Executive brief
Google Chrome is a widely used web browser. A vulnerability in its ServiceWorker component—which handles background tasks for websites—could allow a remote attacker to execute malicious code on a user's computer. To exploit this, an attacker would first need to compromise the browser's rendering process and then trick a user into visiting a specially crafted website. This could lead to unauthorized access to data or full system compromise within the browser's security sandbox.
Technical details
A use-after-free (UAF) vulnerability exists in the ServiceWorker component of Google Chrome prior to version 149.0.7827.103. The flaw is triggered when the browser incorrectly manages memory during the lifecycle of a ServiceWorker, allowing a remote attacker to exploit the memory corruption. A successful exploit requires the attacker to have already achieved code execution within the renderer process (a 'sandbox escape' chain component). By enticing a user to visit a malicious HTML page, the attacker can execute arbitrary code within the context of the browser's sandbox. Google has addressed this in the stable channel update to version 149.0.7827.103.
Affected products
- Google Chrome prior to 149.0.7827.103
Timeline
- 2026-05-28: disclosed: Reported to Chrome by internal/external researchers.
- 2026-06-08: patched: Fixed in Chrome Stable channel update 149.0.7827.103.
- 2026-06-09: advisory: NVD published the CVE record.