Executive brief
A security vulnerability exists in Google Chrome's accessibility features, which are used to assist users with disabilities. An attacker who has already partially compromised the browser could use this flaw to gain higher-level system privileges by tricking a user into visiting a malicious website. This could allow the attacker to bypass security boundaries and potentially access sensitive data or execute unauthorized commands on the underlying operating system.
Technical details
A use-after-free (UAF) vulnerability exists in the Accessibility component of Google Chrome. The flaw is triggered when the browser incorrectly manages the lifecycle of memory objects related to accessibility features. To exploit this, a remote attacker must first compromise the sandboxed renderer process. Once achieved, the attacker can use a specially crafted HTML page to trigger the UAF condition, leading to a sandbox escape or privilege escalation on the host system. Google has addressed this in version 148.0.7778.168.
Affected products
- Google Chrome Prior to 148.0.7778.168
Timeline
- 2026-04-15: disclosed: Reported to Chromium project by Google internal researchers
- 2026-05-12: patched: Fixed in Chrome Stable channel update 148.0.7778.168
- 2026-05-14: advisory: NVD publication date