Junglewise Threat Intelligence

CVE-2026-12011: Google Chrome use after free in WebMIDI

CVE-2026-12011 · Severity: info · Published 2026-06-11

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical security vulnerability has been identified in Google Chrome's WebMIDI component on Windows. This flaw could allow a remote attacker who has already gained partial control of the browser to bypass security 'sandbox' protections. If successfully exploited, an attacker could potentially gain broader access to the underlying operating system, leading to full system compromise or unauthorized data access.

Technical details

A use-after-free (UAF) vulnerability exists in the WebMIDI component of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory during the processing of MIDI-related data. An attacker who has already compromised the renderer process can exploit this condition via a specially crafted HTML page to achieve a sandbox escape. This allows the attacker to execute arbitrary code outside of the restricted browser environment on the host operating system. The issue is resolved in Google Chrome version 149.0.7827.115.

Affected products

  • Google Chrome prior to 149.0.7827.115

Timeline

  • 2026-05-30: disclosed: Reported to Google internally
  • 2026-06-11: advisory: Google Chrome stable channel update published
  • 2026-06-11: patched: Fix released in version 149.0.7827.115

References

Related threats