Executive brief
Google Chrome is a widely used web browser. A vulnerability in the browser's user interface component could allow a remote attacker to bypass security boundaries that normally keep different websites isolated from one another. This could lead to the unauthorized access of sensitive data from other open tabs or websites if a user visits a specially crafted malicious webpage.
Technical details
A use-after-free (UAF) vulnerability exists in the Views component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory for UI elements, allowing an attacker who has already compromised the renderer process to exploit the memory corruption. By enticing a user to visit a malicious HTML page, the attacker can bypass Site Isolation protections. This enables the attacker to access data across different security domains (origins) that would otherwise be restricted. The vulnerability was patched in version 148.0.7778.96.
Affected products
- Google Chrome prior to 148.0.7778.96
Timeline
- 2026-03-29: disclosed: Reported to Chrome by Google researchers
- 2026-05-05: patched: Fixed in Chrome 148.0.7778.96 stable channel update
- 2026-05-06: advisory: NVD publication date