Executive brief
A critical security vulnerability exists in the Google Chrome web browser's Prerender feature. By tricking a user into visiting a specially crafted website, a remote attacker could execute malicious code on the user's computer. This could lead to a total compromise of the system, including the theft of sensitive data or the installation of malware.
Technical details
A use-after-free (UAF) vulnerability exists in the Prerender component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the prerendering of web pages. A remote, unauthenticated attacker can exploit this by hosting a malicious HTML page and enticing a user to visit it. Successful exploitation allows for arbitrary code execution (ACE) within the context of the browser process. Google has addressed this vulnerability in version 147.0.7727.101 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 147.0.7727.101
Timeline
- 2026-03-28: other: Vulnerability reported by Google internal team
- 2026-04-15: patched: Fixed in version 147.0.7727.101/102
- 2026-04-15: disclosed: Public advisory published by Google Chrome team