Executive brief
Google Chrome is a widely used web browser. A critical security vulnerability has been identified that could allow a malicious website to corrupt the browser's memory. If exploited, this could allow an attacker to gain unauthorized access to your computer or disrupt your browsing session. Users should update to the latest version of Chrome immediately to protect their data and systems.
Technical details
A use-after-free (UAF) vulnerability exists in the Views component of Google Chrome. The flaw is triggered when the browser attempts to access memory that has already been freed, typically during the rendering of a specially crafted HTML page. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website, leading to heap corruption. This can result in a browser crash (denial of service) or potentially arbitrary code execution within the context of the browser process. The issue is resolved in Google Chrome version 150.0.7871.115.
Affected products
- Google Chrome prior to 150.0.7871.115
Timeline
- 2026-06-15: disclosed: Reported to Google internally
- 2026-07-08: patched: Fixed in version 150.0.7871.115
- 2026-07-08: advisory