Executive brief
A security vulnerability exists in the Autofill component of the Google Chrome web browser. If a user visits a specially crafted malicious website, an attacker who has already partially compromised the browser's rendering process could exploit this flaw to access sensitive information stored in the computer's memory. This could lead to the exposure of private user data or further system compromise.
Technical details
A use-after-free (UAF) vulnerability exists in the Autofill component of Google Chrome prior to version 149.0.7827.115. The flaw is reachable via a crafted HTML page and requires the attacker to have already compromised the renderer process (a common precondition in Chrome sandbox escape chains). By exploiting this memory corruption issue, a remote attacker can perform an out-of-bounds memory read to extract sensitive information from the process memory. Google has addressed this issue in the stable channel update 149.0.7827.115 for Windows and Mac, and 149.0.7827.114 for Linux.
Affected products
- Google Chrome prior to 149.0.7827.115
Timeline
- 2026-05-21: disclosed: Reported to Chrome by Google researchers
- 2026-06-11: patched: Fixed in Chrome Stable channel update 149.0.7827.115/114
- 2026-06-11: advisory