Executive brief
A critical security vulnerability has been identified in Google Chrome for Linux that could allow an attacker to take control of a user's computer. By tricking a user into installing a malicious browser extension, an attacker can execute unauthorized code on the underlying system. This could lead to the theft of sensitive data, installation of malware, or complete system compromise.
Technical details
A use-after-free (UAF) vulnerability exists in the 'Views' UI framework component of Google Chrome on Linux. The flaw is triggered when the browser incorrectly manages memory lifecycles during interactions with Chrome Extensions. An attacker can exploit this by convincing a user to install a malicious extension, which then triggers the UAF condition to achieve arbitrary code execution (ACE) within the context of the browser process. Google has addressed this in version 149.0.7827.103 for Linux.
Affected products
- Google Chrome prior to 149.0.7827.103
Timeline
- 2026-05-30: disclosed: Reported to Chrome by Google researchers
- 2026-06-08: patched: Stable channel update released
- 2026-06-09: advisory: NVD publication date