
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-11634 is a use-after-free vulnerability in the Gamepad component of Google Chrome on Windows that allows a remote attacker to potentially perform a sandbox escape via a crafted HTML page. It was reported internally by Google on May 27, 2026, and publicly disclosed on June 8–9, 2026, as part of a large Chrome stable channel update (149.0.7827.102/.103). All Chrome versions prior to 149.0.7827.103 on Windows are affected. It carries a CVSS v3.1 base score of 9.6 (Critical) and is rated Critical by Chromium's internal severity scale (Chrome Release, GitHub Advisory).
The vulnerability is classified as CWE-416 (Use After Free), occurring in Chrome's Gamepad API implementation on Windows. A use-after-free flaw arises when memory associated with a Gamepad object is freed but a dangling pointer to that memory is subsequently accessed, potentially allowing an attacker to control the freed memory region and redirect execution flow. Exploitation requires a user to visit or be redirected to a malicious HTML page, at which point the crafted page can trigger the memory corruption condition. The Chromium issue tracker entry is tracked under issue ID 516975148 (Chrome Release, GitHub Advisory).
Successful exploitation could allow a remote attacker to escape Chrome's sandbox and execute arbitrary code with elevated privileges on the underlying Windows host system. This results in high confidentiality, integrity, and availability impact — an attacker could access sensitive data, modify system files, install malware, or pivot to other systems on the network. The changed scope (S:C) in the CVSS vector reflects that the impact extends beyond the browser process itself to the host operating system (GitHub Advisory, Chrome Release).
chrome.exe) to unknown external IP addresses or domains following a web page visit; HTTP/HTTPS requests to newly registered or low-reputation domains serving HTML content that references Gamepad API.chrome.exe on Windows (e.g., cmd.exe, powershell.exe, wscript.exe) that are not typical browser subprocesses; renderer processes (chrome.exe --type=renderer) spawning system-level commands.chrome.exe as the parent and unexpected executables as children; application crash logs or Windows Error Reporting entries referencing Gamepad-related Chrome components.Google has released a patch in Chrome stable channel version 149.0.7827.103 for Windows (and 149.0.7827.102 for Mac and Linux), which addresses CVE-2026-11634 along with 73 other security fixes. Users and administrators should update Chrome to version 149.0.7827.103 or later immediately via Chrome's built-in update mechanism (Settings > Help > About Google Chrome). As a temporary workaround prior to patching, users should avoid visiting untrusted websites or opening HTML files from unknown sources. Enterprise administrators can enforce Chrome updates via Group Policy or Chrome Browser Cloud Management (Chrome Release, GitHub Advisory).
The June 8, 2026 Chrome update attracted broad attention primarily due to the confirmed in-the-wild exploitation of the co-patched CVE-2026-11645 (V8 out-of-bounds access), which overshadowed CVE-2026-11634 in media coverage. The Center for Internet Security (CIS) issued an advisory noting that multiple vulnerabilities in this Chrome update, including CVE-2026-11634, could allow for arbitrary code execution. Security outlets including GBHackers, CyberInsider, and CyberPress covered the update with emphasis on the zero-day (CVE-2026-11645), while CVE-2026-11634 was noted as part of the broader critical patch batch (CIS Advisory, Chrome Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."