Executive brief
A vulnerability in Google Chrome's compositing engine—the component responsible for displaying web page elements—could allow a malicious website to execute unauthorized code. If a user visits a specially crafted web page, an attacker could potentially gain control over the browser's processes, though the impact is limited by the browser's security sandbox. This issue has been resolved in the latest version of Chrome.
Technical details
A use-after-free (UAF) vulnerability exists in the Compositing component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the rendering of complex web content, allowing an attacker to reference memory after it has been freed. By enticing a user to visit a maliciously crafted HTML page, a remote attacker can exploit this condition to achieve arbitrary code execution (ACE) within the context of the browser's sandboxed renderer process. The vulnerability is addressed in version 149.0.7827.53 and later.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE-2026-11125 published.