Executive brief
A critical security vulnerability has been identified in Google Chrome for macOS that could allow an attacker to bypass the browser's security sandbox. By tricking a user into visiting a specially crafted website, an attacker who has already compromised the browser's rendering process could gain broader access to the underlying operating system. This could lead to unauthorized data access or the execution of malicious code outside the restricted browser environment.
Technical details
A use-after-free (UAF) vulnerability exists in the Bluetooth component of Google Chrome on macOS. The flaw is triggered when the browser incorrectly manages memory during Bluetooth-related operations. An attacker who has already achieved code execution within the sandboxed renderer process can exploit this memory corruption to escape the sandbox and execute arbitrary code with the privileges of the browser process. This is achieved via a crafted HTML page. The vulnerability is addressed in Chrome version 149.0.7827.103 for Mac.
Affected products
- Google Chrome prior to 149.0.7827.103
Timeline
- 2026-05-27: disclosed: Reported to Chrome by Google researchers.
- 2026-06-08: patched: Stable channel update released.
- 2026-06-09: advisory: NVD publication date.