Executive brief
Google Chrome is a widely used web browser. A vulnerability in its 'Guest View' component could allow a malicious website to execute unauthorized code on a user's computer. While this code is restricted by a security sandbox, it represents a significant risk to the integrity of the browser and user data.
Technical details
A use-after-free (UAF) vulnerability exists in the Guest View component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory lifecycle for objects within Guest View, allowing a remote attacker to induce a memory corruption state. By convincing a user to visit a malicious website or load a crafted HTML page, an attacker can exploit this condition to execute arbitrary code. Although the execution is confined within the Chrome sandbox, it can be used as a primary stage in a multi-exploit chain to compromise the host system. The issue is resolved in version 149.0.7827.103.
Affected products
- Google Chrome prior to 149.0.7827.103
Timeline
- 2026-05-27: disclosed: Reported to Chromium project
- 2026-06-08: patched: Fixed in stable channel update 149.0.7827.103
- 2026-06-09: advisory: NVD publication date