Executive brief
A vulnerability in Google Chrome's DevTools component could allow a malicious website to execute unauthorized code within the browser's security sandbox. This occurs when a user visits a specially crafted webpage while using an affected version of the browser. While the impact is limited by the browser's sandbox, it represents a flaw in the tools used by developers to inspect and debug web applications.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the DevTools component of Google Chrome prior to version 149.0.7827.53. By enticing a user to visit a specially crafted HTML page, a remote attacker can trigger an out-of-bounds memory access. This flaw can be leveraged to achieve arbitrary code execution, though the execution is restricted within the Chrome sandbox environment. The vulnerability was assigned a 'Low' severity by the Chromium project. Users should update to version 149.0.7827.53 or later to mitigate this risk.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-05: disclosed: CVE published in NVD.