-after-free (UAF) vulnerability exists in the ServiceWorker component of Google Chrome prior to version 149.0.7827.103. The flaw is triggered when the browser incorrectly manages memory during the lifecycle of a ServiceWorker, allowing a remote attacker to exploit the memory corruption. A successful exploit requires the attacker to have already achieved code execution within the renderer process (a 'sandbox escape' chain component). By enticing a user to visit a malicious HTML page, the attacker can execute arbitrary code within the context of the browser's sandbox. Google has addressed this in the stable channel update to version 149.0.7827.103.

Affected products

  • Google Chrome prior to 149.0.7827.103

Timeline

  • 2026-05-28: disclosed: Reported to Chrome by internal/external researchers.
  • 2026-06-08: patched: Fixed in Chrome Stable channel update 149.0.7827.103.
  • 2026-06-09: advisory: NVD published the CVE record.

References

Related threats