Executive brief
Google Chrome is a widely used web browser for accessing the internet and running web applications. A security vulnerability has been identified that could allow a malicious website to bypass the browser's security 'sandbox,' which is designed to keep web content isolated from the rest of the computer. If exploited, this could allow an attacker to gain unauthorized access to the underlying Windows operating system, potentially leading to data theft or the installation of malicious software.
Technical details
A use-after-free (UAF) vulnerability exists in the Core component of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory during the processing of specially crafted HTML content. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious webpage. Successful exploitation allows the attacker to break out of the Chromium sandbox and execute arbitrary code with the privileges of the user on the host Windows system. This issue was addressed in Chrome version 150.0.7871.125.
Affected products
- Google Chrome Prior to 150.0.7871.125
Timeline
- 2026-06-25: disclosed: Reported by xinchaotian of Microsoft
- 2026-07-14: patched: Fixed in version 150.0.7871.125 for Windows
- 2026-07-14: advisory