Executive brief
A vulnerability in Google Chrome's accessibility features could allow a remote attacker to bypass security protections. By convincing a user to visit a specially crafted website, an attacker who has already gained limited control over the browser could escape the 'sandbox'—a security layer designed to prevent malicious code from reaching the rest of the computer. This could lead to full system compromise or unauthorized access to sensitive user data.
Technical details
A use-after-free (UAF) vulnerability exists in the Accessibility component of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory for accessibility objects, allowing an attacker who has already compromised the renderer process to execute arbitrary code outside of the browser's sandbox. Exploitation requires the victim to navigate to a malicious HTML page (User Interaction). This vulnerability is addressed in Chrome version 147.0.7727.138.
Affected products
- Google Chrome prior to 147.0.7727.138
Timeline
- 2026-04-16: other: Reported to Google internally
- 2026-04-28: advisory: Vendor advisory published
- 2026-04-28: patched