Executive brief
Google Chrome is a widely used web browser. A vulnerability in its ViewTransitions component could allow a malicious website to execute unauthorized code on a user's computer. While the browser's security sandbox limits the immediate impact, this could be used as a stepping stone for further attacks or to compromise user data within the browser session.
Technical details
A use-after-free (UAF) vulnerability exists in the ViewTransitions component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of view transitions, allowing an attacker to reference memory after it has been freed. By enticing a user to visit a maliciously crafted HTML page, a remote attacker can exploit this condition to achieve arbitrary code execution (ACE) within the context of the browser's sandboxed process. The vulnerability is tracked as CWE-416 and was addressed in version 149.0.7827.103.
Affected products
- Google Chrome prior to 149.0.7827.103
Timeline
- 2026-05-27: disclosed: Reported by Quac Tran
- 2026-06-08: patched: Fixed in version 149.0.7827.103
- 2026-06-09: advisory