Executive brief
A security vulnerability exists in Google Chrome for Android that could allow a remote attacker to take control of a user's device. By tricking a user into visiting a malicious website and performing specific interactions, the attacker can execute unauthorized commands. This could lead to the theft of sensitive personal data or a complete compromise of the mobile browser.
Technical details
A use-after-free (UAF) vulnerability exists within the Permissions component of Google Chrome on Android. The flaw is triggered when a remote attacker convinces a user to engage in specific UI gestures while viewing a specially crafted HTML page. This memory corruption issue allows for arbitrary code execution within the context of the browser process. The vulnerability was addressed in version 147.0.7727.101. While the attack requires user interaction (UI gestures), the underlying root cause is a CWE-416 memory management error.
Affected products
- Google Chrome prior to 147.0.7727.101
Timeline
- 2026-04-03: other: Reported to Google
- 2026-04-15: disclosed: Public disclosure and NVD publication
- 2026-04-15: patched: Fixed in version 147.0.7727.101