Executive brief
A security vulnerability exists in Google Chrome's Ozone component, which handles how the browser interacts with different windowing systems. An attacker could exploit this by tricking a user into visiting a malicious website and performing specific mouse or keyboard actions. If successful, this could allow the attacker to crash the browser or potentially execute unauthorized code on the user's computer.
Technical details
A use-after-free (UAF) vulnerability exists in the Ozone abstraction layer of Google Chrome. The flaw is triggered when the browser attempts to access memory that has already been deallocated, specifically during certain user interface gestures. A remote attacker can exploit this by hosting a specially crafted HTML page and enticing a user to interact with the UI in a specific manner. This can lead to heap corruption, potentially resulting in arbitrary code execution within the browser's sandbox. The vulnerability is addressed in Chrome version 150.0.7871.125.
Affected products
- Google Chrome Prior to 150.0.7871.125
Timeline
- 2026-05-29: disclosed: Reported by Google internal researchers
- 2026-07-14: patched: Fixed in Stable Channel Update 150.0.7871.125
- 2026-07-14: advisory