Executive brief
A vulnerability exists in Google Chrome's DevTools, a set of web developer tools built directly into the browser. A remote attacker could potentially execute unauthorized code on a user's computer if the user visits a specially crafted website. While the impact is limited by the browser's security sandbox, it could still lead to unauthorized actions within the browser environment.
Technical details
A use-after-free (UAF) vulnerability (CWE-416) exists in the DevTools component of Google Chrome. The flaw is triggered when the browser attempts to access memory that has already been freed, typically during the processing of a specially crafted HTML page. A remote, unauthenticated attacker can exploit this to achieve arbitrary code execution (ACE) within the context of the Chromium sandbox. The vulnerability is addressed in Google Chrome version 150.0.7871.47.
Affected products
- Google Chrome Prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched