Executive brief
Google Chrome is a widely used web browser. A security vulnerability in its Bluetooth component could allow a malicious website to corrupt the browser's memory. If exploited, this could lead to the browser crashing or potentially allow an attacker to execute unauthorized code on the user's computer, compromising personal data and system security.
Technical details
A use-after-free (UAF) vulnerability exists in the Bluetooth component of Google Chrome for macOS. The flaw is triggered when the browser incorrectly manages memory pointers after an object has been deleted, leading to heap corruption. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation could allow for arbitrary code execution within the context of the browser process. This issue was addressed in version 149.0.7827.103.
Affected products
- Google Chrome prior to 149.0.7827.103
Timeline
- 2026-06-08: advisory: Google released the stable channel update addressing the issue.
- 2026-06-09: disclosed: NVD published the CVE record.