Description
Use after free in TabStrip in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-04
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Use after free in the TabStrip class of Google Chrome before 149.0.7827.53 allows a remote attacker to execute arbitrary code by serving a crafted HTML page. The flaw arises from an object being accessed after it has been freed, enabling the attacker to control memory references and trigger code execution. While the Chromium project rates this issue as low severity, the potential impact is full compromise of the user’s system, including integrity and confidentiality loss.

Affected Systems

Google Chrome versions prior to 149.0.7827.53 on Windows, macOS, Linux, or Chrome OS are affected.

Risk and Exploitability

The vulnerability can be exploited over the network by opening a malicious webpage in the browser. The EPSS score is not reported and it is not listed in the CISA KEV catalog, implying limited public exploitation data. However, the nature of a use‑after‑free bug can allow complete remote code execution if an attacker can host the crafted page and entice an end‑user to visit it.

Generated by OpenCVE AI on June 5, 2026 at 00:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Chrome update (149.0.7827.53 or newer) from the official release channel.
  • Keep the auto‑update feature enabled so that future patches are applied automatically.
  • In environments where timely updates are not feasible, consider disabling or sandboxing the execution of local or untrusted HTML content.

Generated by OpenCVE AI on June 5, 2026 at 00:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Jun 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 05 Jun 2026 01:15:00 +0000

Type Values Removed Values Added
Title Use After Free in Chrome TabStrip Enables Remote Code Execution

Fri, 05 Jun 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 04 Jun 2026 23:45:00 +0000

Type Values Removed Values Added
Description Use after free in TabStrip in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-05T00:24:36.914Z

Reserved: 2026-06-04T17:11:08.478Z

Link: CVE-2026-11262

cve-icon Vulnrichment

Updated: 2026-06-05T00:23:55.711Z

cve-icon NVD

Status : Received

Published: 2026-06-05T00:17:02.993

Modified: 2026-06-05T02:17:09.340

Link: CVE-2026-11262

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T01:00:15Z

Weaknesses