Critical· 9.6official fix available
CVE-2026-11065
A memory error in Chrome’s graphics engine could let a malicious web page escape the browser sandbox. The flaw is a use‑after‑free bug that can be triggered by a crafted HTML page.
publishedJun 4, 2026
last modifiedJul 23, 2026
sourcesNVD
severity · cvss
9.6
critical · how bad it is
exploitation · epss
<1%
25th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 22, 2026
An official fix is available, so this entry is kept for 30 days and then removed automatically.
01
Who is affected
Google Chrome browsers older than version 149.0.7827.53 on any platform.
02
Real-world impact
An attacker who can trick a user into opening a malicious page could break out of Chrome’s sandbox and potentially run code on the host system.
03
Why this severity
The CVSS score of 9.6 reflects that the vulnerability is exploitable over the network, requires no special privileges, and can lead to complete compromise of the host.
04
What to do about it
official fix available
recommended steps
- 01Upgrade Google Chrome to version 149.0.7827.53 or later.
- 02Restart the browser to ensure the new version is running.
NVD description indicates the issue is fixed in Chrome 149.0.7827.53 or later.
05
Timeline
- Jun 4, 2026 · Jun 4, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
- Jul 23, 2026 · 12d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
06
How it’s attacked
Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionRequired
ScopeChanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07
References & advisories
- chromereleases.googleblog.com/2026/06/stable-channel-upda…release notes
- issues.chromium.org/issues/499093536permissions required
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →