Executive brief
A security vulnerability exists in Google Chrome's WebMCP component. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to run unauthorized code on the user's computer. While the exploit is limited by Chrome's security sandbox, it still poses a significant risk to system integrity and user data.
Technical details
A use-after-free (UAF) vulnerability exists in the WebMCP component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of a crafted HTML page, allowing a remote attacker to potentially execute arbitrary code. While the execution is confined within the Chrome sandbox, it represents a significant step in a multi-stage exploit chain. The vulnerability is addressed in Google Chrome version 150.0.7871.186 and later. The issue was identified as CWE-416.
Affected products
- Google Chrome prior to 150.0.7871.186
Timeline
- 2026-06-10: other: Reported to Google
- 2026-07-23: patched: Fixed in stable channel update 150.0.7871.186
- 2026-07-23: disclosed