Executive brief
A vulnerability in the Google Chrome update component on Windows could allow a local user to gain elevated system privileges. By using a specially crafted file, an attacker who already has limited access to a computer could take full control of the operating system. This could lead to unauthorized access to sensitive data or the ability to bypass security restrictions on the affected machine.
Technical details
A use-after-free (UAF) vulnerability exists in the Updater component of Google Chrome for Windows. The flaw is triggered when the updater improperly handles memory objects during the processing of a malicious file, leading to a memory corruption state. A local attacker with low-privileged access can exploit this condition to execute code with elevated system privileges. This vulnerability is tracked as CWE-416 and was addressed in Chrome version 150.0.7871.47.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched