Executive brief
Google Chrome is a widely used web browser. A vulnerability in its user interface component could allow a remote attacker to bypass security protections (the 'sandbox') that normally isolate the browser from the rest of the computer. If successfully exploited, this could allow an attacker to gain unauthorized access to the underlying operating system or user data.
Technical details
A use-after-free (UAF) vulnerability exists in the 'Views' component of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory for UI elements, allowing an attacker who has already compromised the renderer process to execute code outside of the browser's sandbox. Exploitation requires a remote attacker to entice a user to visit a specially crafted HTML page. This vulnerability is rated as Critical by Chromium and High by CISA-ADP, and it was addressed in Chrome version 147.0.7727.138.
Affected products
- Google Chrome prior to 147.0.7727.138
Timeline
- 2026-04-17: other: Reported to Google
- 2026-04-28: disclosed
- 2026-04-28: patched