Executive brief
Google Chrome is a widely used web browser. A vulnerability in its ServiceWorker component could allow a malicious browser extension to bypass security protections known as the 'sandbox.' If exploited, this could allow an attacker to gain unauthorized access to the underlying operating system or user data beyond the browser's normal restrictions.
Technical details
A use-after-free (UAF) vulnerability exists in the ServiceWorker component of Google Chrome prior to version 149.0.7827.103. The flaw is triggered when the browser incorrectly manages memory during ServiceWorker operations. An attacker can exploit this by convincing a user to install a specially crafted, malicious Chrome Extension. Successful exploitation allows the attacker to escape the Chrome sandbox, potentially leading to arbitrary code execution on the host operating system. The issue was fixed in the Stable channel update to version 149.0.7827.103.
Affected products
- Google Chrome prior to 149.0.7827.103
Timeline
- 2026-05-15: disclosed: Reported to Google by internal researchers
- 2026-06-08: patched: Fixed in Chrome Stable channel update 149.0.7827.103
- 2026-06-09: advisory: NVD publication date