Executive brief
Google Chrome, a widely used web browser, is affected by a security vulnerability in its user interface component. An attacker could exploit this by tricking a user into visiting a malicious website and performing specific mouse or keyboard actions. If successful, this could lead to a browser crash or allow the attacker to gain unauthorized control over the application.
Technical details
A use-after-free (UAF) vulnerability exists in the 'Views' component of Google Chrome. The flaw is triggered when a remote attacker convinces a user to engage in specific UI gestures while visiting a specially crafted HTML page. This leads to memory corruption in the heap, which can be leveraged for arbitrary code execution within the browser's sandbox or a denial-of-service (crash). The vulnerability is tracked as CWE-416 and was addressed in the stable channel update to version 150.0.7871.47 for Windows, Mac, and Linux.
Affected products
- Google Chrome Prior to 150.0.7871.47
Timeline
- 2026-05-10: disclosed: Reported by Google internal researchers
- 2026-06-30: patched: Fixed in Chrome 150.0.7871.47 stable channel update
- 2026-06-30: advisory