Google Chrome < 149.0.7827.102 Multiple Vulnerabilities

critical Nessus Plugin ID 319881

Synopsis

A web browser installed on the remote macOS host is affected by multiple vulnerabilities.

Description

The version of Google Chrome installed on the remote macOS host is prior to 149.0.7827.102. It is, therefore, affected by multiple vulnerabilities as referenced in the 2026_06_stable-channel-update-for-desktop_0153744567 advisory.

- Use after free in Tracing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: Medium) (CVE-2026-11700)

- Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a local attacker to potentially exploit heap corruption via physical access to the device. (Chromium security severity: Critical) (CVE-2026-11628)

- Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) (CVE-2026-11629)

- Use after free in File Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) (CVE-2026-11630)

- Use after free in Aura in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: Critical) (CVE-2026-11631)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Google Chrome version 149.0.7827.102 or later.

See Also

https://crbug.com/513465272

https://crbug.com/513564337

https://crbug.com/513702971

https://crbug.com/513731890

https://crbug.com/513748868

https://crbug.com/513773313

https://crbug.com/513820666

https://crbug.com/513830374

https://crbug.com/513948465

https://crbug.com/514009323

https://crbug.com/514671098

https://crbug.com/515419790

https://crbug.com/515429352

https://crbug.com/515469283

https://crbug.com/516608438

https://crbug.com/516794471

https://crbug.com/516902973

https://crbug.com/516910450

https://crbug.com/516915337

https://crbug.com/516949298

https://crbug.com/516979551

http://www.nessus.org/u?f39848a0

https://crbug.com/516501794

https://crbug.com/516674532

https://crbug.com/516677924

https://crbug.com/516691130

https://crbug.com/516707881

https://crbug.com/516963272

https://crbug.com/516975148

https://crbug.com/516987814

https://crbug.com/517023053

https://crbug.com/517040438

https://crbug.com/517047197

https://crbug.com/517227707

https://crbug.com/517339758

https://crbug.com/517418936

https://crbug.com/517678820

https://crbug.com/518006379

https://crbug.com/518043597

https://crbug.com/506689381

https://crbug.com/517168239

https://crbug.com/502156940

https://crbug.com/506684534

https://crbug.com/511270083

https://crbug.com/511279942

https://crbug.com/511736002

https://crbug.com/513156160

https://crbug.com/513321171

https://crbug.com/513362710

https://crbug.com/513396305

https://crbug.com/513424000

https://crbug.com/517644287

https://crbug.com/517705966

https://crbug.com/517762104

https://crbug.com/517993381

https://crbug.com/518105731

https://crbug.com/518235412

https://crbug.com/518237527

https://crbug.com/511732085

https://crbug.com/516413817

https://crbug.com/516986556

https://crbug.com/516997135

https://crbug.com/517004487

https://crbug.com/517050585

https://crbug.com/517103584

https://crbug.com/517129549

https://crbug.com/517130229

https://crbug.com/517183713

https://crbug.com/517247333

https://crbug.com/517303276

https://crbug.com/517309206

https://crbug.com/517486004

https://crbug.com/517533654

https://crbug.com/517585486

https://crbug.com/517607902

Plugin Details

Severity: Critical

ID: 319881

File Name: macosx_google_chrome_149_0_7827_102.nasl

Version: 1.1

Type: Local

Agent: macosx

Published: 6/8/2026

Updated: 6/8/2026

Supported Sensors: Nessus Agent, Nessus

Risk Information

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-11700

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:google:chrome

Required KB Items: installed_sw/Google Chrome

Exploit Ease: No known exploits are available

Patch Publication Date: 6/8/2026

Vulnerability Publication Date: 6/8/2026

Reference Information

CVE: CVE-2026-11628, CVE-2026-11629, CVE-2026-11630, CVE-2026-11631, CVE-2026-11632, CVE-2026-11633, CVE-2026-11634, CVE-2026-11635, CVE-2026-11636, CVE-2026-11637, CVE-2026-11638, CVE-2026-11639, CVE-2026-11640, CVE-2026-11641, CVE-2026-11642, CVE-2026-11643, CVE-2026-11644, CVE-2026-11645, CVE-2026-11646, CVE-2026-11647, CVE-2026-11648, CVE-2026-11649, CVE-2026-11650, CVE-2026-11651, CVE-2026-11652, CVE-2026-11653, CVE-2026-11654, CVE-2026-11655, CVE-2026-11656, CVE-2026-11657, CVE-2026-11658, CVE-2026-11659, CVE-2026-11660, CVE-2026-11661, CVE-2026-11662, CVE-2026-11663, CVE-2026-11664, CVE-2026-11665, CVE-2026-11666, CVE-2026-11667, CVE-2026-11668, CVE-2026-11669, CVE-2026-11670, CVE-2026-11671, CVE-2026-11672, CVE-2026-11673, CVE-2026-11674, CVE-2026-11675, CVE-2026-11676, CVE-2026-11677, CVE-2026-11678, CVE-2026-11679, CVE-2026-11680, CVE-2026-11681, CVE-2026-11682, CVE-2026-11683, CVE-2026-11684, CVE-2026-11685, CVE-2026-11686, CVE-2026-11687, CVE-2026-11688, CVE-2026-11689, CVE-2026-11690, CVE-2026-11691, CVE-2026-11692, CVE-2026-11693, CVE-2026-11694, CVE-2026-11695, CVE-2026-11696, CVE-2026-11697, CVE-2026-11698, CVE-2026-11699, CVE-2026-11700, CVE-2026-11701