Skip to main content
Mallory
Back to intelligence
widely-deployed-product-advisoryendpoint-software-vulnerabilityproof-of-concept-release

Google Chrome 149 fixes multiple high-severity memory corruption flaws

Updated 2d agoFirst seen Jun 5, 202649 sources

Google released a Stable Channel security update for Chrome Desktop, fixing a broad set of vulnerabilities in versions prior to 149.0.7827.53/54 on Windows and Mac and 149.0.7827.53 on Linux, while related records also show Chrome on Android was affected before 149.0.7827.53. The Canadian Centre for Cyber Security urged users and administrators to apply the update, and public CVE entries tie the release to numerous flaws across V8, Blink, WebRTC, Compositing, Dawn, DevTools, GPU, PDFium, Extensions, Media, TabStrip, Cast, LiveCaption, Google Lens, CSS, and USB. Many of the issues are memory-safety bugs such as use-after-free, out-of-bounds write/read, integer overflow, and type confusion, with several carrying CVSS vectors indicating high impact to confidentiality, integrity, and availability.

The patched vulnerabilities include remote code execution inside Chrome’s sandbox through crafted HTML pages or malicious PDF files, information disclosure from process memory, UI spoofing, navigation restriction bypass, privilege escalation on adjacent networks, and multiple paths that could aid sandbox escape after renderer compromise. Notable examples include CVE-2026-11188 in Android USB that could potentially enable sandbox escape, CVE-2026-11256 in the GPU component, CVE-2026-11173 in V8, CVE-2026-11118 and CVE-2026-11074 in WebRTC, and several PDFium bugs including CVE-2026-11303, CVE-2026-11305, and CVE-2026-11307. Visible metadata from one additional report also points to CVE-2026-10881, linked to Chrome 149, the ANGLE layer, and memory corruption involving GPU buffer overflow and use-after-free.

Share:
Google Chrome 149 fixes multiple high-severity memory corruption flaws
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

26 events from the most recent confirmed update back to the earliest known activity.

26 EVENTS
Jun 12, 20262d ago

CVE-2026-12028 disclosed for Chrome GPU on Android

On June 12, 2026, CVE-2026-12028 was documented as a high-severity use-after-free flaw in Chrome's GPU component on Android affecting versions prior to 149.0.7827.115. The vulnerability could allow a remote attacker, after compromising the renderer process via a crafted HTML page, to potentially escape Chrome's sandbox; the record was updated with CWE-416 and CVSS v3.1 details.

CVE-2026-12028 - Google Chrome GPU Use-After-Free Sandbox Escape

CVE-2026-12022 disclosed for Chrome Safe Browsing on Mac

On June 12, 2026, CVE-2026-12022 was documented as a high-severity race condition in Chrome's Safe Browsing component on Mac affecting versions prior to 149.0.7827.115. The flaw could allow a remote attacker, after compromising the renderer process, to potentially escape Chrome's sandbox via a malicious file; the record includes CWE-362 and CVSS v3.1 details.

CVE-2026-12022 - Google Chrome Race Condition Sandbox Escape

Google releases Chrome 149.0.7827.114/.115 desktop security update

Google shipped a new Stable Channel desktop update for Chrome 149, releasing version 149.0.7827.114/.115 for Windows and Mac and 149.0.7827.114 for Linux. The update fixes 28 security flaws, including five critical vulnerabilities affecting Core, DigitalCredentials, WebMIDI, Accessibility, and GPU components.

Chrome 149 Update Fixes 28 Security Flaws
Jun 11, 20263d ago

CVE-2026-12023 disclosed for Chrome GPU on Mac

On June 11, 2026, CVE-2026-12023 was recorded as a high-severity use-after-free flaw in Chrome's GPU component on Mac affecting versions prior to 149.0.7827.115. The vulnerability could allow a remote attacker, after compromising the renderer process via a crafted HTML page, to potentially escape Chrome's sandbox; the record was later updated with CWE-416 and CVSS v3.1 details.

CVE-2026-12023 - Google Chrome GPU Use-After-Free Sandbox Escape

CVE-2026-12030 disclosed for Chrome GPU on Android

On June 11, 2026, CVE-2026-12030 was documented as a high-severity out-of-bounds write flaw in Chrome's GPU component on Android affecting versions prior to 149.0.7827.115. The vulnerability could allow a remote attacker, after compromising the renderer process via a crafted HTML page, to potentially escape Chrome's sandbox; the record was later updated with CWE-122 and CVSS v3.1 details.

