CVE-2026-11688
Description
An object lifecycle issue flaw was found in the SVG component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=517309206
Statement
Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Understanding the Weakness (CWE)
Confidentiality
Technical Impact: Read Memory
If the untrusted pointer is used in a read operation, an attacker might be able to read sensitive portions of memory.
Availability
Technical Impact: DoS: Crash, Exit, or Restart
If the untrusted pointer references a memory location that is not accessible to the program, or points to a location that is "malformed" or larger than expected by a read or write operation, the application may terminate unexpectedly.
Integrity,Confidentiality,Availability
Technical Impact: Execute Unauthorized Code or Commands; Modify Memory
If the untrusted pointer is used in a function call, or points to unexpected data in a write operation, then code execution may be possible.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.