Executive brief
Google Chrome and ChromeOS are affected by a critical security flaw in the Canvas component, which handles 2D and 3D graphics in the browser. By tricking a user into visiting a specially crafted website, a remote attacker could execute malicious code on the user's device. While the attack is limited by the browser's security sandbox, it could lead to unauthorized access to data or further compromise of the system.
Technical details
A use-after-free (UAF) vulnerability exists in the Canvas component of Google Chrome on Linux and ChromeOS. The flaw is triggered when the browser incorrectly manages memory for graphics rendering objects, allowing an attacker to reference memory after it has been freed. By enticing a user to visit a malicious HTML page, a remote attacker can exploit this condition to achieve arbitrary code execution within the browser's sandbox. The vulnerability is addressed in version 147.0.7727.138 and later.
Affected products
- Google Chrome prior to 147.0.7727.138
- Google ChromeOS prior to 147.0.7727.138
Timeline
- 2026-03-19: disclosed: Reported by external researcher heapracer
- 2026-04-28: patched: Stable channel update released
- 2026-04-28: advisory