Executive brief
A security vulnerability in Google Chrome's compositing engine could allow a remote attacker to execute unauthorized code. This issue specifically affects users who visit a malicious website using an older version of the browser. While the impact is limited by the browser's security sandbox, it represents a breakdown in the browser's internal policy enforcement.
Technical details
An insufficient policy enforcement vulnerability exists in the Compositing component of Google Chrome. The flaw (CWE-20) allows a remote attacker who has already achieved a renderer process compromise to bypass internal security boundaries and execute arbitrary code within the browser's sandbox. Exploitation requires the victim to navigate to a specially crafted HTML page. This vulnerability was addressed in Chrome version 149.0.7827.53. Google classified this as a 'Low' severity issue.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE-2026-11235 published.