Executive brief
A vulnerability in the audio component of Google Chrome on Linux could allow a malicious website to execute unauthorized code on a user's computer. This occurs when a user visits a specially crafted webpage, potentially leading to a compromise of the user's data or system. Users are advised to update to the latest version of Chrome to mitigate this risk.
Technical details
A use-after-free (UAF) vulnerability exists in the Audio component of Google Chrome on Linux. The flaw is triggered when the browser incorrectly manages memory pointers after an object has been deleted, which can be exploited by a remote attacker using a specially crafted HTML page. Successful exploitation could lead to arbitrary code execution within the context of the browser process. The issue is addressed in Chrome version 150.0.7871.47 and later. Chromium developers have classified this with a 'Low' security severity.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched