Executive brief
A vulnerability in Google Chrome's ServiceWorker component could allow an attacker to execute malicious code on a user's computer. To exploit this, an attacker must first trick a user into installing a specifically crafted, malicious Chrome Extension. Successful exploitation could lead to full system compromise or unauthorized access to sensitive data handled by the browser.
Technical details
A use-after-free (UAF) vulnerability exists in the ServiceWorker component of Google Chrome prior to version 149.0.7827.53. The flaw is triggered when the browser improperly manages memory during ServiceWorker operations, which can be manipulated by a crafted Chrome Extension. An attacker who successfully convinces a user to install a malicious extension can exploit this memory corruption to execute arbitrary code within the context of the browser. This vulnerability is tracked as CWE-416 and was addressed in the stable channel update for desktop.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome version 149.0.7827.53 released to stable channel
- 2026-06-04: disclosed: CVE published to NVD