CVE-2026-12030 - Google Chrome GPU Out-of-Bounds Write Sandbox Escape

CVE-2026-12019 disclosed for Chrome Codecs on Linux and ChromeOS

On June 11, 2026, CVE-2026-12019 was documented as a high-severity heap buffer overflow in Chrome's Codecs component affecting Linux and ChromeOS versions prior to 149.0.7827.115. The flaw could allow a remote attacker, after compromising the renderer process via a crafted HTML page, to potentially escape Chrome's sandbox; the record was later updated with CWE-787 and CVSS v3.1 details.

CVE-2026-12019 - Google Chrome Codecs Heap Buffer Overflow Sandbox Escape
Jun 9, 20265d ago

CVE-2026-11700 disclosed for Chrome Tracing component

On June 9, 2026, references and metadata were added for CVE-2026-11700, a high-severity use-after-free flaw in Chrome's Tracing component affecting versions prior to 149.0.7827.103. The vulnerability could allow a remote attacker, after compromising the renderer process via a crafted HTML page, to potentially escape the sandbox; the record includes CWE-416 and CVSS v3.1 details.

CVE-2026-11700 - Google Chrome Use After Free

CVE-2026-11663 disclosed for Chrome Skia component

On June 9, 2026, references were added for CVE-2026-11663, a high-severity use-after-free flaw in Chrome's Skia component affecting versions prior to 149.0.7827.103. The vulnerability could allow a remote attacker, after compromising the renderer process via a crafted HTML page, to potentially escape Chrome's sandbox; the record includes CWE-416 and CVSS v3.1 details.

CVE-2026-11663 - Chrome Skia Use-After-Free Sandbox Escape

CVE-2026-11652 disclosed for Chrome Extensions

On June 9, 2026, references and metadata were added for CVE-2026-11652, a high-severity use-after-free flaw in Chrome's Extensions component affecting versions prior to 149.0.7827.103. The vulnerability could allow a remote attacker, after compromising the renderer process via a crafted HTML page, to potentially escape the sandbox; the record includes CWE-416 and CVSS v3.1 details.

CVE-2026-11652 - Google Chrome Use-After-Free Sandbox Escape

CVE-2026-11662 disclosed for Chrome Bindings component

On June 9, 2026, references were added for CVE-2026-11662, a high-severity type confusion flaw in Chrome's Bindings component affecting versions prior to 149.0.7827.103. The issue can be triggered by a crafted HTML page and may allow remote attackers to execute arbitrary code inside the browser sandbox; the record was later updated with CWE-843 and CVSS v3.1 details.

CVE-2026-11662 - Google Chrome Type Confusion Vulnerability

CVE-2026-11687 disclosed for Chrome Dawn on Mac

On June 9, 2026, references were added for CVE-2026-11687, a high-severity use-after-free flaw in Chrome's Dawn component on Mac affecting versions prior to 149.0.7827.103. The issue could allow a remote attacker to trigger heap corruption via a crafted HTML page, and the record includes CWE-416 and CVSS v3.1 details.

CVE-2026-11687 - Google Chrome Use-after-free

CVE-2026-11698 disclosed for Chrome Bluetooth on Mac

On June 9, 2026, references were added for CVE-2026-11698, a high-severity use-after-free flaw in Chrome's Bluetooth component on Mac affecting versions prior to 149.0.7827.103. The issue could allow a remote attacker to trigger heap corruption via a crafted HTML page, and the record includes CWE-416 and CVSS v3.1 details.

CVE-2026-11698 - Google Chrome Use-After-Free Bluetooth Vulnerability

CVE-2026-11651 disclosed for Chrome Network component

On June 9, 2026, references were added for CVE-2026-11651, a high-severity use-after-free flaw in Chrome's Network component affecting versions prior to 149.0.7827.103. The issue can be triggered by a crafted HTML page and may allow remote attackers to execute arbitrary code inside Chrome's sandbox; the record includes CWE-416 and CVSS v3.1 details.

