Junglewise Threat Intelligence

CVE-2026-11699: Google Chrome use after free in Bluetooth on macOS

CVE-2026-11699 · Severity: info · CVSS 8.8 · Published 2026-06-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in the Bluetooth component of Google Chrome for macOS. By tricking a user into visiting a specially crafted website, a remote attacker could cause the browser to crash or potentially execute unauthorized code on the user's computer. This could lead to the theft of sensitive information or a complete compromise of the browser session.

Technical details

A use-after-free (UAF) vulnerability exists in the Bluetooth implementation of Google Chrome for macOS. The flaw is triggered when the browser incorrectly manages memory lifecycle for Bluetooth-related objects, allowing an attacker to reference memory after it has been freed. By enticing a user to visit a malicious website, a remote attacker can leverage this heap corruption to achieve arbitrary code execution within the context of the browser process. The vulnerability is addressed in Chrome version 149.0.7827.103 for Mac.

Affected products

  • Google Chrome prior to 149.0.7827.103

Timeline

  • 2026-06-08: patched: Chrome Stable Channel Update released for Desktop
  • 2026-06-09: advisory: NVD published the CVE record

References

Related threats