Executive brief
A critical security vulnerability has been identified in Google Chrome for Linux that could allow an attacker to compromise a user's computer. By tricking a user into visiting a malicious website and performing specific mouse or keyboard actions, an attacker could potentially execute unauthorized code or crash the browser. This issue affects the Ozone component, which handles how the browser interacts with the operating system's windowing system.
Technical details
A use-after-free (UAF) vulnerability exists in the Ozone abstraction layer of Google Chrome for Linux. The flaw is triggered when the browser incorrectly manages memory during specific UI gestures, leading to heap corruption. A remote attacker can exploit this by convincing a user to visit a specially crafted HTML page and perform specific UI interactions. Successful exploitation could lead to arbitrary code execution within the context of the browser process. The vulnerability is addressed in Google Chrome version 149.0.7827.53 for Linux.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-05-26: disclosed: Reported by Google researchers internally
- 2026-06-02: patched: Fixed in stable channel update 149.0.7827.53
- 2026-06-04: advisory: CVE published to NVD