Executive brief
A security vulnerability has been identified in Google Chrome for macOS that could allow a malicious Bluetooth device to compromise a user's computer. By interacting with the browser via Bluetooth, an attacker could potentially take control of the system or execute unauthorized commands. This issue specifically affects users on Mac computers who have not yet updated to the latest version of the Chrome browser.
Technical details
A use-after-free (UAF) vulnerability exists in the Bluetooth implementation of Google Chrome for macOS. The flaw is triggered when the browser incorrectly manages memory during interactions with Bluetooth peripherals. An attacker within Bluetooth range can utilize a specially crafted malicious peripheral to exploit this memory corruption, potentially leading to arbitrary code execution (ACE) within the context of the browser. The vulnerability is tracked as CWE-416 and was resolved in version 149.0.7827.197.
Affected products
- Google Chrome prior to 149.0.7827.197
Timeline
- 2026-06-13: disclosed: Reported to Google internally
- 2026-06-23: patched: Fixed in Stable Channel Update 149.0.7827.196/197
- 2026-06-24: advisory: NVD publication date