Executive brief
Google Chrome is a widely used web browser. A vulnerability in the way the browser handles internal data types could allow a malicious website to execute unauthorized code within the browser's security sandbox. This could lead to the compromise of the browser session or be used as a starting point for further attacks on the user's computer.
Technical details
A type confusion vulnerability (CWE-843) exists in the Bindings component of Google Chrome. The flaw is triggered when the browser incorrectly processes objects of incompatible types, which can be exploited by a remote attacker who convinces a user to visit a specially crafted HTML page. Successful exploitation allows for arbitrary code execution within the context of the Chromium sandbox. The vulnerability was fixed in version 149.0.7827.103 for Windows and Mac, and 149.0.7827.102 for Linux.
Affected products
- Google Chrome prior to 149.0.7827.103
Timeline
- 2026-05-16: disclosed: Reported to Chrome by Google researchers
- 2026-06-08: patched: Fixed in Stable Channel Update 149.0.7827.102/.103
- 2026-06-09: advisory: NVD publication date