Executive brief
A vulnerability in the Google Chrome Password Manager could allow a malicious website to execute unauthorized code on a user's computer. While the impact is limited by Chrome's security sandbox, an attacker could potentially disrupt the browser or use this as a stepping stone for further attacks. Users are protected by updating to the latest version of the browser.
Technical details
A use-after-free (UAF) vulnerability exists in the Password Manager component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of a crafted HTML page, allowing an attacker to reference memory after it has been freed. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website, potentially leading to arbitrary code execution (ACE) within the context of the Chromium sandbox. The issue is addressed in Google Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Stable channel update released
- 2026-06-04: disclosed: NVD publication date