Executive brief
Google Chrome is a widely used web browser. A vulnerability in its 'Blink' rendering engine could allow a malicious website to execute unauthorized code on a user's computer. While this code execution is restricted by a security sandbox, it represents a significant risk to user data and system integrity if combined with other flaws.
Technical details
A use-after-free (UAF) vulnerability exists in the Blink rendering engine of Google Chrome versions prior to 149.0.7827.197. The flaw is triggered when the browser incorrectly manages memory pointers during the processing of web content, specifically within the Blink component. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to execute arbitrary code in the context of the browser's sandboxed process. This issue was addressed in the Stable channel update to version 149.0.7827.197 for Windows and Mac, and 149.0.7827.196 for Linux.
Affected products
- Google Chrome prior to 149.0.7827.197
Timeline
- 2026-06-13: disclosed: Reported to Chrome by Google internal researchers
- 2026-06-23: patched: Stable channel update released for desktop
- 2026-06-24: advisory: NVD publication date