Junglewise Threat Intelligence

CVE-2026-11639: Google Chrome use after free in Compositing

CVE-2026-11639 · Severity: info · CVSS 9.8 · Published 2026-06-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical security vulnerability has been identified in Google Chrome for macOS that could allow a malicious website to take control of a user's computer. The issue exists in the browser's compositing engine, which is responsible for drawing and displaying web content. By tricking a user into visiting a specially crafted webpage, an attacker could potentially execute unauthorized code, leading to data theft or full system compromise.

Technical details

A use-after-free (UAF) vulnerability exists in the Compositing component of Google Chrome for macOS. The flaw is triggered when the browser incorrectly manages memory during the rendering process of a crafted HTML page. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website, leading to the execution of arbitrary code within the context of the browser process. This vulnerability is classified as 'Critical' by Chromium developers. Google has addressed this issue in version 149.0.7827.103 for Mac and Windows.

Affected products

  • Google Chrome prior to 149.0.7827.103

Timeline

  • 2026-05-27: disclosed: Reported to Chromium by Google researchers
  • 2026-06-08: patched: Fixed in Stable Channel Update 149.0.7827.102/.103
  • 2026-06-09: advisory: NVD publication date

References

Related threats