CVE-2026-11114
A memory error in Google Chrome on macOS lets a malicious web page escape the browser sandbox if the attacker can already compromise the renderer process. The flaw is a use‑after‑free bug that could let the attacker gain full system access.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Google Chrome on macOS versions earlier than 149.0.7827.53. Users running those versions on Apple macOS are at risk.
Real-world impact
An attacker could use a specially crafted web page to escape the browser sandbox and execute arbitrary code on the victim’s computer, potentially taking full control of the system.
Why this severity
The CVSS score of 9.6 reflects that the vulnerability can be exploited over the network, requires no user interaction beyond visiting a page, and gives an attacker complete compromise of confidentiality, integrity, and availability.
What to do about it
- 01Upgrade Google Chrome to version 149.0.7827.53 or later.
- 02Restart Chrome.
NVD description indicates fix in Chrome version 149.0.7827.53 or later.
Timeline
- Jun 4, 2026 · Jun 4, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
- Jul 24, 2026 · 11d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- chromereleases.googleblog.com/2026/06/stable-channel-upda…vendor advisory
- issues.chromium.org/issues/501360342permissions required