CVE-2026-11235: Insufficient policy enforcement in Compositing in Google Chrome prior to 149
Insufficient policy enforcement in Compositing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
Metrics
- CVSS v3.1
- 8.8
- Severity
- HIGH
- Fixed in
- 149.0.7827.53
- Affected Products
- 1
HarborGuard Analysis
Synopsis
Insufficient policy enforcement in the Compositing component of Google Chrome (versions prior to 149.0.7827.53) allows a remote attacker who has already compromised the renderer process to escape the browser sandbox and execute arbitrary code on the underlying host. The vulnerability is reachable over the network and requires no authentication, but does require the victim to visit a crafted HTML page. Successful exploitation gives the attacker full code execution outside the browser sandbox. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection capability is available across every HarborGuard environment: CVE-2026-11235 is ingested from upstream security feeds within minutes of publication and matched against all customer images, including custom-built images that bundle a Chromium or Chrome binary. Any image in a connected registry or CI pipeline that carries a vulnerable Chrome version is flagged automatically.
AvailableHarborGuard scores this finding at CVSS 8.8 (HIGH) and weights it against each environment's compliance policy to determine urgency and routing. Triage tickets are directed to the appropriate team inbox within each customer organization based on configured ownership rules.
AvailableA patched-image rebuild based on Chrome 149.0.7827.53 is available on HarborGuard for any environment where an affected image is detected. For customers with auto-remediation enabled, HarborGuard triggers a rebuild, runs a regression test suite against the updated image, and opens a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the crafted HTML page over the network, so the vulnerable Chrome instance must be reachable or browsing to attacker-controlled content.
- AuthenticationNot required
No account or credentials are needed; the attacker only needs the victim to load a crafted page.
- Victim interactionRequired
The victim must visit or be redirected to a crafted HTML page, making this a social-engineering or drive-by delivery scenario.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other unpredictable environmental factors.
Blast Radius
- An attacker who already holds renderer compromise can break out of the Chrome sandbox and execute arbitrary code as the browser process user on the host.
- Code execution outside the sandbox gives read access to files and credentials accessible by that user account on the host system.
- The attacker can write or modify files on the host, enabling persistence mechanisms or further lateral movement.
- The attacker can terminate or disrupt any process running under the same user, causing service disruption on the affected host.
How HarborGuard Handles This
Available on HarborGuard: detection for CVE-2026-11235 fires within minutes of image ingestion for any image carrying a Chrome binary older than 149.0.7827.53. Where compliance policy permits, a rebuild at the patched version is queued automatically. For customers who opt into auto-remediation, HarborGuard performs the rebuild, executes a regression test run against the updated image, and opens a pull request against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. For environments where auto-remediation is not configured, the patched rebuild is staged and a finding is surfaced in the dashboard for manual review and promotion.
Fix available
- Google / Chrome< 149.0.7827.53 (from 149.0.7827.53)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H