Executive brief
A vulnerability in Google Chrome's Tracing component could allow an attacker to bypass the browser's security sandbox. This component is used for performance monitoring and diagnostics within the browser. If exploited, an attacker who has already gained limited control over a browser process could escalate their access to the underlying operating system, potentially leading to full system compromise or unauthorized data access.
Technical details
A use-after-free (UAF) vulnerability exists in the Tracing component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during tracing operations, allowing a remote attacker to exploit the memory corruption. To successfully exploit this, an attacker must first compromise the renderer process (e.g., via a separate vulnerability). Once the renderer is compromised, the attacker can use a specially crafted HTML page to trigger the UAF in the Tracing component to escape the Chrome sandbox and execute arbitrary code with the privileges of the browser process. This issue is fixed in version 149.0.7827.103.
Affected products
- Google Chrome prior to 149.0.7827.103
Timeline
- 2026-06-08: patched: Fixed in Chrome Stable Channel Update 149.0.7827.103
- 2026-06-09: disclosed: NVD publication date