Executive brief
A critical security vulnerability has been identified in Google Chrome for Android's password management component. An attacker could exploit this flaw by tricking a user into visiting a specially crafted website, potentially allowing the attacker to take control of the device or execute unauthorized commands. This could lead to the theft of sensitive information, including saved passwords, or a complete compromise of the browser session.
Technical details
A use-after-free (UAF) vulnerability exists in the Passwords component of Google Chrome for Android. The flaw is triggered when the browser incorrectly manages memory during the handling of password-related data, which can be exploited by a remote attacker via a specially crafted HTML page. Successful exploitation requires minimal user interaction (visiting a malicious site) and can lead to arbitrary code execution (ACE) within the context of the browser process. Google has addressed this in version 149.0.7827.155 and later.
Affected products
- Google Chrome prior to 149.0.7827.155
Timeline
- 2026-06-09: disclosed: Reported to Google internally
- 2026-06-16: patched: Stable channel update released
- 2026-06-17: advisory: NVD publication date