Executive brief
Google Chrome is a widely used web browser. A vulnerability in the browser's navigation component could allow a remote attacker to execute malicious code on a user's computer if they visit a specially crafted website. While the attack is limited by the browser's security sandbox, it could still lead to unauthorized data access or further system compromise.
Technical details
A use-after-free (UAF) vulnerability exists in the Navigation component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during page navigation processes. A remote, unauthenticated attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation allows for arbitrary code execution within the context of the Chrome sandbox. The vulnerability was addressed in version 147.0.7727.55.
Affected products
- Google Chrome prior to 147.0.7727.55
Timeline
- 2024-04-05: disclosed: Reported by Cassidy Kim
- 2026-04-07: patched: Fixed in Chrome 147.0.7727.55 stable release
- 2026-04-08: advisory: CVE published