Junglewise Threat Intelligence

CVE-2026-11235: Google Chrome insufficient policy enforcement in Compositing

CVE-2026-11235 · Severity: info · CVSS 2 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome's compositing engine could allow a remote attacker to execute unauthorized code. This issue specifically affects users who visit a malicious website using an older version of the browser. While the impact is limited by the browser's security sandbox, it represents a breakdown in the browser's internal policy enforcement.

Technical details

An insufficient policy enforcement vulnerability exists in the Compositing component of Google Chrome. The flaw (CWE-20) allows a remote attacker who has already achieved a renderer process compromise to bypass internal security boundaries and execute arbitrary code within the browser's sandbox. Exploitation requires the victim to navigate to a specially crafted HTML page. This vulnerability was addressed in Chrome version 149.0.7827.53. Google classified this as a 'Low' severity issue.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE-2026-11235 published.

References

Related threats