Executive brief
Google Chrome is a widely used web browser for accessing the internet and internal applications. A critical vulnerability in the browser's Blink engine could allow a remote attacker to execute malicious code on a user's computer if they visit a specially crafted website. This could lead to a total compromise of the user's system, including the theft of sensitive data or the installation of malware.
Technical details
A critical out-of-bounds (OOB) read and write vulnerability exists in the Blink>InterestGroups component of Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to bypass memory safety protections. By exploiting this memory corruption issue, an attacker can achieve arbitrary code execution (ACE) within the context of the browser process. The vulnerability was reported by Google internal researchers and is addressed in version 149.0.7827.197 for Windows and Mac, and 149.0.7827.196 for Linux.
Affected products
- Google Chrome prior to 149.0.7827.197
Timeline
- 2026-06-13: other: Reported by Google researchers
- 2026-06-23: patched: Stable channel update released
- 2026-06-24: disclosed: CVE published