CVE-2026-11633
Google · Chrome
A Use-After-Free vulnerability exists in the Bluetooth component of Google Chrome on macOS.
Executive summary
A critical-risk Use-After-Free vulnerability in the Bluetooth component of Google Chrome on macOS poses a significant threat to user system security.
Vulnerability
This is a Use-After-Free vulnerability located specifically within the Bluetooth subsystem of Chrome for Mac. It allows for potential arbitrary code execution if an attacker can manipulate the browser's memory state through malicious web content.
Business impact
With a CVSS score of 8.8, this flaw is highly dangerous for macOS environments. Successful exploitation could lead to full system compromise, bypassing operating system-level protections and resulting in significant data loss or unauthorized administrative access.
Remediation
Immediate Action: Update Google Chrome on all macOS devices to version 149.0.7827.54 immediately.
Proactive Monitoring: Monitor macOS system logs for suspicious activity related to Bluetooth services or unexpected browser behavior.
Compensating Controls: Disable unnecessary browser features and utilize strict endpoint security policies to limit the potential impact of a browser compromise.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Given the elevated risk to macOS users, immediate patching of the Chrome browser is mandatory. This vulnerability underscores the importance of maintaining up-to-date software to prevent exploitation of low-level system components.