Executive brief
Google Chrome is a widely used web browser. A vulnerability in the way it handles certain ad-targeting data (InterestGroups) could allow a malicious website to execute unauthorized code on a user's computer. While this code would be restricted by the browser's security sandbox, it represents a significant step in a potential multi-stage attack that could lead to data theft or system compromise.
Technical details
A use-after-free (UAF) vulnerability exists in the InterestGroups component of Google Chrome. The flaw is triggered when the browser attempts to access memory that has already been freed, typically during the processing of a specially crafted HTML page. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website, potentially leading to arbitrary code execution within the context of the browser's sandboxed process. This issue is tracked as CWE-416 and was resolved in version 150.0.7871.115.
Affected products
- Google Chrome prior to 150.0.7871.115
Timeline
- 2026-06-24: disclosed: Reported by Jihyeon Jeong
- 2026-07-08: patched: Fixed in version 150.0.7871.115
- 2026-07-08: advisory