Executive brief
A security vulnerability exists in the Google Chrome web browser for Linux that could allow a remote attacker to compromise a user's system. By tricking a user into visiting a malicious website and performing specific interactions, an attacker could cause the browser to crash or potentially execute unauthorized code. This could lead to the theft of sensitive data or unauthorized access to the user's computer.
Technical details
A use-after-free (UAF) vulnerability exists in the UI component of Google Chrome for Linux. The flaw is triggered when a remote attacker convinces a user to visit a specially crafted HTML page and perform specific UI gestures. This sequence leads to memory corruption (heap corruption) due to the application attempting to use memory after it has been freed. The attack requires user interaction and has a high complexity, but successful exploitation could result in arbitrary code execution within the context of the browser process. The issue is resolved in version 150.0.7871.125.
Affected products
- Google Chrome prior to 150.0.7871.125
Timeline
- 2026-07-09: disclosed: Reported by Google internal researchers
- 2026-07-14: patched: Fixed in Stable Channel Update 150.0.7871.124/.125
- 2026-07-14: advisory