Junglewise Threat Intelligence

CVE-2026-11629: Google Chrome use after free in Ozone

CVE-2026-11629 · Severity: info · Published 2026-06-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A critical security vulnerability was identified in its Ozone component, which handles windowing and input. An attacker could exploit this flaw by tricking a user into visiting a specially crafted website, potentially leading to a complete system compromise or unauthorized access to sensitive data.

Technical details

A use-after-free (UAF) vulnerability exists in the Ozone abstraction layer of Google Chrome. The flaw is triggered when the browser incorrectly manages memory lifecycle for objects within the Ozone component, which is responsible for supporting various windowing systems (like Wayland or X11). A remote attacker can exploit this by enticing a user to load a maliciously crafted HTML page, leading to heap corruption. This can result in arbitrary code execution within the context of the browser process. The vulnerability is addressed in Google Chrome version 149.0.7827.103 for Windows and Mac, and 149.0.7827.102 for Linux.

Affected products

  • Google Chrome prior to 149.0.7827.103

Timeline

  • 2026-05-26: disclosed: Reported by Google researchers
  • 2026-06-08: patched: Fixed in Stable Channel Update 149.0.7827.102/.103
  • 2026-06-09: advisory: NVD publication date

References

Related threats