Executive brief
A vulnerability in the Google Chrome web browser could allow an attacker to execute malicious code on a user's computer. This occurs when the browser processes a specially crafted web page, potentially leading to unauthorized access to data or system disruption. Users are protected by updating to the latest version of the browser.
Technical details
A use-after-free (UAF) vulnerability exists in the Media component of Google Chrome for Windows. The flaw is triggered when the browser attempts to access memory that has already been freed, typically during the processing of malicious multimedia content within a crafted HTML page. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website, potentially leading to arbitrary code execution within the browser's sandbox. Google has addressed this issue in version 149.0.7827.103.
Affected products
- Google Chrome prior to 149.0.7827.103
Timeline
- 2026-05-27: disclosed: Reported to Chrome by Google researchers
- 2026-06-08: patched: Fixed in Stable Channel Update 149.0.7827.102/.103
- 2026-06-09: advisory