Executive brief
A critical security vulnerability has been identified in the Google Chrome web browser on Windows. This flaw allows a remote attacker to execute malicious code on a user's computer if they visit a specially crafted website. This could lead to a total compromise of the user's system, including unauthorized access to sensitive data or the installation of malware.
Technical details
A use-after-free (UAF) vulnerability exists in the 'Core' component of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory during the processing of HTML content. A remote, unauthenticated attacker can exploit this by enticing a user to visit a maliciously crafted webpage. Successful exploitation allows for arbitrary code execution (RCE) within the context of the browser process. Google has addressed this issue in version 149.0.7827.115.
Affected products
- Google Chrome prior to 149.0.7827.115
Timeline
- 2026-05-26: other: Reported by Google internal researchers
- 2026-06-11: patched: Fixed in version 149.0.7827.115
- 2026-06-11: advisory