CVE-2026-11699
📛 CVE Title
Chromium: CVE-2026-11698 Use after free in Bluetooth
Description
Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Overview
- State
- —
- Assigner (CNA)
- —
- CVSS severity
- high
- CVSS score
- 8.8 / 10
- CVSS vector
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H- Effective score
- 8.8 / 10 HIGH source: CNA overview
- CWE(s)
- —
- Reserved
- —
- Published
- 2026-06-09 07:00 UTC
- Last updated
- 2026-06-20 01:43 UTC
- Source
- https://www.tenable.com/cve/CVE-2026-11699
- Linked Threat
- CVE-2026-11699 — CVE-2026-11699
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-06-09 00:16:53 UTC
- NVD last modified
- 2026-07-23 08:10:00 UTC
- NVD CVSS v3.1
- 8.8 / 10 HIGH source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
- NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H- Exploitability subscore
- 2.8 / 10
- Impact subscore
- 5.9 / 10
- EPSS score
- 0.0020 (probability of exploitation in next 30 days)
- EPSS percentile
- 10.42% vs all CVEs — higher = more likely to be exploited, as of 2026-08-01
NVD-assigned CWE(s):
CWE-416
(differs from the CNA list above)
NVD / KEV / EPSS data refreshed 2026-08-01 16:33 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-35225 - Assigner
- Chrome
- Published
- Jun 8, 2026, 11:28:02 PM
- Updated
- Jun 9, 2026, 3:56:02 AM
- EUVD base score (CVSS 3.1)
-
8.8 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EUVD-reported EPSS
- 0.2000
- Vendors
- Products
-
Chrome (149.0.7827.103 <149.0.7827.103)
- Aliases
-
GHSA-wffw-9j7c-5pwf
ENISA description: Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Microsoft Security Response Center MSRC
Microsoft's vendor-authoritative record from the Security Update Guide — its own CVSS score, impact, severity rating, exploit assessment, and KB-article fixes. Refreshed 2026-07-23 03:00 UTC (source: CVRF).
- Release
- 2026-Jun
Microsoft remediations / KB articles (2)
- Release Notes — Vendor Fix / Security Update (fixed build 149.0.4022.62)
- https://docs.microsoft.com/en-us/DeployEdge/microsoft-edge-relnotes-security — None Available / Release Notes
Microsoft FAQ (2)
Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
- In your Microsoft Edge browser, click on the 3 dots (...) on the very right-hand side of the window
- Click on Help and Feedback
- Click on About Microsoft Edge
What is the version information for this release?
| Microsoft Edge Version | Date Released | Based on Chromium Version |
|---|---|---|
| 149.0.4022.62 | 06/15/2026 | 149.0.7827.103 |
Affected products — CPE 2.3 (2) NVD
NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
Vendor references (0)
References embedded in the original CVE record by the assigning CNA.
None in the CVE record.
Web references (6)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- None Available msrc
- MSRC update guide: CVE-2026-11699 msrc
- https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html tenable:chromereleases.googleblog.com
- https://issues.chromium.org/issues/518237527 tenable:issues.chromium.org
- https://nvd.nist.gov/vuln/detail/CVE-2026-11699 tenable:nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2026-11699 tenable:www.cve.org
NVD-tagged references (2)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html chrome-cve-admin@google.com Vendor Advisory
- https://issues.chromium.org/issues/518237527 chrome-cve-admin@google.com Permissions Required
Remediations (10)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:docs.nvidia.com
After restore, the command runs openclaw doctor -- fix for cross-version structure repair. ... Check for a NemoClaw CLI update and, when requested, run the maintained installer flow. This command is a discoverable CLI wrapper around the supported installer path:
2026-06-09 11:01 UTC -
web:federalnewsnetwork.com
We are entering an era where vulnerabilities are discovered at machine scale, far outstripping the human capacity to fix them.
2026-06-09 11:01 UTC -
web:hi.service-now.com
ServiceNow 24/7 Support Available Patches Australia Patch 2 Hot Fix 1 Zurich Patch 9 Hot Fix 1 See more for product documentation
2026-06-09 11:01 UTC -
web:msrc.microsoft.com
Security Update Guide - Microsoft Security Response Center
2026-06-09 11:01 UTC -
web:tarylfixesall.bigcartel.com
The official store for all your Taryl Apparel! American YouTube small engine master, Taryl Dactal's very own web store shipping worldwide! Now There's Your Dinner!! Support American Small Business 🇺🇸
2026-06-09 11:01 UTC -
web:translate.google.com
Google's service, offered free of charge, instantly translates words, phrases, and web pages between English and over 100 other languages.
2026-06-09 11:01 UTC -
web:wa.me
Hosted by WhatsApp 2026 © WhatsApp LLC Privacy & Terms
2026-06-09 11:01 UTC -
web:www.3cx.com
Action required due to a web server configuration vulnerability. 3CX has released a security hotfix relating to a third party component. If your 3CX
2026-06-09 11:01 UTC -
web:www.grammarly.com
Grammarly makes AI writing convenient. Work smarter with personalized AI guidance and text generation on any app or website.
2026-06-09 11:01 UTC -
web:www.virustotal.com
VirusTotal is a platform for scanning files and URLs for viruses, malware, and other threats using multiple antivirus engines.
2026-06-09 11:01 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.