Executive brief
Google Chrome is a widely used web browser. A critical security vulnerability was found in its Gamepad component on Windows, which handles input from gaming controllers. An attacker could use a specially designed website to break out of the browser's security protections (the sandbox), potentially allowing them to gain unauthorized access to the underlying operating system and user data.
Technical details
A use-after-free (UAF) vulnerability exists in the Gamepad component of Google Chrome on Windows. The flaw is triggered when the browser incorrectly manages memory for gamepad devices, allowing a remote attacker to exploit the memory corruption via a malicious HTML page. This vulnerability is classified as Critical by Chromium because it can lead to a sandbox escape, allowing code execution outside of the restricted browser environment. The issue was addressed in version 149.0.7827.103.
Affected products
- Google Chrome prior to 149.0.7827.103
Timeline
- 2026-05-27: disclosed: Reported to the Chromium project
- 2026-06-08: patched: Fixed in Stable Channel Update 149.0.7827.102/.103
- 2026-06-09: advisory: NVD publication date