Executive brief
A critical vulnerability has been identified in Google Chrome's Ozone component, which handles hardware abstraction for different windowing systems. An attacker could exploit this flaw by tricking a user into visiting a specially crafted website, potentially allowing the attacker to take control of the user's computer. This could lead to the theft of sensitive data, unauthorized access to accounts, or the installation of malicious software.
Technical details
A use-after-free (UAF) vulnerability exists in the Ozone abstraction layer of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of specific web content, allowing a remote attacker to achieve arbitrary code execution (ACE) within the context of the browser process. The attack vector is network-based and requires a user to navigate to a malicious HTML page. Google has addressed this in version 150.0.7871.47 and later. The vulnerability is classified as Critical by the Chromium project (CWE-416).
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-05-29: disclosed: Reported to Chromium by Google researchers
- 2026-06-30: advisory: Public advisory and CVE assignment
- 2026-06-30: patched: Fixed in Chrome version 150.0.7871.47