Executive brief
A critical vulnerability exists in Google Chrome's Tab Groups feature, which allows users to organize their browser tabs. A remote attacker could exploit this flaw to execute unauthorized code on a user's computer by sending specially crafted network traffic. This could lead to a complete compromise of the user's system, data theft, or the installation of malicious software.
Technical details
A use-after-free (UAF) vulnerability (CWE-416) exists in the Tab Groups component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of malicious network traffic, allowing an attacker to reference memory after it has been freed. This can lead to remote code execution (RCE) in the context of the browser process. The vulnerability affects Google Chrome versions prior to 148.0.7778.168. Users are advised to update to the latest stable channel release to mitigate this risk.
Affected products
- Google Chrome prior to 148.0.7778.168
Timeline
- 2026-04-18: disclosed: Reported by Google researchers
- 2026-05-12: patched: Stable channel update released
- 2026-05-14: advisory: NVD publication date