Executive brief
A critical vulnerability exists in Google Chrome's printing component that could allow a malicious website to bypass the browser's security sandbox. By tricking a user into visiting a specially crafted webpage, an attacker could potentially gain unauthorized access to the underlying operating system or user data. This poses a significant risk to data confidentiality and system integrity for users of affected browser versions.
Technical details
A use-after-free (UAF) vulnerability exists in the Printing component of Google Chrome prior to version 149.0.7827.103. The flaw is triggered when the browser incorrectly manages memory during printing operations, which can be exploited by a remote attacker using a specially crafted HTML page. If successfully exploited, this vulnerability allows the attacker to escape the Chromium sandbox and execute arbitrary code with the privileges of the user. Google has addressed this issue in the stable channel update for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 149.0.7827.103
Timeline
- 2026-05-27: disclosed: Reported to Google by internal researchers
- 2026-06-08: patched: Fixed in Chrome version 149.0.7827.103
- 2026-06-09: advisory: NVD publication date