Executive brief
A security vulnerability exists in the Google Chrome web browser for Windows. The affected component is the Updater, which manages software updates for the browser. If exploited, a remote attacker could potentially bypass the browser's security sandbox, which is designed to prevent malicious websites from accessing the rest of the computer.
Technical details
A use-after-free (UAF) vulnerability exists in the Updater component of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory during update processes. An attacker who has already compromised a renderer process could leverage this vulnerability via a specially crafted HTML page to achieve a sandbox escape. This would allow the attacker to execute code outside of the restricted browser environment on the host operating system. The issue is addressed in Google Chrome version 150.0.7871.47.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched
- 2026-06-30: advisory