Executive brief
Google Chrome is a widely used web browser. A critical security vulnerability was identified in its Human Interface Device (HID) component, which handles communication with hardware like keyboards and mice. If a user is tricked into visiting a malicious website and performing specific interactions, an attacker could bypass the browser's security 'sandbox' to gain unauthorized access to the underlying operating system.
Technical details
A use-after-free (UAF) vulnerability exists in the Human Interface Device (HID) implementation within Google Chrome. The flaw is triggered when the browser incorrectly manages memory for HID objects after they have been freed. A remote attacker can exploit this by hosting a specially crafted HTML page and convincing a user to perform specific UI gestures. Successful exploitation can lead to a sandbox escape, allowing the attacker to execute arbitrary code outside of the browser's restricted environment. This issue was resolved in version 148.0.7778.168.
Affected products
- Google Chrome prior to 148.0.7778.168
Timeline
- 2026-03-25: other: Reported by Google researchers
- 2026-05-12: patched: Fixed in Chrome Stable Channel Update 148.0.7778.168
- 2026-05-14: disclosed: Public CVE publication