Executive brief
Google Chrome is a widely used web browser. A critical vulnerability was found in how the browser handles file input fields, which could allow a malicious website to corrupt the computer's memory. If a user visits a specially crafted webpage, an attacker could potentially take control of the browser or execute unauthorized commands on the user's system.
Technical details
A use-after-free (UAF) vulnerability exists in the File Input component of Google Chrome prior to version 149.0.7827.103. The flaw is triggered when the browser incorrectly manages memory lifecycle during the processing of file input elements. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, leading to heap corruption. This can result in arbitrary code execution within the context of the browser process. Google has addressed this in the stable channel update to version 149.0.7827.103 for Windows/Mac and .102 for Linux.
Affected products
- Google Chrome prior to 149.0.7827.103
Timeline
- 2026-05-26: disclosed: Reported to Chrome by Google researchers
- 2026-06-08: patched: Stable channel update released
- 2026-06-09: advisory: NVD publication date