Executive brief
A vulnerability in Google Chrome for macOS could allow a malicious website to bypass security boundaries. If a user visits a specially crafted webpage, an attacker who has already compromised part of the browser's internal processes could escape the 'sandbox'—the security layer designed to keep web content isolated from the rest of the computer. This could potentially lead to unauthorized access to the user's system or data.
Technical details
A use-after-free (UAF) vulnerability exists in the Device Trust component of Google Chrome for macOS. The flaw is triggered when the browser incorrectly manages memory during interactions with device identity or trust services. A remote attacker who has already achieved code execution within the renderer process (via a separate exploit) can leverage this UAF to escape the Chrome sandbox. This is achieved by enticing a user to visit a malicious HTML page. Google has addressed this issue in version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Fixed in Chrome stable channel update 149.0.7827.53/54
- 2026-06-04: disclosed: NVD publication date