Executive brief
Google Chrome is a widely used web browser. A vulnerability in its GTK component on Windows could allow a remote attacker to execute malicious code on a user's computer if they visit a specially crafted website. This could lead to a total compromise of the user's system, including data theft or the installation of malware.
Technical details
A use-after-free (UAF) vulnerability exists in the GTK component of Google Chrome for Windows. The flaw is triggered when the browser attempts to access memory that has already been freed, typically during the processing of a specially crafted HTML page. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website, leading to arbitrary code execution (ACE) within the context of the browser process. This vulnerability was addressed in version 148.0.7778.168.
Affected products
- Google Chrome Prior to 148.0.7778.168
Timeline
- 2026-04-06: disclosed: Reported to Chrome by Google internal researchers
- 2026-05-12: patched: Fixed in Stable Channel Update 148.0.7778.168
- 2026-05-14: advisory: NVD publication date