Executive brief
A security vulnerability exists in the Google Chrome installer for Windows. A local attacker could use a specially crafted file to gain higher-level system permissions. This could allow an unauthorized user to take control of the operating system or access restricted data.
Technical details
A use-after-free (UAF) vulnerability exists in the Installer component of Google Chrome for Windows (CWE-416). The flaw is triggered when the installer processes a malicious file, leading to memory corruption. A local attacker with limited privileges can exploit this condition to execute code with elevated OS-level permissions. The issue is addressed in Google Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched
- 2026-06-30: advisory