CVE-2026-11147

Google · Chrome

A Use-After-Free vulnerability in the WebML component of Google Chrome for Windows may allow an unauthenticated attacker to achieve arbitrary code execution.

Executive summary

A critical Use-After-Free vulnerability in the WebML component of Google Chrome on Windows presents a high-severity risk of remote code execution.

Vulnerability

This vulnerability involves a Use-After-Free (UAF) memory error within the WebML (Web Machine Learning) implementation. It can be triggered by an unauthenticated attacker via a crafted web page, leading to a crash or arbitrary code execution.

Business impact

With a CVSS score of 8.8, this flaw poses a significant threat to Windows-based environments. Successful exploitation allows for the execution of code with the privileges of the browser process, which could result in severe data theft or unauthorized access to sensitive system resources.

Remediation

Immediate Action: Update the Windows installation of Google Chrome to version 149 or later immediately.

Proactive Monitoring: Watch for unusual process spawns from the browser process and monitor for unexpected system crashes that could indicate exploitation attempts.

Compensating Controls: Restrict browser capabilities using Group Policy Objects (GPO) where possible and ensure that Windows Defender or third-party AV is configured to scan for browser-based threats.

Exploitation status

Public Exploit Available: false

Analyst recommendation

This vulnerability specifically impacts Windows users. Organizations should prioritize updating all Chrome instances on Windows platforms to version 149 to eliminate this risk, as UAF flaws are common targets for exploit development.