Description
Use after free in V8 in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Medium)
Published: 2026-06-04
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a use‑after‑free bug in the V8 JavaScript engine in Google Chrome versions prior to 149.0.7827.53. When a malicious Chrome Extension is installed, the engine can free memory and later access it again, allowing the attacker to run arbitrary code inside the sandboxed environment. The vulnerability is classified as CWE‑416 and CWE‑825 and carries a medium severity rating from Chromium security.

Affected Systems

Google Chrome on desktop platforms, specifically all stable channel releases before 149.0.7827.53. Users with earlier builds are affected; updated releases have the fix in place.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity and suggests that exploitation could lead to significant impact if achieved. The risk is high because exploitation requires the user to install a malicious extension, typically involving social engineering or a compromised extension source. The EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, meaning no known widespread exploitation. However, because the attack vector depends on user behavior, the threat remains significant for environments that allow unrestricted extension installation.

Generated by OpenCVE AI on June 7, 2026 at 14:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 149.0.7827.53 or later
  • Disable automatic installation of extensions from unknown or unverified sources through Chrome policy settings or the Settings > Extensions page
  • For existing installations, remove any suspicious or unverified extensions, review permissions in the Extensions manager, and consider running a malware scan to detect compromised extensions

Generated by OpenCVE AI on June 7, 2026 at 14:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6325-1 chromium security update
History

Sun, 07 Jun 2026 12:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: Use after free in V8
Weaknesses CWE-825
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 05 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Fri, 05 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in V8 via Malicious Chrome Extension

Fri, 05 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 05 Jun 2026 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 05 Jun 2026 05:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in V8 via Malicious Chrome Extension

Thu, 04 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Use after free in V8 in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Medium)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-05T18:55:22.278Z

Reserved: 2026-06-04T17:10:41.538Z

Link: CVE-2026-11185

cve-icon Vulnrichment

Updated: 2026-06-05T12:19:04.603Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-04T23:17:25.460

Modified: 2026-06-05T20:43:03.823

Link: CVE-2026-11185

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-06-02T00:00:00Z

Links: CVE-2026-11185 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-06-07T15:00:13Z

Weaknesses