Executive brief
A critical security vulnerability has been identified in Google Chrome for macOS that could allow an attacker to bypass the browser's security sandbox. By tricking a user into visiting a malicious website and performing specific interactions, an attacker could potentially gain unauthorized access to the underlying operating system. This could lead to the theft of sensitive data or the installation of malicious software.
Technical details
A use-after-free (UAF) vulnerability exists in the Bluetooth implementation of Google Chrome for macOS. The flaw is triggered when the browser incorrectly manages memory during Bluetooth-related operations, which can be exploited by a remote attacker who convinces a user to visit a malicious website and perform specific UI gestures. Successful exploitation allows the attacker to escape the Chrome renderer sandbox and execute arbitrary code with the privileges of the browser process. This vulnerability is addressed in Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-05-27: disclosed: Reported to Chromium project
- 2026-06-30: patched: Fixed in stable channel update 150.0.7871.47
- 2026-06-30: advisory