Executive brief
A security vulnerability has been identified in Google Chrome for Android within its AdFilter component. An attacker could exploit this by tricking a user into visiting a malicious website and performing specific touch gestures, potentially allowing the attacker to take control of the browser or execute unauthorized commands. This could lead to the theft of sensitive information or a compromise of the user's device.
Technical details
A use-after-free vulnerability exists in the AdFilter component of Google Chrome for Android. The flaw is triggered when a remote attacker lures a user to a specially crafted HTML page and induces specific UI gestures, leading to memory corruption. This vulnerability (CWE-416) can be leveraged for remote code execution (RCE) within the context of the browser process. The issue was addressed in version 149.0.7827.201.
Affected products
- Google Chrome prior to 149.0.7827.201
Timeline
- 2026-06-11: disclosed: Reported to Google
- 2026-06-25: patched: Stable channel update released
- 2026-06-25: advisory