Executive brief
A security vulnerability in Google Chrome's networking component could allow a malicious website to escape the browser's security sandbox. If an attacker successfully exploits this flaw, they could potentially gain control over the underlying operating system or access sensitive data outside of the browser. Users should update to the latest version of Chrome to mitigate this risk.
Technical details
A use-after-free (UAF) vulnerability exists in the Network component of Google Chrome prior to version 149.0.7827.53. The flaw is triggered when the browser incorrectly manages memory during network operations, which can be exploited by a remote attacker who has already compromised the renderer process. By enticing a user to visit a specially crafted HTML page, the attacker can leverage this memory corruption to achieve a sandbox escape, potentially leading to arbitrary code execution on the host system. Google has addressed this issue in the stable channel update for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-02-25: disclosed: Reported by security researcher c6eed09fc8b174b0f3eebedcceb1e792
- 2026-06-02: patched: Fixed in Chrome version 149.0.7827.53
- 2026-06-04: advisory: NVD publication date