Executive brief
A vulnerability exists in Google Chrome's Extensions component that could allow a malicious website to execute unauthorized code within the browser's security sandbox. This occurs when a user visits a specially crafted webpage, potentially allowing an attacker to interfere with browser operations or access restricted data within that isolated environment. While the impact is limited by the browser's sandbox, it represents a breakdown in the software's internal memory management.
Technical details
A use-after-free (UAF) vulnerability (CWE-416) exists in the Extensions subsystem of Google Chrome. The flaw is triggered when the browser incorrectly manages memory lifecycle for extension-related objects, allowing a remote attacker to induce a memory corruption state via a specially crafted HTML page. If successfully exploited, an attacker can achieve arbitrary code execution (ACE) within the confines of the Chromium renderer sandbox. The vulnerability was addressed in Chrome version 149.0.7827.53. Chromium developers have classified this with a 'Low' security severity.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
- 2026-06-04: disclosed: CVE published