Executive brief
Google Chrome is a widely used web browser. A vulnerability in its FileSystem component could allow a malicious website to corrupt the browser's memory. This could lead to the browser crashing or potentially allow an attacker to execute unauthorized code on the user's computer, compromising personal data and system security.
Technical details
A use-after-free (UAF) vulnerability exists in the FileSystem component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory pointers after an object has been deleted, leading to heap corruption. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation could allow for arbitrary code execution within the context of the browser's renderer process. This issue was addressed in Chrome version 149.0.7827.197 for Windows and Mac, and 149.0.7827.196 for Linux.
Affected products
- Google Chrome prior to 149.0.7827.197
Timeline
- 2026-06-05: other: Reported to Google by internal researchers
- 2026-06-23: patched: Stable channel update released
- 2026-06-24: disclosed: CVE published