CVE-2026-11293
A critical use-after-free bug in Google Chrome's input handling could let a remote attacker escape the browser's sandbox by getting a user to visit a specially crafted web page. The flaw affects Chrome versions before 149.0.7827.53 on Windows, macOS, and Linux.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Anyone using Google Chrome on Windows, macOS, or Linux prior to version 149.0.7827.53.
Real-world impact
An attacker could trick a user into visiting a malicious webpage and potentially break out of Chrome's security sandbox, which might allow them to access or modify data on the user's computer beyond what the browser normally permits.
Why this severity
This vulnerability scores 9.6 out of 10 because it can be exploited remotely over the internet, requires only basic user interaction (visiting a webpage), and could lead to complete compromise of the user's system. However, Google's own security team rated it as 'Low' severity, suggesting they may have additional protections in place.
What to do about it
- 01Update Google Chrome to version 149.0.7827.53 or later.
- 02Restart the browser to complete the update process.
NVD-referenced vendor advisory specifying patched version 149.0.7827.53
Timeline
- Jun 5, 2026 · Jun 5, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
- Jul 24, 2026 · 11d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- chromereleases.googleblog.com/2026/06/stable-channel-upda…release notes
- issues.chromium.org/issues/502362260permissions required