CVE-2026-11638
A critical flaw in Google Chrome’s printing feature lets a remote attacker use a specially crafted web page to escape the browser sandbox. The bug is a use‑after‑free error that could allow the attacker to run code on the victim’s machine. It affects all Chrome installations before version 149.0.7827.103 on Windows, macOS, and Linux.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users of Google Chrome versions earlier than 149.0.7827.103 on Windows, macOS, and Linux are affected.
Real-world impact
An attacker could load a malicious web page that triggers the bug, escape the browser sandbox, and run arbitrary code on the victim’s computer, potentially taking full control.
Why this severity
The CVSS score of 9.6 reflects that the flaw is exploitable over the network, requires no user interaction beyond viewing a page, and gives the attacker full compromise of confidentiality, integrity, and availability.
What to do about it
- 01Upgrade Google Chrome to version 149.0.7827.103 or later.
- 02Restart the browser to complete the update.
NVD description
Timeline
- Jun 9, 2026 · Jun 9, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
- Jul 24, 2026 · 11d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- chromereleases.googleblog.com/2026/06/stable-channel-upda…release notesvendor advisory
- issues.chromium.org/issues/517047197permissions required