Executive brief
A critical security vulnerability has been identified in Google Chrome for macOS that could allow a remote attacker to execute malicious code on a user's computer. The issue exists within the browser's password management component and is triggered when a user is tricked into visiting a malicious website and performing specific mouse or keyboard actions. If exploited, this could lead to a full system compromise, unauthorized data access, or the installation of malware.
Technical details
A use-after-free (UAF) vulnerability exists in the Passwords component of Google Chrome for macOS (CWE-416). The flaw is triggered when the browser incorrectly manages memory during password-related operations, specifically when a user is induced to perform certain UI gestures on a malicious HTML page. A remote, unauthenticated attacker can exploit this to achieve arbitrary code execution (ACE) within the context of the browser process. Google has addressed this vulnerability in version 149.0.7827.53. The vulnerability was internally discovered by Google and assigned a 'Critical' severity rating by the Chromium project.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-05-27: other: Vulnerability reported to Chrome team
- 2026-06-02: patched: Fixed in stable channel update 149.0.7827.53/54
- 2026-06-04: disclosed: Public advisory published