Executive brief
A vulnerability exists in Google Chrome's input handling component. A remote attacker could use a specially crafted website to potentially bypass the browser's security sandbox. This could allow an attacker to gain unauthorized access to the underlying operating system or user data beyond the browser's normal restrictions.
Technical details
A use-after-free (UAF) vulnerability exists in the Input component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of input events. By enticing a user to visit a maliciously crafted HTML page, a remote attacker can exploit this memory corruption to execute code outside of the browser's sandbox environment. This vulnerability is addressed in Google Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
- 2026-06-05: disclosed: NVD publication date