Executive brief
A critical vulnerability exists in Google Chrome's Blink rendering engine, which is responsible for displaying web content. By tricking a user into visiting a specially crafted website, an attacker could execute malicious code on the user's computer. While the code is restricted by Chrome's security sandbox, this flaw could lead to data theft or be used as part of a larger attack to compromise the entire system.
Technical details
A use-after-free (UAF) vulnerability exists in the Blink rendering engine of Google Chrome prior to version 148.0.7778.168. The flaw is triggered when the browser incorrectly manages memory during the processing of HTML content, allowing an attacker to reference memory after it has been freed. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website, leading to arbitrary code execution (ACE) within the context of the Chromium sandbox. Google has addressed this issue in the stable channel update for Windows, Mac, and Linux.
Affected products
- Google Chrome Prior to 148.0.7778.168
Timeline
- 2026-03-30: other: Reported to Chrome by Google researchers
- 2026-05-12: patched: Fixed in version 148.0.7778.168/167
- 2026-05-14: disclosed: CVE published