Executive brief
A security vulnerability has been identified in Google Chrome's Digital Credentials component, which handles digital identity and credential sharing. An attacker could use a specially crafted website to bypass the browser's security 'sandbox,' which is designed to keep malicious code from affecting the rest of the computer. If successful, this could allow an attacker to gain unauthorized access to the underlying operating system and sensitive user data.
Technical details
This vulnerability is a use-after-free (UAF) located within the DigitalCredentials component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory lifecycle for digital credential objects, allowing an attacker who has already compromised the renderer process to exploit the memory corruption. By enticing a user to visit a malicious HTML page, a remote attacker can leverage this UAF to achieve a sandbox escape, potentially gaining full execution privileges on the host operating system. The issue was addressed in Chrome version 149.0.7827.155.
Affected products
- Google Chrome prior to 149.0.7827.155
Timeline
- 2026-05-19: disclosed: Reported to Chrome by Google researchers
- 2026-06-16: patched: Stable channel update released
- 2026-06-17: advisory: NVD publication date