Executive brief
Google Chrome is a widely used web browser. A vulnerability in its core components could allow a remote attacker to bypass security protections (the 'sandbox') that normally isolate the browser from the rest of the computer. If exploited, this could allow an attacker who has already gained a foothold in the browser to gain broader access to the underlying Windows operating system.
Technical details
A use-after-free vulnerability exists in the Core component of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory during the processing of a crafted HTML page. To exploit this, an attacker must first compromise the renderer process (typically via a separate vulnerability). Once the renderer is compromised, this flaw allows the attacker to escape the Chrome sandbox and execute code with higher privileges on the host Windows system. The issue is resolved in version 150.0.7871.115.
Affected products
- Google Chrome prior to 150.0.7871.115
Timeline
- 2026-06-13: disclosed: Reported to Google
- 2026-07-08: patched: Stable channel update released
- 2026-07-08: advisory