Executive brief
A vulnerability in the Downloads component of Google Chrome could allow a remote attacker to execute malicious code on a user's computer. To exploit this, an attacker must trick a user into visiting a specially crafted website and performing specific interactions or gestures within the browser's interface. Successful exploitation could lead to a full system compromise, unauthorized data access, or the installation of malware.
Technical details
A use-after-free (UAF) vulnerability exists in the Downloads component of Google Chrome prior to version 148.0.7778.168. The flaw is triggered when the browser incorrectly manages memory during download operations, specifically when a user is coerced into performing certain UI gestures on a malicious HTML page. This memory corruption allows a remote attacker to achieve arbitrary code execution (ACE) within the context of the browser process. The vulnerability is tracked as CWE-416 and was resolved in the Stable channel update for Windows, Mac, and Linux.
Affected products
- Google Chrome Prior to 148.0.7778.168
Timeline
- 2026-04-01: other: Reported to Chrome by Google researchers
- 2026-05-12: patched: Fixed in Chrome version 148.0.7778.168
- 2026-05-14: disclosed: NVD publication date