Junglewise Threat Intelligence

CVE-2026-11628: Google Chrome use after free in Ozone

CVE-2026-11628 · Severity: info · Published 2026-06-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical security vulnerability exists in Google Chrome's Ozone component, which handles input and graphics for different windowing systems. An attacker with physical access to a device could exploit this flaw to corrupt the browser's memory. This could potentially lead to a complete system compromise or unauthorized access to sensitive data stored within the browser.

Technical details

A use-after-free (UAF) vulnerability exists in the Ozone abstraction layer of Google Chrome. The flaw is triggered via physical access to the device, allowing a local attacker to exploit memory corruption in the heap. Ozone is Chromium's platform abstraction layer used for supporting various windowing systems (like Wayland or X11). Successful exploitation could lead to arbitrary code execution within the context of the browser process. The issue is resolved in Google Chrome version 149.0.7827.103 for Windows and Mac, and 149.0.7827.102 for Linux.

Affected products

  • Google Chrome prior to 149.0.7827.103

Timeline

  • 2026-05-25: disclosed: Reported by Google researchers
  • 2026-06-08: patched: Stable channel update released
  • 2026-06-09: advisory: NVD publication date

References

Related threats