Executive brief
A critical security vulnerability has been identified in the Bluetooth component of Google Chrome for Windows. This flaw could allow a remote attacker to execute malicious code on a user's computer if the user is tricked into visiting a specifically crafted website and performing certain interface gestures. Successful exploitation could lead to full system compromise, unauthorized data access, or the installation of malware.
Technical details
A use-after-free (UAF) vulnerability exists in the Bluetooth implementation of Google Chrome for Windows (CWE-416). The flaw is triggered when the browser incorrectly manages memory objects during Bluetooth-related operations. A remote attacker can exploit this by hosting a malicious HTML page and convincing a user to perform specific UI gestures, leading to arbitrary code execution (RCE) within the context of the browser process. This vulnerability is rated as Critical by Chromium developers. Users should update to version 149.0.7827.103 or later to mitigate this risk.
Affected products
- Google Chrome prior to 149.0.7827.103
Timeline
- 2026-05-28: other: Reported to Google internally
- 2026-06-08: patched: Fixed in version 149.0.7827.103 for Windows
- 2026-06-09: disclosed