Executive brief
A vulnerability exists in Google Chrome's WebAuthentication component, which handles secure logins and hardware security keys. An attacker could exploit this flaw by tricking a user into visiting a malicious website and performing specific mouse or keyboard actions. Successful exploitation could allow the attacker to crash the browser or potentially execute unauthorized code on the user's computer, compromising personal data and system security.
Technical details
A use-after-free (UAF) vulnerability exists in the WebAuthentication component of Google Chrome prior to version 149.0.7827.53. The flaw is triggered when the browser incorrectly manages memory during the processing of WebAuthn requests, specifically when a user is coerced into performing certain UI gestures on a malicious webpage. This memory corruption can lead to heap corruption, which a remote attacker could leverage to achieve arbitrary code execution within the context of the browser process. The vulnerability was reported by external researchers and has been addressed in the stable channel update for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-04-17: disclosed: Reported by Weipeng Jiang (@Krace) of VRI
- 2026-06-02: patched: Fixed in version 149.0.7827.53
- 2026-06-04: advisory: NVD publication date