Executive brief
A security vulnerability has been identified in Google Chrome for macOS that affects the Touchbar functionality. By tricking a user into visiting a specially crafted website, a remote attacker could potentially bypass the browser's security sandbox. This could allow the attacker to gain unauthorized access to the underlying operating system or user data.
Technical details
A use-after-free (UAF) vulnerability exists in the Touchbar implementation of Google Chrome for macOS (CWE-416). The flaw is triggered when the browser incorrectly manages memory during the lifecycle of Touchbar-related objects. A remote attacker can exploit this by enticing a user to visit a malicious HTML page, leading to memory corruption. This corruption can be leveraged to achieve a sandbox escape, allowing code execution outside of the restricted browser environment. The issue is resolved in Google Chrome version 150.0.7871.47.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-03-25: disclosed: Reported by Weipeng Jiang (@Krace) of VRI
- 2026-06-30: patched: Fixed in stable channel update 150.0.7871.47
- 2026-06-30: advisory