Executive brief
A security vulnerability exists in Google Chrome's InterestGroups component, which is part of the browser's ad-targeting and privacy features. By tricking a user into visiting a specially crafted website, an attacker could execute malicious code on the user's computer. While the attack is limited by the browser's security sandbox, it could still lead to unauthorized data access or be used as a stepping stone for further system compromise.
Technical details
A use-after-free (UAF) vulnerability exists in the InterestGroups component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory for interest groups (part of the Privacy Sandbox/FLEDGE API) during the processing of a crafted HTML page. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website, leading to arbitrary code execution (ACE) within the context of the sandboxed renderer process. This vulnerability is tracked as CWE-416. Google has addressed this issue in version 149.0.7827.103 for Windows and Mac, and 149.0.7827.102 for Linux.
Affected products
- Google Chrome prior to 149.0.7827.103
Timeline
- 2026-05-26: disclosed: Reported to Chromium by Google researchers
- 2026-06-08: patched: Fixed in Chrome Stable channel update 149.0.7827.103
- 2026-06-09: advisory: NVD publication date