CVE-2026-11651 - Google Chrome Use-After-Free in Network

CVE-2026-11647 disclosed for Chrome Printing on Android

On June 9, 2026, references were added for CVE-2026-11647, a high-severity use-after-free flaw in Chrome's Printing component on Android affecting versions prior to 149.0.7827.103. The vulnerability could allow a remote attacker, after compromising the renderer process via a crafted HTML page, to potentially escape the sandbox; the record includes CWE-416 and CVSS v3.1 details.

CVE-2026-11647 - Google Chrome Use-After-Free Sandbox Escape

CVE-2026-11674 disclosed for Chrome Guest View

On June 9, 2026, references were added for CVE-2026-11674, a high-severity use-after-free flaw in Chrome's Guest View component affecting versions prior to 149.0.7827.103. The issue can be triggered by a crafted HTML page and may allow remote attackers to execute arbitrary code inside Chrome's sandbox; the record includes CWE-416 and CVSS v3.1 details.

CVE-2026-11674 - Google Chrome Guest View Use-After-Free

CVE-2026-11680 disclosed for Chrome Media on Windows

On June 9, 2026, references were added for CVE-2026-11680, a high-severity use-after-free flaw in Chrome's Media component on Windows affecting versions prior to 149.0.7827.103. The issue can be triggered by a crafted HTML page and may allow remote attackers to execute arbitrary code inside Chrome's sandbox; the record was updated with CWE-416 and CVSS v3.1 details.

CVE-2026-11680 - Google Chrome Use-After-Free in Media

CVE-2026-11657 disclosed for Chrome Payments on Mac

On June 9, 2026, references were added for CVE-2026-11657, a high-severity use-after-free flaw in Chrome's Payments component on Mac affecting versions prior to 149.0.7827.103. The issue can be triggered by a crafted HTML page and may allow remote attackers to execute arbitrary code inside Chrome's sandbox.

CVE-2026-11657 - Google Chrome Use-After-Free Remote Code Execution

CVE-2026-11673 disclosed for Chrome InterestGroups component

On June 9, 2026, references were added for CVE-2026-11673, a high-severity use-after-free flaw in Chrome's InterestGroups component affecting versions prior to 149.0.7827.103. The issue can be triggered by a crafted HTML page and may allow remote attackers to execute arbitrary code inside the browser sandbox.

CVE-2026-11673 - Google Chrome: Use-After-Free in InterestGroups

CVE-2026-11643 disclosed for Chrome Proxy component

On June 9, 2026, references were added for CVE-2026-11643, a use-after-free flaw in Chrome's Proxy component affecting versions prior to 149.0.7827.103. The issue could allow remote attackers to execute arbitrary code via malicious network traffic, and the record was later enriched with CWE-416 and CVSS v3.1 details.

CVE-2026-11643 - Google Chrome Use-After-Free

CVE-2026-11688 disclosed for Chrome SVG implementation

On June 9, 2026, references were added for CVE-2026-11688, a high-severity inappropriate implementation flaw in Chrome's SVG component affecting versions prior to 149.0.7827.103. The issue can be triggered by a crafted HTML page and may allow arbitrary code execution inside Chrome's sandbox.

CVE-2026-11688 - Google Chrome SVG Sandbox Escape

CVE-2026-11683 disclosed for Chrome WebCodecs

On June 9, 2026, references were added for CVE-2026-11683, a high-severity use-after-free flaw in Chrome WebCodecs affecting versions prior to 149.0.7827.103. The issue can be triggered by a crafted HTML page and may allow remote code execution inside Chrome's sandbox.

CVE-2026-11683 - Google Chrome Use-After-Free
Jun 5, 20269d ago

Chrome CVE records are enriched with CVSS and CWE metadata

On June 5, 2026, many of the Chrome CVE entries were updated with CVSS v3.1 vectors, CWE mappings, descriptions, and references to the Chrome Releases blog and Chromium issue tracker. This added technical detail for both the June 4 and June 5 vulnerability records.

CVE-2026-11188 - Google Chrome Android Use-After-Free

Additional Chrome CVE records are received

On June 5, 2026, Google received additional CVE records for Chrome vulnerabilities affecting DevTools, GPU, PDFium, TabStrip, LiveCaption, Cast, and other components. These newly received entries expanded the set of flaws associated with the Chrome 149.0.7827.53 update cycle.

