Executive brief
A critical security vulnerability has been identified in Google Chrome for Android. This flaw exists in the browser's fullscreen functionality, which is used to display web content across the entire screen. If exploited, a malicious website could execute unauthorized code on a user's device, potentially leading to full device compromise, data theft, or the installation of malware. Users should update their browser to version 150.0.7871.47 or later immediately to mitigate this risk.
Technical details
A use-after-free (UAF) vulnerability exists in the Fullscreen component of Google Chrome for Android prior to version 150.0.7871.47. The flaw is triggered when the browser incorrectly manages memory during the transition to or from fullscreen mode. A remote, unauthenticated attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation allows the attacker to corrupt memory and execute arbitrary code within the context of the browser process. Google has addressed this issue in the stable channel update 150.0.7871.47.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-12: disclosed: Reported to Chromium by Google researchers
- 2026-06-30: patched: Fixed in version 150.0.7871.47
- 2026-06-30: advisory