Executive brief
Google Chrome is a widely used web browser. A security flaw in its Web Authentication component could allow a malicious browser extension to corrupt the browser's memory. If a user is tricked into installing a specifically crafted extension, an attacker could potentially gain unauthorized control over the browser or access sensitive information.
Technical details
A use-after-free (UAF) vulnerability exists in the Web Authentication component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory lifecycle during authentication processes, specifically when interacting with Chrome Extensions. An attacker can exploit this by convincing a user to install a malicious extension that performs crafted operations to trigger heap corruption. This can lead to a sandbox escape or arbitrary code execution within the context of the browser process. The issue is fixed in Google Chrome version 149.0.7827.197 for Windows and Mac, and 149.0.7827.196 for Linux.
Affected products
- Google Chrome prior to 149.0.7827.197
Timeline
- 2026-06-08: disclosed: Reported to Google by internal researchers
- 2026-06-23: patched: Stable channel update released
- 2026-06-24: advisory: NVD publication date