Executive brief
A vulnerability in Google Lens within the Chrome browser could allow an attacker to access sensitive information from the computer's memory. To exploit this, an attacker would first need to compromise a specific part of the browser's internal processes and then trick a user into visiting a specially crafted website. This could lead to the exposure of private data handled by the browser.
Technical details
A use-after-free (UAF) vulnerability exists in the Google Lens component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the lifecycle of Google Lens objects. An attacker who has already achieved code execution within a sandboxed renderer process can leverage this vulnerability by enticing a user to visit a malicious HTML page. Successful exploitation allows the attacker to bypass certain memory protections to read sensitive information from the browser's process memory. This issue is resolved in Chrome version 148.0.7778.168.
Affected products
- Google Chrome Prior to 148.0.7778.168
Timeline
- 2026-03-31: disclosed: Reported by Google internally
- 2026-05-12: patched: Fixed in Stable Channel Update 148.0.7778.167/168
- 2026-05-14: advisory: NVD publication date