Use after free in Base in Google Chrome on Linux prior to 149
Description
Use after free in Base in Google Chrome on Linux prior to 149
AI Analyst Comment
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Google
PRODUCT: Chrome
AFFECTED_VERSIONS: Chrome on Linux prior to 149.0.7827.53
---END_METADATA---
Description Summary:
A use-after-free vulnerability in the Base component of Google Chrome on Linux allows attackers to disclose sensitive process memory information.
Executive Summary:
A high-severity use-after-free vulnerability in the Base component of Linux-based Google Chrome could allow an attacker to exfiltrate sensitive memory data from the renderer process.
Vulnerability Details
CVE-ID: CVE-2026-11071
Affected Software: Google Chrome
Affected Versions: Chrome on Linux prior to 149.0.7827.53
Vulnerability: This use-after-free vulnerability occurs within the Base component. It requires the prior compromise of the renderer process and enables an attacker to leak sensitive information from process memory via a crafted HTML page.
Business Impact
The CVSS score of 8.8 highlights the high risk associated with this vulnerability. Information disclosure of this nature could lead to the exposure of authentication tokens, session data, or other sensitive corporate information, potentially facilitating further attacks or unauthorized access to internal systems.
Remediation Plan
Immediate Action: Update Google Chrome on Linux platforms to version 149.0.7827.53 immediately.
Proactive Monitoring: Perform regular audits of application logs and monitor for unusual memory access patterns that could indicate an exploitation attempt.
Compensating Controls: Ensure that browser sandboxing is strictly enforced and that users are instructed to avoid navigating to untrusted or suspicious websites.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of June 6, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
While this vulnerability requires a prior renderer process compromise, the resulting information disclosure is a severe concern for privacy and security. Administrators must ensure all Linux-based Chrome endpoints are updated to the latest version to close this security gap.