Executive brief
A vulnerability in Google Chrome's PerformanceManager component could allow an attacker to bypass security protections. If a user visits a specially crafted website, an attacker who has already compromised the browser's rendering process could escape the 'sandbox'—the security layer designed to keep malicious code from reaching the rest of the computer. This could lead to unauthorized access to the user's system and data.
Technical details
A use-after-free (UAF) vulnerability exists in the PerformanceManager component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during performance monitoring tasks. An attacker who has already achieved code execution within a compromised renderer process can exploit this issue via a crafted HTML page to perform a sandbox escape. This allows the attacker to execute arbitrary code with the privileges of the browser process rather than the restricted renderer process. The vulnerability is addressed in Chrome version 148.0.7778.216 and later.
Affected products
- Google Chrome Prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for desktop
- 2026-05-28: disclosed: CVE published to NVD