Executive brief
A vulnerability in Google Chrome's networking component could allow an attacker to compromise a user's computer. By intercepting or sending malicious network traffic, an attacker could cause the browser to crash or execute unauthorized code. This typically requires the attacker to be in a 'privileged' network position, such as on the same Wi-Fi network or controlling a network router.
Technical details
A use-after-free (UAF) vulnerability exists in the Network component of Google Chrome prior to version 149.0.7827.115. The flaw is triggered when the browser incorrectly manages memory during the processing of network traffic. An attacker in a privileged network position (e.g., man-in-the-middle) can provide specially crafted network responses to trigger heap corruption. This can lead to a browser crash (denial of service) or potentially arbitrary code execution within the context of the browser process. Google has released a patch in version 149.0.7827.115 to address this issue.
Affected products
- Google Chrome prior to 149.0.7827.115
Timeline
- 2026-04-03: disclosed: Reported to Google by internal researchers
- 2026-06-11: patched: Fixed in Stable Channel Update 149.0.7827.115
- 2026-06-11: advisory