Executive brief
Google Chrome is a widely used web browser. A critical security vulnerability was identified that could allow a remote attacker to corrupt the browser's memory if a user is tricked into visiting a malicious website and performing specific interactions, such as clicking or dragging elements. This could potentially lead to the attacker gaining control over the browser or causing it to crash.
Technical details
A use-after-free (UAF) vulnerability exists in the Views component of Google Chrome. The flaw is triggered when a remote attacker convinces a user to engage in specific UI gestures while visiting a maliciously crafted HTML page. This root cause is a CWE-416 (Use After Free) condition, which can lead to heap corruption. Successful exploitation could allow for arbitrary code execution within the context of the browser process, though it requires user interaction. The vulnerability is resolved in Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-05-27: disclosed: Reported to Google internally
- 2026-06-30: patched: Fixed in version 150.0.7871.47
- 2026-06-30: advisory