Executive brief
A vulnerability in Google Chrome's Bluetooth component could allow a malicious device physically near a user's computer to access sensitive information. By mimicking a legitimate Bluetooth peripheral, an attacker could potentially read data from the browser's memory. This could lead to the exposure of private user information or browsing data.
Technical details
A use-after-free (UAF) vulnerability exists in the Bluetooth implementation of Google Chrome prior to version 150.0.7871.47. The flaw is triggered when the browser interacts with a specially crafted or malicious Bluetooth peripheral within the local network/radio segment. By exploiting this memory corruption issue, an attacker can perform an out-of-bounds read to leak sensitive information from the Chrome process memory. This vulnerability is tracked as CWE-416 and was addressed in the stable channel update for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched
- 2026-06-30: advisory