Executive brief
A vulnerability exists in the SSL component of Google Chrome on ChromeOS. An attacker could use a specially crafted website to access sensitive information stored in the computer's memory. This could lead to the exposure of private data from other open tabs or browser processes.
Technical details
A use-after-free (UAF) vulnerability exists within the SSL implementation of Google Chrome on ChromeOS. The flaw is triggered when the browser improperly manages memory objects during SSL operations, specifically when processing a maliciously crafted HTML page. A remote, unauthenticated attacker can exploit this condition to perform an out-of-bounds read of the browser's process memory. This can result in the disclosure of sensitive information, such as session tokens or other private data residing in memory. The issue is fixed in ChromeOS version 150.0.7871.47.
Affected products
- Google ChromeOS prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched