Executive brief
A security vulnerability exists in the Google Chrome updater for macOS. This component is responsible for keeping the web browser up to date with the latest features and security patches. A local attacker could exploit this flaw to gain elevated system privileges, potentially allowing them to take full control of the affected computer or access sensitive data.
Technical details
A use-after-free (UAF) vulnerability (CWE-416) exists in the Updater component of Google Chrome for macOS. The flaw is triggered when the updater incorrectly handles memory after it has been freed, specifically during the processing of a malicious file. A local attacker with limited permissions can exploit this condition to execute arbitrary code with elevated privileges. The vulnerability was addressed in Google Chrome version 150.0.7871.47 for Mac.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-05-15: disclosed: Reported to Google internally
- 2026-06-30: advisory: Publicly disclosed in Chrome Stable Channel update