Executive brief
A critical security vulnerability exists in Google Chrome's user interface component. A remote attacker could potentially take control of a user's browser or cause it to crash if the user is tricked into visiting a malicious website and performing specific mouse or keyboard actions. This could lead to the theft of sensitive information or the installation of unauthorized software.
Technical details
A use-after-free (UAF) vulnerability exists in the 'Views' component of Google Chrome. The flaw is triggered when a remote attacker convinces a user to engage in specific UI gestures while visiting a specially crafted HTML page. This memory corruption issue can lead to heap corruption, potentially allowing for arbitrary code execution within the browser's process. The vulnerability is addressed in Google Chrome version 150.0.7871.47 and later. It is tracked as CWE-416.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-05-27: disclosed: Reported by Google internal researchers
- 2026-06-30: patched: Fixed in version 150.0.7871.47
- 2026-06-30: advisory