Executive brief
A security vulnerability exists in Google Chrome's 'Actor' component that could allow a malicious website to execute unauthorized code on a user's computer. While the exploit is limited to the browser's 'sandbox' (a security layer designed to isolate the browser from the rest of the system), it represents a significant risk to data privacy and session security. Users are protected by updating to the latest version of the Chrome browser.
Technical details
A use-after-free (UAF) vulnerability exists in the Actor component of Google Chrome prior to version 149.0.7827.53. The flaw is triggered when the browser incorrectly manages memory lifecycle for Actor objects, allowing an attacker to reference memory after it has been freed. By enticing a user to visit a maliciously crafted HTML page, a remote attacker can exploit this memory corruption to achieve arbitrary code execution (ACE) within the context of the browser's sandboxed process. This vulnerability was assigned a 'High' severity rating by the Chromium team. Users should update to version 149.0.7827.53 or later to mitigate the risk.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE-2026-10954 published.