Executive brief
A vulnerability exists in the Google Chrome web browser for Linux that could allow a malicious website to execute unauthorized code on a user's computer. To trigger the issue, an attacker must trick a user into visiting a specially crafted webpage and performing specific mouse or keyboard interactions. If successful, this could lead to a complete compromise of the user's browser session and local data.
Technical details
A use-after-free (UAF) vulnerability exists in the Ozone abstraction layer of Google Chrome on Linux. The flaw is triggered when the browser incorrectly manages memory during specific UI gestures on a crafted HTML page. A remote attacker can exploit this by enticing a user to visit a malicious site and perform certain interactions, leading to arbitrary code execution within the context of the browser process. This issue is tracked as CWE-416 and was resolved in version 150.0.7871.47.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched
- 2026-06-30: advisory