Description
Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: High)
Published: 2026-06-08
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Use after free vulnerability exists in the ServiceWorker module of Google Chrome prior to version 149.0.7827.103. The flaw allows an attacker who tricks a user into installing a malicious Chrome extension to read or write memory after the original allocation has been freed. In the worst case this can undermine the browser sandbox and give the attacker elevated privileges or control over the victim’s system.

Affected Systems

Google Chrome browsers running any build older than 149.0.7827.103 are affected. The issue is specifically tied to the Chrome ServiceWorker implementation and only impacts installations that allow the installation of third‑party extensions.

Risk and Exploitability

The weakness has a CVSS score of 8.3, classifying it as High by Chromium. No EPSS score is available and the vulnerability is not currently listed in CISA KEV, suggesting a lower public exploitation probability. However, the attack requires social engineering to install a malicious extension. If an attacker succeeds, sandbox escape could lead to full system compromise. Due to the lack of a published exploit, it is not known how often this vulnerability is being exploited in the wild.

Generated by OpenCVE AI on June 9, 2026 at 03:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install any Chrome build 149.0.7827.103 or newer from the official release channel
  • Disable or remove any third‑party extensions that the user does not trust
  • Enable Chrome’s Safe Browsing protections to block malicious extensions from installing

Generated by OpenCVE AI on June 9, 2026 at 03:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 09 Jun 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Tue, 09 Jun 2026 04:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in ServiceWorker Allows Sandbox Escape via Malicious Extension

Tue, 09 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 09 Jun 2026 00:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in ServiceWorker Allows Sandbox Escape via Malicious Extension

Mon, 08 Jun 2026 23:45:00 +0000

Type Values Removed Values Added
Description Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-09T03:56:11.759Z

Reserved: 2026-06-08T21:33:42.002Z

Link: CVE-2026-11656

cve-icon Vulnrichment

Updated: 2026-06-09T01:36:51.584Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-09T00:16:48.580

Modified: 2026-06-09T14:58:20.520

Link: CVE-2026-11656

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-09T04:00:14Z

Weaknesses