Executive brief
A security vulnerability exists in the Google Chrome web browser's user interface. A remote attacker could exploit this by tricking a user into visiting a malicious website and performing specific mouse or keyboard actions. If successful, this could allow the attacker to crash the browser or potentially execute unauthorized code on the user's computer, compromising personal data and system security.
Technical details
A use-after-free (UAF) vulnerability exists in the UI component of Google Chrome prior to version 150.0.7871.182. The flaw is triggered when a remote attacker convinces a user to engage in specific UI gestures while visiting a specially crafted HTML page. This memory corruption issue (CWE-416) can lead to heap corruption, potentially allowing for arbitrary code execution within the context of the browser process. The vulnerability was reported by Google internal researchers and is addressed in the stable channel update for Windows, Mac, and Linux.
Affected products
- Google Chrome Prior to 150.0.7871.182
Timeline
- 2026-07-14: disclosed: Reported by Google internal researchers
- 2026-07-21: patched: Fixed in version 150.0.7871.182
- 2026-07-21: advisory