CVE-2026-11279 - Google Chrome Out-of-Bounds Read Sandbox Escape
Jun 4, 202610d ago

Google receives initial batch of Chrome CVE records

On June 4, 2026, Google received and recorded an initial batch of Chrome vulnerability entries affecting components including Dawn, V8, Blink, WebRTC, Media, CSS, Extensions, Compositing, and Android USB. These records covered flaws fixed in versions prior to Chrome 149.0.7827.53.

CVE-2026-11188 - Google Chrome Android Use-After-Free
Jun 3, 202611d ago

Canadian Centre for Cyber Security issues Chrome advisory

On June 3, 2026, the Canadian Centre for Cyber Security published advisory AV26-544, urging users and administrators to review Google's Chrome advisory and apply updates when available. The notice highlighted affected desktop versions on Windows, Mac, and Linux.

Google Chrome security advisory (AV26-544) - Canadian Centre for Cyber Security
Jun 2, 202612d ago

Google releases Chrome 149.0.7827.53/54 desktop security update

Google published a security advisory on June 2, 2026 for Stable Channel Chrome for Desktop, fixing vulnerabilities in versions prior to 149.0.7827.53/54 on Windows and Mac and prior to 149.0.7827.53 on Linux. The advisory is referenced across multiple CVE records tied to this stable channel update.

Google Chrome security advisory (AV26-544) - Canadian Centre for Cyber Security
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

56 LINKEDOpen in app
Vulnerabilities
52 linked
Use-after-free sandbox escape in Google Chrome DigitalCredentialsSandbox Escape in Google Chrome Accessibility on MacUse-after-free in Google Chrome Core on WindowsUse-after-free sandbox escape in Google Chrome WebMIDI on WindowsHeap Buffer Overflow in Chrome GPU Sandbox Escape on AndroidInteger overflow in Blink in Google ChromeUse-after-free in USB in Google Chrome on AndroidSandboxed code execution in Dawn in Google ChromeUse-after-free in WebRTC in Google ChromeNavigation restriction bypass in Google Lens in Google ChromeUse-after-free in PDFium in Google ChromePrivilege Escalation in Google Chrome CastUse-after-free in Google Chrome CompositingUI spoofing in Google Chrome MediaInformation disclosure in Google Chrome DevToolsUse-after-free in WebRTC in Google Chrome on LinuxUse-after-free in Google Chrome TabStripBad cast in Dawn in Google ChromeOut-of-bounds write in V8 in Google ChromeUse-after-free in PDFium in Google ChromeOut-of-bounds read in Google Chrome DevToolsSandbox escape via integer overflow in Chrome GPUOut-of-bounds memory access in Google Chrome LiveCaptionUse-after-free in Blink in Google ChromeSandbox escape in Google Chrome ANGLE via out-of-bounds read/writeUse-after-free in Media in Google ChromeUse-after-free in V8 in Google ChromeUse-after-free in PDFium in Google ChromeInsufficient policy enforcement in Google Chrome CompositingUse-after-free in Google Chrome ExtensionsType Confusion in CSS in Google ChromeUse-after-free in Guest View in Google ChromeSandbox escape use-after-free in Skia in Google ChromeType Confusion in Bindings in Google ChromeRCE in Google Chrome SVGUse-after-free in Media in Google Chrome on WindowsUse-after-free in Proxy in Google ChromeUse-after-free in Google Chrome NetworkUse-after-free in Google Chrome ExtensionsUse-after-free in Google Chrome Bluetooth on MacUse-after-free in Printing in Google Chrome on AndroidUse-after-free in Google Chrome Tracing sandbox escapeUse-after-free in Google Chrome WebCodecsUse-after-free in Dawn in Google Chrome on MacUse-after-free in Google Chrome InterestGroupsUse-after-free in Payments in Google Chrome on MacUse-after-free in GPU in Google Chrome on AndroidSandbox escape race in Safe Browsing in Google Chrome on MacHeap Buffer Overflow in Google Chrome Codecs Sandbox EscapeUse-after-free in Google Chrome GPU on MacUse-after-free in Google Chrome Media on WindowsSandbox escape via GPU out-of-bounds write in Google Chrome on Android
Affected products
1 linked
Chromeos
Organizations
3 linked
GoogleLinkedinX
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Google Chrome 149 fixes multiple high-severity memory corruption flaws | Mallory