Executive brief
Google Chrome is a widely used web browser. A critical security vulnerability was found in its Web Authentication component, which handles secure logins. An attacker could exploit this by tricking a user into visiting a malicious website, potentially allowing the attacker to take control of the user's computer or access sensitive data.
Technical details
A use-after-free (UAF) vulnerability exists in the Web Authentication component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the authentication process, allowing an attacker to reference memory after it has been freed. By enticing a user to visit a maliciously crafted HTML page, a remote attacker can exploit this condition to achieve arbitrary code execution (ACE) within the context of the browser. This vulnerability affects Google Chrome versions prior to 149.0.7827.155. Google has released a patch to address this issue in the stable channel update.
Affected products
- Google Chrome prior to 149.0.7827.155
Timeline
- 2026-06-11: disclosed: Reported to Google by internal researchers
- 2026-06-16: patched: Stable channel update released for Desktop
- 2026-06-17: advisory: NVD advisory published