Executive brief
Google Chrome is a widely used web browser. A vulnerability in the browser's Extensions component could allow a malicious website to bypass security boundaries (the sandbox) that normally keep web content isolated from the rest of the computer. If successfully exploited, an attacker could potentially gain unauthorized access to the underlying operating system or user data.
Technical details
A use-after-free (UAF) vulnerability exists in the Extensions component of Google Chrome prior to version 149.0.7827.103. The flaw is triggered when the browser incorrectly manages memory for extension-related objects, allowing an attacker who has already compromised the renderer process to exploit the memory corruption. By enticing a user to visit a specially crafted HTML page, a remote attacker can leverage this UAF to achieve a sandbox escape, potentially leading to arbitrary code execution on the host system. This issue was fixed in the Stable channel update to version 149.0.7827.102/.103.
Affected products
- Google Chrome prior to 149.0.7827.103
Timeline
- 2026-05-14: disclosed: Reported to Chrome by Google researchers
- 2026-06-08: patched: Fixed in Stable channel update 149.0.7827.102/.103
- 2026-06-09: advisory: NVD publication date