Executive brief
A critical security vulnerability has been identified in Google Chrome for Linux that could allow an attacker to compromise a user's computer. By tricking a user into visiting a specially crafted website, an attacker could potentially gain unauthorized access to data or execute malicious code. This issue affects the browser's graphics component and has been addressed in the latest software update.
Technical details
A use-after-free (UAF) vulnerability exists in the GFX component of Google Chrome for Linux. The flaw is triggered when the browser improperly manages memory during the rendering of specially crafted HTML content. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious webpage, leading to heap corruption. This can result in arbitrary code execution within the context of the browser process. The vulnerability is fixed in version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-05-14: disclosed: Reported by Google internal researchers
- 2026-06-02: patched: Fixed in stable channel update 149.0.7827.53
- 2026-06-04: advisory: NVD publication date