Integer overflow in Google Chrome - CVE-2026-11640

 

Integer overflow in Google Chrome - CVE-2026-11640

Published: June 9, 2026


Vulnerability identifier: #VU133985
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-11640
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in libyuv. A remote attacker can trick the victim into visiting a specially crafted website, trigger an integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Google Chrome
Microsoft Edge
Debian Linux
Fedora
Chrome OS
chromium
chromium (Debian package)

How to mitigate CVE-2026-11640

Install updates from vendor's website.

Google Chrome - update to 149.0.7827.102
Microsoft Edge - update to 149.0.4022.62
Chrome OS - update to 144.0.7559.255
chromium - addressed in versions 149.0.7827.102-1.el9, 149.0.7827.102-1.el10_2, 149.0.7827.102-1.el10_3, 149.0.7827.102-1.fc43, 149.0.7827.102-1.fc44
chromium (Debian package) - addressed in versions 149.0.7827.102-1~deb12u1, 149.0.7827.102-1~deb13u1

External References

Related Security Bulletins