Executive brief
A security vulnerability has been identified in Google Chrome's input handling component. This flaw could allow a remote attacker who has already gained partial control of the browser to bypass security 'sandbox' protections. If successfully exploited, an attacker could potentially gain full control over the user's computer or access sensitive local data.
Technical details
A use-after-free (UAF) vulnerability exists in the Input component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of user input or events. An attacker who has already compromised the renderer process can exploit this memory corruption to escape the Chrome sandbox and execute arbitrary code on the underlying operating system. This attack is typically delivered via a specially crafted HTML page. The issue is resolved in Google Chrome version 150.0.7871.186 and later.
Affected products
- Google Chrome prior to 150.0.7871.186
Timeline
- 2026-06-16: other: Reported to Google
- 2026-07-23: patched: Fixed in stable channel update 150.0.7871.186
- 2026-07-23: disclosed