Executive brief
A critical security vulnerability has been identified in the Google Chrome web browser's Autofill feature. By tricking a user into visiting a specially crafted website, a remote attacker could gain the ability to run unauthorized code on the user's computer. This could lead to a full system compromise, theft of sensitive data, or the installation of malicious software.
Technical details
A use-after-free (UAF) vulnerability exists in the Autofill component of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory during the processing of specific HTML elements or Autofill interactions. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website containing a crafted HTML page. Successful exploitation allows the attacker to achieve arbitrary code execution (ACE) within the context of the browser process. This issue was addressed in Chrome version 149.0.7827.197.
Affected products
- Google Chrome prior to 149.0.7827.197
Timeline
- 2026-06-14: disclosed: Reported by Google internal researchers
- 2026-06-23: patched: Stable channel update released
- 2026-06-24: advisory: NVD publication date