Executive brief
Google Chrome for Android is a mobile web browser used to access the internet. A security vulnerability in the user interface component could allow a malicious website to corrupt the browser's memory. If exploited, this could lead to the browser crashing or potentially allow an attacker to execute unauthorized code on the device, compromising user data and device security.
Technical details
A use-after-free (UAF) vulnerability exists in the User Interface (UI) component of Google Chrome on Android. The flaw is triggered when the browser incorrectly manages memory lifecycle for UI elements, allowing a remote attacker to induce a heap corruption state. By convincing a user to visit a specially crafted HTML page, an attacker can exploit this memory corruption to achieve arbitrary code execution within the context of the browser process. The vulnerability is addressed in version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-04-10: disclosed: Reported by Google internal researchers
- 2026-06-02: patched: Fixed in stable channel update 149.0.7827.53
- 2026-06-04: advisory: NVD publication date