Description
Use after free in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use-after-free vulnerability (CWE-416) in Google Chrome’s Guest View allows a remote attacker to execute arbitrary code within the browser’s sandbox by serving a carefully crafted HTML page. Based on the description, it is inferred that the attacker must deliver a malicious HTML page while the user is in Guest View. This flaw enables bypassing the sandbox’s security boundaries, potentially compromising confidentiality, integrity, and availability if the user visits the malicious page. Chromium grading labels the severity as High.

Affected Systems

Google Chrome versions prior to 149.0.7827.103 are affected. Only the stable channel releases before this version are susceptible; versions 149.0.7827.103 and newer include the fix.

Risk and Exploitability

The CVSS score of 8.8 indicates high risk. EPSS data is currently unavailable, and the issue is not listed in the CISA KEV catalog, suggesting no known active exploitation. Based on the description, it is inferred that the likely attack vector requires a malicious webpage to be loaded while the target is using Guest View, implying that the attacker must either deceive the user into visiting the page or harvest an existing Guest View session. The presence of the use-after-free bug means that exploitation is possible without additional privileges, and the sandbox escape grants full code execution within the browser context. Given the lack of publicly available exploits, the likelihood of immediate attack remains moderate but at the same time the potential impact is severe.

Generated by OpenCVE AI on June 9, 2026 at 02:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 149.0.7827.103 or later, ensuring the patch is applied.
  • Disable the Guest View feature or restrict its use to trusted environments to eliminate the attack surface.
  • Enable automatic updates for Chrome so that future security fixes are applied promptly.

Generated by OpenCVE AI on June 9, 2026 at 02:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 09 Jun 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Tue, 09 Jun 2026 03:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Guest View Allows Remote Code Execution

Tue, 09 Jun 2026 01:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Guest View Allows Remote Code Execution
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Mon, 08 Jun 2026 23:45:00 +0000

Type Values Removed Values Added
Description Use after free in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-09T03:55:44.985Z

Reserved: 2026-06-08T21:33:48.758Z

Link: CVE-2026-11674

cve-icon Vulnrichment

Updated: 2026-06-09T01:02:05.409Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-09T00:16:50.673

Modified: 2026-06-09T14:54:17.200

Link: CVE-2026-11674

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-09T03:00:14Z

Weaknesses