Executive brief
Google Chrome is a widely used web browser. A vulnerability in its WebML component could allow a remote attacker to execute malicious code on a user's computer if they visit a specially crafted website. While the exploit is limited by the browser's security sandbox, it could still lead to unauthorized actions or be used as part of a larger attack to compromise the system.
Technical details
A use-after-free (UAF) vulnerability exists in the WebML component of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory during the processing of WebML content, allowing an attacker to reference memory after it has been freed. By enticing a user to visit a maliciously crafted HTML page, a remote attacker can exploit this condition to achieve arbitrary code execution. Although the execution is restricted within the Chromium sandbox, this represents a significant security risk. The issue is resolved in version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
- 2026-06-04: disclosed: CVE published in NVD dataset