Executive brief
A security vulnerability exists in Google Chrome's Aura component, which is responsible for the browser's window management and user interface. A local attacker could use a specially crafted file to cause the browser to crash or potentially execute unauthorized commands. This could lead to a compromise of the user's device or the theft of sensitive information stored within the browser.
Technical details
This vulnerability is a use-after-free (UAF) classified as CWE-416, located within the Aura windowing engine of Google Chrome. The flaw is triggered when the browser attempts to access memory that has already been deallocated, specifically during the processing of a malicious file by a local attacker. Successful exploitation can lead to heap corruption, which may allow for arbitrary code execution within the context of the browser process. The issue was addressed in Chrome version 150.0.7871.128 for Linux and 150.0.7871.128/.129 for Windows and Mac.
Affected products
- Google Chrome Prior to 150.0.7871.128
Timeline
- 2026-07-09: disclosed: Reported to Google internally
- 2026-07-16: patched: Stable channel update released
- 2026-07-20: advisory: NVD publication date