Executive brief
A vulnerability in the Downloads component of Google Chrome for Windows could allow a remote attacker to execute malicious code on a user's computer. To exploit this, an attacker must trick a user into visiting a specially crafted website and performing specific interactions or gestures within the browser's user interface. If successful, this could lead to a full compromise of the user's system and unauthorized access to their data.
Technical details
An inappropriate implementation vulnerability exists in the Downloads component of Google Chrome for Windows. The flaw allows a remote attacker to achieve arbitrary code execution by convincing a user to engage in specific UI gestures while visiting a malicious HTML page. While the exact root cause is described generically as an 'inappropriate implementation,' the impact is rated as Medium severity by Chromium, likely due to the requirement for specific user interaction (UI gestures). The vulnerability is addressed in Google Chrome version 150.0.7871.47 for Windows.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched: Fixed in version 150.0.7871.47