Executive brief
Google Chrome is a widely used web browser. A vulnerability in its Blink rendering engine could allow a remote attacker to execute malicious code on a user's computer if they visit a specially crafted website. While the attack is limited by the browser's security sandbox, it could still lead to unauthorized actions or serve as a stepping stone for further system compromise.
Technical details
A use-after-free (UAF) vulnerability exists in the Blink rendering engine of Google Chrome prior to version 147.0.7727.55. The flaw is triggered when the browser incorrectly manages memory during the processing of HTML content, allowing an attacker to reference memory after it has been freed. By enticing a user to visit a malicious website, a remote attacker can exploit this condition to achieve arbitrary code execution (ACE) within the context of the Chromium sandbox. This vulnerability is tracked as CWE-416 and was resolved in the stable channel update for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 147.0.7727.55
Timeline
- 2026-03-25: disclosed: Reported to Chrome by Google internal researchers
- 2026-04-07: patched: Fixed in Chrome version 147.0.7727.55
- 2026-04-08: advisory