Executive brief
Google Chrome is a widely used web browser. A critical security flaw was found in its networking component that could allow a malicious website to corrupt the browser's memory. If exploited, this could allow an attacker to take control of the browser or execute unauthorized code on a user's computer simply by having them visit a specially crafted webpage.
Technical details
A use-after-free (UAF) vulnerability exists in the Network stack of Google Chrome. The flaw is triggered when the browser incorrectly manages memory pointers during network operations, allowing an attacker to reference memory after it has been freed. By enticing a user to visit a specially crafted HTML page, a remote, unauthenticated attacker can cause heap corruption. This can lead to arbitrary code execution within the context of the browser process. The vulnerability is fixed in version 150.0.7871.128 and later.
Affected products
- Google Chrome prior to 150.0.7871.128
Timeline
- 2026-07-10: disclosed: Reported to Google internally
- 2026-07-16: patched: Fixed in stable channel update 150.0.7871.128/.129
- 2026-07-20: advisory: NVD publication date