Description
Use after free in Aura in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Published: 2026-06-08
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw in the Aura rendering engine of Google Chrome on Windows allows an attacker who has already compromised the renderer process to potentially escape the browser sandbox by loading a specially crafted HTML page. The vulnerability belongs to CWE‑416 and, according to the Chromium security team, is rated Critical. If successfully exploited an attacker could gain arbitrary code execution outside the browser environment, compromising confidentiality, integrity, and availability of the host system. The description does not detail the exact sequence of steps a malicious page would need to trigger the flaw, but the requirement of a pre‑existing renderer compromise narrows the attack surface to scenarios in which the attacker can inject code into the renderer.

Affected Systems

Google Chrome browsers running on Windows that are versions prior to 149.0.7827.103 are affected. The vulnerability is fixed in version 149.0.7827.103 and later. All builds of Chrome for Windows prior to that release are potentially vulnerable if the renderer process can be compromised.

Risk and Exploitability

The EPSS score is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog. The Chromium security severity is marked Critical, indicating a high likelihood that a capable attacker will develop or adapt an exploit. The attack vector relies on a renderer process compromise, which can be achieved through malicious web content, phishing, or other means of exploiting a different vulnerability. Once in the renderer, the use‑after‑free can be leveraged to escape the sandbox and execute code with higher privileges. Given the combination of a critical rating, the absence of known public exploits, and the need for a renderer foothold, the overall risk is high for organizations that allow arbitrary web content or use Chrome in uncontrolled environments. The CVSS score of 8.3 highlights the severity of potential impact.

Generated by OpenCVE AI on June 9, 2026 at 12:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 149.0.7827.103 or later on all Windows systems.
  • Configure Chrome to run with automatic updates enabled to ensure continuous receipt of security patches.
  • Limit the exposure of the renderer process by disabling or sandboxing extensions and use a restricted user profile for untrusted web browsing.

Generated by OpenCVE AI on June 9, 2026 at 12:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 09 Jun 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows

Tue, 09 Jun 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 01:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Aura Leading to Sandbox Escape

Tue, 09 Jun 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Mon, 08 Jun 2026 23:45:00 +0000

Type Values Removed Values Added
Description Use after free in Aura in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-09T10:41:53.966Z

Reserved: 2026-06-08T21:33:32.692Z

Link: CVE-2026-11631

cve-icon Vulnrichment

Updated: 2026-06-09T10:41:49.474Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-09T00:16:45.623

Modified: 2026-06-09T14:45:17.290

Link: CVE-2026-11631

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-09T12:30:04Z

Weaknesses