CVE-2026-11118
Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a
CVSS
8.8
High
EPSS
0.4%
p32
KEV
—
Exploit Today
10
0-100
Published: Jun 4, 2026 · Last modified: Jul 23, 2026 · CWE-416
0.4%EPSS · 30 days0.4%
2026-08-242026-09-21
Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-940849.4 CRI34.1%
——10Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.2dCVE-2026-940553.7 LOW24.3%
——7Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.8hCVE-2026-880978.1 HIG12.7%
——4Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.2dCVE-2026-935862.9 LOW1.7%
——1ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, caused by a pointer that is not updated correctly. Exploitation may result in a limited availability impact (e.g., a crash of the affected process). The issue is fixed in versions 7.1.2-31 and 6.9.13-56.3dCVE-2026-933828.8 HIG31.1%
——9Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)3dCVE-2026-933749.6 CRI29.1%
——9Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)9h