Executive brief
A security vulnerability exists in the Google Chrome web browser for Mac. This flaw could allow a malicious website to bypass the browser's security sandbox, which is designed to keep web content isolated from the rest of the computer. If successfully exploited, an attacker who has already gained some control over the browser's rendering process could potentially access or modify data on the user's system.
Technical details
A use-after-free (UAF) vulnerability exists in the GPU component of Google Chrome for macOS. The flaw is triggered when the browser incorrectly manages memory during GPU operations, allowing a remote attacker to exploit the memory corruption. To achieve a sandbox escape, the attacker must first compromise the renderer process, typically via a crafted HTML page. This vulnerability is tracked as CWE-416. Google has addressed this issue in version 149.0.7827.115.
Affected products
- Google Chrome prior to 149.0.7827.115
Timeline
- 2026-05-27: disclosed: Reported to Chrome by Google researchers.
- 2026-06-11: patched: Fixed in version 149.0.7827.115 for Mac.
- 2026-06-11: advisory