Executive brief
A critical security vulnerability exists in Google Chrome for macOS that affects how the browser interacts with Bluetooth devices. An attacker could use a malicious Bluetooth peripheral to gain control over the browser and execute unauthorized commands on the user's computer. This could lead to the theft of sensitive data or the installation of malicious software.
Technical details
A use-after-free (UAF) vulnerability exists in the Bluetooth implementation of Google Chrome for macOS (CWE-416). The flaw is triggered when the browser incorrectly manages memory during interactions with Bluetooth peripherals. An attacker within Bluetooth range can exploit this by presenting a specially crafted malicious peripheral to the system. Successful exploitation allows for arbitrary code execution (ACE) within the context of the browser process. The issue is resolved in Chrome version 149.0.7827.103.
Affected products
- Google Chrome prior to 149.0.7827.103
Timeline
- 2026-05-27: other: Reported by Google researchers
- 2026-06-08: patched: Stable channel update released
- 2026-06-09: disclosed: NVD publication date