Executive brief
A critical vulnerability has been identified in the Google Chrome web browser's proxy component. This flaw could allow a remote attacker to execute malicious code on a user's computer simply by sending specially crafted network traffic. Such an exploit could lead to a total compromise of the affected system, including the theft of sensitive data or the installation of malware.
Technical details
A use-after-free (UAF) vulnerability exists within the Proxy component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of network traffic, allowing a remote, unauthenticated attacker to exploit the memory corruption to achieve arbitrary code execution (ACE). The attack vector is network-based and does not require user interaction beyond the browser processing malicious traffic. Google has addressed this in version 149.0.7827.103 for Windows and Mac, and 149.0.7827.102 for Linux.
Affected products
- Google Chrome prior to 149.0.7827.103
Timeline
- 2026-05-29: disclosed: Reported to Chrome by Google researchers
- 2026-06-08: patched: Stable channel update released
- 2026-06-09: advisory: NVD publication date