Executive brief
Google Chrome is a widely used web browser. A vulnerability in the browser's Actor component could allow a malicious website to execute unauthorized code on a user's computer. While the attack is limited by the browser's security sandbox, it could still lead to service instability or be used as part of a larger attack chain to compromise user data.
Technical details
A use-after-free (UAF) vulnerability exists in the Actor component of Google Chrome. The flaw is triggered when the browser attempts to access memory that has already been deallocated, typically during the processing of specially crafted web content. A remote attacker can exploit this by enticing a user to visit a malicious HTML page, leading to arbitrary code execution within the context of the browser's sandbox. This issue was addressed in Google Chrome version 150.0.7871.115 for Windows and Mac, and 150.0.7871.114 for Linux.
Affected products
- Google Chrome prior to 150.0.7871.115
Timeline
- 2026-06-10: disclosed: Reported to Google
- 2026-07-08: patched: Fixed in stable channel update 150.0.7871.115
- 2026-07-08: advisory