Executive brief
Google Chrome is a widely used web browser. A security vulnerability in the 'Journeys' feature could allow a remote attacker to bypass the browser's security sandbox. If successfully exploited, this could allow an attacker to gain unauthorized access to the underlying operating system or user data after first compromising a website rendering process.
Technical details
A use-after-free (UAF) vulnerability exists in the Journeys component of Google Chrome. The flaw (CWE-416) can be triggered via a specially crafted HTML page. An attacker who has already achieved code execution within a compromised renderer process could leverage this vulnerability to escape the Chrome sandbox and execute code with higher privileges on the host system. The issue is resolved in Google Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory: Google released a stable channel update addressing the issue.
- 2026-06-30: patched